Title:
Persistence and Execution at Scale via GPO Scheduled Task
Status:
test
Description:Detect lateral movement using GPO scheduled task, usually used to deploy ransomware at scale
References:
-https://twitter.com/menasec1/status/1106899890377052160
-https://www.secureworks.com/blog/ransomware-as-a-distraction
-https://www.elastic.co/guide/en/security/7.17/prebuilt-rule-0-16-1-scheduled-task-execution-at-scale-via-gpo.html
Author: Samir Bousseaden
Date: 2019-04-03
modified:2024-09-04
Tags:
- -'attack.privilege-escalation'
- -'attack.execution'
- -'attack.persistence'
- -'attack.lateral-movement'
- -'attack.t1053.005'
Logsource:
- product: windows
- service: security
- definition: The advanced audit policy setting "Object Access > Audit Detailed File Share" must be configured for Success/Failure
Detection:
selection_5136:
EventID:
'5136'
AttributeLDAPDisplayName:
-'gPCMachineExtensionNames'
-'gPCUserExtensionNames'
AttributeValue|contains:
-'CAB54552-DEEA-4691-817E-ED4A4D1AFC72'
-'AADCED64-746C-4633-A97C-D61349046527'
selection_5145:
EventID:
'5145'
ShareName|endswith:
'\SYSVOL'
RelativeTargetName|endswith:
'ScheduledTasks.xml'
AccessList|contains:
-'WriteData'
-'%%4417'
condition:
1 of selection_*
Falsepositives:
-If the source IP is not localhost then it's super suspicious, better to monitor both local and remote changes to GPO scheduled tasks.
Level:
high