logo

One policy to rule them all

ID: adac2f1f-4b80-5eee-b266-4db820faa031

STIX ID: report--adac2f1f-4b80-5eee-b266-4db820faa031

Feed Name: Securelist by Kaspersky

Threat Score
75/100

Date Published: 2025-01-31

Date Updated: 2026-04-29

Author: Gleb Ivanov

...
...

This report examines how adversaries can abuse Windows Group Policy Objects to distribute malware and ransomware, establish domain-wide persistence, and escalate privileges; it explains GPO internals (GPC/GPT and attributes), demonstrates abuse techniques and tools (SharpGPOAbuse, GPOddity), and provides practical detection rules (Event 5136, CSE GUIDs), scripts and monitoring approaches (Group3r, SharpHound, GCNet) for Compromise Assessment and MDR.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.