Persistence and Execution at Scale via GPO Scheduled Task

 Original Source: [Sigma source]
Title: Persistence and Execution at Scale via GPO Scheduled Task
Status: test
Description:Detect lateral movement using GPO scheduled task, usually used to deploy ransomware at scale
References:
  -https://twitter.com/menasec1/status/1106899890377052160
  -https://www.secureworks.com/blog/ransomware-as-a-distraction
  -https://www.elastic.co/guide/en/security/7.17/prebuilt-rule-0-16-1-scheduled-task-execution-at-scale-via-gpo.html
Author: Samir Bousseaden
Date: 2019-04-03
modified:2024-09-04
Tags:
  • -'attack.privilege-escalation'
  • -'attack.execution'
  • -'attack.persistence'
  • -'attack.lateral-movement'
  • -'attack.t1053.005'
Logsource:
  • product: windows
  • service: security
  • definition: The advanced audit policy setting "Object Access > Audit Detailed File Share" must be configured for Success/Failure
Detection:
  selection_5136:
    EventID: '5136'
    AttributeLDAPDisplayName:
      -'gPCMachineExtensionNames'
      -'gPCUserExtensionNames'

    AttributeValue|contains:
      -'CAB54552-DEEA-4691-817E-ED4A4D1AFC72'
      -'AADCED64-746C-4633-A97C-D61349046527'

  selection_5145:
    EventID: '5145'
    ShareName|endswith: '\SYSVOL'
    RelativeTargetName|endswith: 'ScheduledTasks.xml'
    AccessList|contains:
      -'WriteData'
      -'%%4417'

  condition:1 of selection_*
Falsepositives:
  -If the source IP is not localhost then it's super suspicious, better to monitor both local and remote changes to GPO scheduled tasks.
Level: high