If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: attack.mitre.org/techniques/T1615 - Group Policy Discovery, Techni.

site address: attack.mitre.org/techniques/T1615 redirected to: attack.mitre.org/techniques/T1615

site title: Group Policy Discovery, Technique T1615 - Enterprise MITRE ATT&CK®

Our opinion (on Saturday 22 August 2026 22:02:26 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:



Meta tags:

Headings (most frequently used words):

group, policy, discovery, procedure, examples, mitigations, detection, strategy, references,

Text of the page (most frequently used words):
#policy (20), group (18), the (12), att (10), all (10), retrieved (10), and (9), enterprise (7), domain (7), settings (7), for (7), techniques (6), information (6), ics (5), mobile (5), none (5), detection (5), objects (5), may (5), 2024 (5), 2016 (5), gpresult (5), get (5), discovery (5), mitre (4), february (4), march (4), can (4), version (4), are (3), use (3), cti (3), data (3), mitigations (3), defenses (3), sub (3), emissary (3), has (3), bloodhound (3), 2019 (3), october (3), active (3), directory (3), leviathan (3), adversaries (3), within (3), 2026 (2), corporation (2), changelog (2), domains (2), resources (2), reference (2), campaigns (2), software (2), groups (2), components (2), analytics (2), strategies (2), assets (2), tactics (2), matrices (2), core (2), 2020 (2), from (2), june (2), july (2), security (2), 2025 (2), schroeder (2), april (2), admin (2), august (2), 2021 (2), command (2), execution (2), powershell (2), enumeration (2), domaingpo (2), domaingpolocalgroup (2), ldap (2), strategy (2), windows (2), analytic (2), description (2), name (2), this (2), attack (2), technique (2), with (2), system (2), discover (2), details (2), turla (2), lunarweb (2), victim (2), australian (2), intrusions (2), various (2), empire (2), identify (2), environment (2), dusttrap (2), t1615 (2), such (2), gather (2), paths (2), network (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, cookie, preferences, website, privacy, terms, contact, reset, filters, faou, agent, btz, comrat, ten, year, journey, jurčacko, moon, back, doors, lunar, landing, diplomatic, missions, cisa, people, republic, china, prc, ministry, state, apt40, tradecraft, action, falcone, miller, osborn, trojan, did, operation, lotus, blossom, cause, evolve, mike, stokkel, apt41, arisen, dust, september, robbins, vazarkar, six, degrees, warner, nelson, github, powershellempire, microsoft, 2017, metcalf, sneaky, persistence, srachui, 2012, basics, part, understanding, structure, object, references, adversary, attempts, enumerate, through, suspicious, abnormal, queries, targeting, grouppolicycontainer, defenders, observe, unusual, process, lineage, script, filter, activity, against, controllers, an0152, det0055, type, cannot, easily, mitigated, preventive, controls, since, based, abuse, features, surveys, upon, check, using, g0010, capture, s1141, performed, extensive, environments, during, c0049, includes, modules, enumerating, s0363, capability, execute, s0082, s1159, ability, collect, local, via, gpo, s0521, procedure, examples, live, permalink, last, modified, created, jonhnathan, ribeiro, 3coresec, _w0rk3r, ted, samuels, rapid7, contributors, platforms, tactic, commands, publicly, available, functions, shape, follow, behaviors, including, determining, potential, target, well, opportunities, manipulate, their, benefit, tenant, modification, privilege, escalation, measures, applied, patterns, that, manipulated, used, blend, allows, centralized, management, user, computer, gpos, containers, made, files, stored, predictable, path, sysvol, policies, home, open, join, mclean, hotel, location, found, register, here, search, blog, contribute, benefactors, legal, branding, updates, history, engage, tools, advisory, council, learn, more, about, started, detections,


Text of the page (random words):
group policy discovery technique t1615 enterprise mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home techniques enterprise group policy discovery group policy discovery adversaries may gather information on group policy settings to identify paths for privilege escalation security measures applied within a domain and to discover patterns in domain objects that can be manipulated or used to blend in the environment group policy allows for centralized management of user and computer settings in active directory ad group policy objects gpos are containers for group policy settings made up of files stored within a predictable network path domain sysvol domain policies 1 2 adversaries may use commands such as gpresult or various publicly available powershell functions such as get domaingpo and get domaingpolocalgroup to gather information on group policy settings 3 4 adversaries may use this information to shape follow on behaviors including determining potential attack paths within the target network as well as opportunities to manipulate group policy settings i e domain or tenant policy modification for their benefit id t1615 sub techniques no sub techniques ⓘ tactic discovery ⓘ platforms windows contributors jonhnathan ribeiro 3coresec _w0rk3r ted samuels rapid7 version 1 1 created 06 august 2021 last modified 24 october 2025 version permalink live version procedure examples id name description s0521 bloodhound bloodhound has the ability to collect local admin information via gpo 5 s1159 dusttrap dusttrap can identify victim environment group policy information 6 s0082 emissary emissary has the capability to execute gpresult 7 s0363 empire empire includes various modules for enumerating group policy 4 c0049 leviathan australian intrusions leviathan performed extensive active directory enumeration of victim environments during leviathan australian intrusions 8 s1141 lunarweb lunarweb can capture information on group policy settings 9 g0010 turla turla surveys a system upon check in to discover group policy details using the gpresult command 10 mitigations this type of attack technique cannot be easily mitigated with preventive controls since it is based on the abuse of system features detection strategy id name analytic id analytic description det0055 detection strategy for group policy discovery on windows an0152 detection of adversary attempts to enumerate group policy settings through suspicious command execution gpresult powershell enumeration get domaingpo get domaingpolocalgroup and abnormal ldap queries targeting grouppolicycontainer objects defenders observe unusual process lineage script execution or ldap filter activity against domain controllers references srachui 2012 february 13 group policy basics part 1 understanding the structure of a group policy object retrieved march 5 2019 metcalf s 2016 march 14 sneaky active directory persistence 17 group policy retrieved march 5 2019 microsoft 2017 october 16 gpresult retrieved august 6 2021 schroeder w warner j nelson m n d github powershellempire retrieved april 28 2016 robbins a vazarkar r and schroeder w 2016 april 17 bloodhound six degrees of domain admin retrieved march 5 2019 mike stokkel et al 2024 july 18 apt41 has arisen from the dust retrieved september 16 2024 falcone r and miller osborn j 2016 february 3 emissary trojan changelog did operation lotus blossom cause it to evolve retrieved february 15 2016 cisa et al 2024 july 8 people s republic of china prc ministry of state security apt40 tradecraft in action retrieved february 3 2025 jurčacko f 2024 may 15 to the moon and back doors lunar landing in diplomatic missions retrieved june 26 2024 faou m 2020 may from agent btz to comrat v4 a ten year journey retrieved june 15 2020 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
Thumbnail images (randomly selected): * Images may be subject to copyright.GREEN status (no comments)
  • External site

Verified site has: 53 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-53


The site also has references to the 1 subdomain(s)

  mitre.org  Verify


The site also has 1 references to other resources (not html/xhtml )

 www.welivesecurity.com/wp-content/uplo___.pdf  Verify


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/1.1 301 Moved Permanently
Connection close
Content-Length 162
Server GitHub.com
Content-Type text/html
Location htt????/attack.mitre.org/techniques/T1615
X-GitHub-Request-Id A79A:779F0:2D64D1A:2DC55E2:6A8A1C71
x-github-edge-region fra
Accept-Ranges bytes
Age 0
Date Sat, 22 Aug 2026 22:02:25 GMT
Via 1.1 varnish
X-Served-By cache-rtm-ehrd2290043-RTM
X-Cache MISS
X-Cache-Hits 0
X-Timer S1787436146.577508,VS0,VE103
Vary Accept-Encoding
X-Fastly-Request-ID 0157a1377d9f0a3225839982c678597f981c310a
HTTP/2 301
server GitHub.com
content-type text/html
x-origin-cache HIT
location htt????/attack.mitre.org/techniques/T1615/
access-control-allow-origin *
expires Sat, 22 Aug 2026 22:12:25 GMT
cache-control max-age=600
x-proxy-cache MISS
x-github-request-id E962:1CD82:50493A:542E2C:6A8A1C71
x-github-edge-region uksouth
accept-ranges bytes
age 0
date Sat, 22 Aug 2026 22:02:25 GMT
via 1.1 varnish
x-served-by cache-lcy-egml8630033-LCY
x-cache MISS
x-cache-hits 0
x-timer S1787436146.706777,VS0,VE89
vary Accept-Encoding
x-fastly-request-id 74ab0e0db00c503b0b9fca39a739dbe00ced201b
content-length 162
HTTP/2 200
server GitHub.com
content-type text/html; charset=utf-8
x-origin-cache HIT
last-modified Fri, 07 Aug 2026 14:24:19 GMT
access-control-allow-origin *
etag W/ 6a75ea93-be8e
expires Sat, 22 Aug 2026 22:12:25 GMT
cache-control max-age=600
content-encoding gzip
x-proxy-cache MISS
x-github-request-id 234E:34AC52:4FE560:53CAB2:6A8A1C71
x-github-edge-region uksouth
accept-ranges bytes
age 0
date Sat, 22 Aug 2026 22:02:25 GMT
via 1.1 varnish
x-served-by cache-lcy-egml8630033-LCY
x-cache MISS
x-cache-hits 0
x-timer S1787436146.803980,VS0,VE96
vary Accept-Encoding
x-fastly-request-id 15c975034c0251010bce338672775c2d5294c6e6
content-length 8346

Meta Tags

title="Group Policy Discovery, Technique T1615 - Enterprise | MITRE ATT&CK®"
name="google-site-verification" content="2oJKLqNN62z6AOCb0A0IXGtbQuj-lev5YPAHFF_cbHQ"
charset="utf-8"
name="viewport" content="width=device-width, initial-scale=1,shrink-to-fit=no"
http-equiv="X-UA-Compatible" content="IE=edge"

Load Info

page size8346
load time (s)0.557582
redirect count2
speed download14983
server IP 185.199.110.153
* all occurrences of the string "http://" have been changed to "htt???/"