Meta tags:
Headings (most frequently used words):
group, policy, discovery, procedure, examples, mitigations, detection, strategy, references,
Text of the page (most frequently used words):
#policy (20), group (18), the (12), att (10), all (10), retrieved (10), and (9), enterprise (7), domain (7), settings (7), for (7), techniques (6), information (6), ics (5), mobile (5), none (5), detection (5), objects (5), may (5), 2024 (5), 2016 (5), gpresult (5), get (5), discovery (5), mitre (4), february (4), march (4), can (4), version (4), are (3), use (3), cti (3), data (3), mitigations (3), defenses (3), sub (3), emissary (3), has (3), bloodhound (3), 2019 (3), october (3), active (3), directory (3), leviathan (3), adversaries (3), within (3), 2026 (2), corporation (2), changelog (2), domains (2), resources (2), reference (2), campaigns (2), software (2), groups (2), components (2), analytics (2), strategies (2), assets (2), tactics (2), matrices (2), core (2), 2020 (2), from (2), june (2), july (2), security (2), 2025 (2), schroeder (2), april (2), admin (2), august (2), 2021 (2), command (2), execution (2), powershell (2), enumeration (2), domaingpo (2), domaingpolocalgroup (2), ldap (2), strategy (2), windows (2), analytic (2), description (2), name (2), this (2), attack (2), technique (2), with (2), system (2), discover (2), details (2), turla (2), lunarweb (2), victim (2), australian (2), intrusions (2), various (2), empire (2), identify (2), environment (2), dusttrap (2), t1615 (2), such (2), gather (2), paths (2), network (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, cookie, preferences, website, privacy, terms, contact, reset, filters, faou, agent, btz, comrat, ten, year, journey, jurčacko, moon, back, doors, lunar, landing, diplomatic, missions, cisa, people, republic, china, prc, ministry, state, apt40, tradecraft, action, falcone, miller, osborn, trojan, did, operation, lotus, blossom, cause, evolve, mike, stokkel, apt41, arisen, dust, september, robbins, vazarkar, six, degrees, warner, nelson, github, powershellempire, microsoft, 2017, metcalf, sneaky, persistence, srachui, 2012, basics, part, understanding, structure, object, references, adversary, attempts, enumerate, through, suspicious, abnormal, queries, targeting, grouppolicycontainer, defenders, observe, unusual, process, lineage, script, filter, activity, against, controllers, an0152, det0055, type, cannot, easily, mitigated, preventive, controls, since, based, abuse, features, surveys, upon, check, using, g0010, capture, s1141, performed, extensive, environments, during, c0049, includes, modules, enumerating, s0363, capability, execute, s0082, s1159, ability, collect, local, via, gpo, s0521, procedure, examples, live, permalink, last, modified, created, jonhnathan, ribeiro, 3coresec, _w0rk3r, ted, samuels, rapid7, contributors, platforms, tactic, commands, publicly, available, functions, shape, follow, behaviors, including, determining, potential, target, well, opportunities, manipulate, their, benefit, tenant, modification, privilege, escalation, measures, applied, patterns, that, manipulated, used, blend, allows, centralized, management, user, computer, gpos, containers, made, files, stored, predictable, path, sysvol, policies, home, open, join, mclean, hotel, location, found, register, here, search, blog, contribute, benefactors, legal, branding, updates, history, engage, tools, advisory, council, learn, more, about, started, detections,
Text of the page (random words):
group policy discovery technique t1615 enterprise mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home techniques enterprise group policy discovery group policy discovery adversaries may gather information on group policy settings to identify paths for privilege escalation security measures applied within a domain and to discover patterns in domain objects that can be manipulated or used to blend in the environment group policy allows for centralized management of user and computer settings in active directory ad group policy objects gpos are containers for group policy settings made up of files stored within a predictable network path domain sysvol domain policies 1 2 adversaries may use commands such as gpresult or various publicly available powershell functions such as get domaingpo and get domaingpolocalgroup to gather information on group policy settings 3 4 adversaries may use this information to shape follow on behaviors including determining potential attack paths within the target network as well as opportunities to manipulate group policy settings i e domain or tenant policy modification for their benefit id t1615 sub techniques no sub techniques ⓘ tactic discovery ⓘ platforms windows contributors jonhnathan ribeiro 3coresec _w0rk3r ted samuels rapid7 version 1 1 created 06 august 2021 last modified 24 october 2025 version permalink live version procedure examples id name description s0521 bloodhound bloodhound has the ability to collect local admin information via gpo 5 s1159 dusttrap dusttrap can identify victim environment group policy information 6 s0082 emissary emissary has the capability to execute gpresult 7 s0363 empire empire includes various modules for enumerating group policy 4 c0049 leviathan australian intrusions leviathan performed extensive active directory enumeration of victim environments during leviathan australian intrusions 8 s1141 lunarweb lunarweb can capture information on group policy settings 9 g0010 turla turla surveys a system upon check in to discover group policy details using the gpresult command 10 mitigations this type of attack technique cannot be easily mitigated with preventive controls since it is based on the abuse of system features detection strategy id name analytic id analytic description det0055 detection strategy for group policy discovery on windows an0152 detection of adversary attempts to enumerate group policy settings through suspicious command execution gpresult powershell enumeration get domaingpo get domaingpolocalgroup and abnormal ldap queries targeting grouppolicycontainer objects defenders observe unusual process lineage script execution or ldap filter activity against domain controllers references srachui 2012 february 13 group policy basics part 1 understanding the structure of a group policy object retrieved march 5 2019 metcalf s 2016 march 14 sneaky active directory persistence 17 group policy retrieved march 5 2019 microsoft 2017 october 16 gpresult retrieved august 6 2021 schroeder w warner j nelson m n d github powershellempire retrieved april 28 2016 robbins a vazarkar r and schroeder w 2016 april 17 bloodhound six degrees of domain admin retrieved march 5 2019 mike stokkel et al 2024 july 18 apt41 has arisen from the dust retrieved september 16 2024 falcone r and miller osborn j 2016 february 3 emissary trojan changelog did operation lotus blossom cause it to evolve retrieved february 15 2016 cisa et al 2024 july 8 people s republic of china prc ministry of state security apt40 tradecraft in action retrieved february 3 2025 jurčacko f 2024 may 15 to the moon and back doors lunar landing in diplomatic missions retrieved june 26 2024 faou m 2020 may from agent btz to comrat v4 a ten year journey retrieved june 15 2020 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
|