Malicious Group Policy Preferences Credential Hunting via Findstr by UAT-8837

PremiumReviewedSigma · High · v1
Category
process_creation
Author
HuntRule
Published
2026-09-11
Updated
2026-09-11

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects use of findstr to recursively search policy files for the cpassword attribute. UAT-8837 harvests Group Policy Preferences passwords which can be decrypted with a publicly known AES key. Locating cpassword values yields reusable domain credentials for privilege escalation and lateral movement.

Related detections4 linkedT1552.006 — drag to rearrange
Suspicious SYSVOL Group Policy Preferences Access via Share Audit
Windows: findstr.exe LSASS keyword matching for process reconnaissance
Windows: Findstr searches GPP cpassword in SYSVOL XML
Windows Process Creation: Access to Domain Group Policy in SYSVOL
Malicious Group Policy Preferences Credential Hunting via Findstr by UAT-8837
Pivot detection · T1552.006 · 4 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.