Suspicious SYSVOL Group Policy Preferences Access via Share Audit

PremiumReviewedSigma · Medium · v1
Product
windows
Service
security
Author
HuntRule
Published
2026-05-23
Updated
2026-08-28

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects a user account reading machine level Group Policy Preferences files under the SYSVOL policies path through Windows detailed file share auditing as described in the WithSecure lab where GPP XML files were targeted for stored credentials. Interactive user access to machine policy XML files under SYSVOL frequently indicates hunting for cpassword secrets which is an early credential access and discovery signal.

Related detections3 linkedT1552.006 — drag to rearrange
Windows: findstr.exe LSASS keyword matching for process reconnaissance
Windows: Findstr searches GPP cpassword in SYSVOL XML
Windows Process Creation: Access to Domain Group Policy in SYSVOL
Suspicious SYSVOL Group Policy Preferences Access via Share Audit
Pivot detection · T1552.006 · 3 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.