Windows: Findstr searches GPP cpassword in SYSVOL XML

Alerts when Windows findstr/find searches SYSVOL XML files for GPP cpassword.

FreeReviewedSigma · High · v2
Product
windows
Category
process_creation
Author
frack113 (SigmaHQ), DRL 1.1
Published
2021-12-27
Updated
2026-07-31

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies Windows process executions where find.exe or findstr.exe are used to search for the string "cpassword" within SYSVOL Group Policy XML files. Attackers can use the exposed encrypted cpassword value to recover credentials with tools that decrypt GPP passwords. The detection relies on process creation telemetry, matching the executable name and the presence of specific command-line substrings (.xml, \sysvol\, and cpassword).

Related detections4 linkedT1552.006 — drag to rearrange
Malicious Group Policy Preferences Credential Hunting via Findstr by UAT-8837
Suspicious SYSVOL Group Policy Preferences Access via Share Audit
Windows: findstr.exe LSASS keyword matching for process reconnaissance
Windows Process Creation: Access to Domain Group Policy in SYSVOL
Windows: Findstr searches GPP cpassword in SYSVOL XML
Pivot detection · T1552.006 · 4 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.