Windows: GPO Modification Adds Startup/Logon Script References

Flags GPO changes that add startup/logon scripts (SYSVOL scripts.ini) for user or computer targets using Windows directory/audit events.

FreeReviewedSigma · Medium · v2
Product
windows
Service
security
Author
Elastic, Josh Nickels, Marius Rothenbücher (SigmaHQ), DRL 1.1
Published
2024-09-06
Updated
2026-07-31

ATT&CK techniques

Persistence → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Cred Access

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule identifies Windows Security events where a Group Policy Object is modified to add or reference startup/logon script entries for either computer or user extensions. Attackers commonly abuse GPO script mechanisms to establish persistence and run code in the context of targeted accounts or machines. The detection relies on object access events (EventID 5136/5145) along with LDAP attribute names and values that match known script-related identifiers, and on SYSVOL path targets pointing to scripts.ini or psscripts.ini.

Related detections9 linkedT1484.001 — drag to rearrange
Suspicious Boot Verification Program Persistence via Registry (via registry_set)
Suspicious Modification of a Sensitive Group Policy - GPO (via security)
SwimSnake Driver Execution Persistence via Session Manager PlatformExecute (via registry_set)
Suspicious Group Policy File System Path Redirection via Directory Service Change
Malicious GPO Permission Abuse via SharpGPOAbuse
Suspicious Session Manager Execute Value Modification for Persistence (via registry_set)
Suspicious Executable Launched from SYSVOL Share
Suspicious RDP Wds StartupPrograms Persistence Modification (via registry_set)
Malicious SharpGPOAbuse GPO Modification Tool from Public Directory
Windows: GPO Modification Adds Startup/Logon Script References
Pivot detection · T1484.001 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.