Windows Process Creation: gpresult.exe Group Policy (RSoP) Discovery (/z /v)

Flags process executions of gpresult.exe that request RSoP details using /z and /v on Windows.

FreeReviewedSigma · Medium · v2
Product
windows
Category
process_creation
Author
frack113 (SigmaHQ), DRL 1.1
Published
2022-05-01
Updated
2026-07-31

ATT&CK techniques

Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags process creation events where gpresult.exe is executed with parameters used to display the Resultant Set of Policy (RSoP) output. Attackers may use this information to understand effective Group Policy settings on a host and guide further discovery or targeting. The detection relies on Windows command-line telemetry to match gpresult.exe execution with the expected /z and /v arguments.

Related detections4 linkedT1615 — drag to rearrange
Suspicious Windows Process Execution of gatherNetworkInfo.vbs via Cscript/Wscript
Windows: SharpUp (SharpUp.exe) Local Privilege Escalation Tool Execution
Windows PowerShell: Suspicious GPO Discovery via Get-GPO
Windows Process Creation: cscript/wscript Running gatherNetworkInfo.vbs
Windows Process Creation: gpresult.exe Group Policy (RSoP) Discovery (/z /v)
Pivot detection · T1615 · 4 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.