Windows Security: Group Policy Object modification adds privileges to user accounts

Alerts on Windows GPO attribute changes that correspond to adding privileges or making users local admins.

FreeReviewedSigma · Medium · v2
Product
windows
Service
security
Author
Elastic, Josh Nickels, Marius Rothenbücher (SigmaHQ), DRL 1.1
Published
2024-09-04
Updated
2026-07-31

ATT&CK techniques

Priv Esc → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags the first observed Windows Security event (EventID 5136) where a Group Policy Object attribute related to machine extension names is modified. The matched attribute values indicate changes consistent with adding privileges to user accounts or using Group Policy to add users as local administrators. It relies on directory service change auditing telemetry that records LDAP object attribute modifications, including the actor identity (SubjectUserName) and the modified attribute/value details.

Related detections9 linkedT1484.001 — drag to rearrange
Suspicious Modification of a Sensitive Group Policy - GPO (via security)
Suspicious Group Policy File System Path Redirection via Directory Service Change
Malicious GPO Permission Abuse via SharpGPOAbuse
Suspicious Executable Launched from SYSVOL Share
Malicious SharpGPOAbuse GPO Modification Tool from Public Directory
Suspicious Permissions Changed on a Group Policy - GPO (via security)
Suspicious Executable Launched from Domain Netlogon Share (via process_creation)
Windows Process: GPME Used to Modify Default Domain and Default Domain Controllers GPOs
Windows Security Event 5136 for Changes to Default Domain and Default Domain Controllers GPOs
Windows Security: Group Policy Object modification adds privileges to user accounts
Pivot detection · T1484.001 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.