Windows PowerShell: GPO ScriptBlock Modifying Group Policy and SmartScreen Settings

Alerts on PowerShell ScriptBlock content referencing Group Policy policy keys and specific security policy value names.

FreeReviewedSigma · Medium · v2
Product
windows
Category
ps_script
Author
frack113 (SigmaHQ), DRL 1.1
Published
2022-08-19
Updated
2026-07-31

ATT&CK techniques

Priv Esc → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule identifies PowerShell activity containing registry policy paths and specific group policy-related values, including Group Policy refresh timing and SmartScreen configuration. Attackers can use GPO modifications to impair defenses or enforce malicious settings across systems, making this a high-signal defense-impairment indicator. The detection relies on Script Block Logging telemetry by matching specific substrings within captured ScriptBlockText.

Related detections9 linkedT1484.001 — drag to rearrange
Suspicious Modification of a Sensitive Group Policy - GPO (via security)
Suspicious Group Policy File System Path Redirection via Directory Service Change
Malicious GPO Permission Abuse via SharpGPOAbuse
Suspicious Executable Launched from SYSVOL Share
Malicious SharpGPOAbuse GPO Modification Tool from Public Directory
Suspicious Permissions Changed on a Group Policy - GPO (via security)
Suspicious Executable Launched from Domain Netlogon Share (via process_creation)
Windows Process: GPME Used to Modify Default Domain and Default Domain Controllers GPOs
Windows Security Event 5136 for Changes to Default Domain and Default Domain Controllers GPOs
Windows PowerShell: GPO ScriptBlock Modifying Group Policy and SmartScreen Settings
Pivot detection · T1484.001 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.