Windows PowerShell: Suspicious GPO Discovery via Get-GPO

Detects PowerShell script blocks using Get-GPO to enumerate domain Group Policy Objects.

FreeReviewedSigma · Low · v2
Product
windows
Category
ps_script
Author
frack113 (SigmaHQ), DRL 1.1
Published
2022-06-04
Updated
2026-07-31

ATT&CK techniques

Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags PowerShell script block text containing Get-GPO, indicating an attempt to enumerate Group Policy Objects in a domain. Attackers often use GPO discovery to understand configuration and identify misconfigurations or targets for later abuse. It relies on script block logging telemetry capturing PowerShell code executed on Windows.

Related detections4 linkedT1615 — drag to rearrange
Suspicious Windows Process Execution of gatherNetworkInfo.vbs via Cscript/Wscript
Windows: SharpUp (SharpUp.exe) Local Privilege Escalation Tool Execution
Windows Process Creation: gpresult.exe Group Policy (RSoP) Discovery (/z /v)
Windows Process Creation: cscript/wscript Running gatherNetworkInfo.vbs
Windows PowerShell: Suspicious GPO Discovery via Get-GPO
Pivot detection · T1615 · 4 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.