Windows Process Creation: Access to Domain Group Policy in SYSVOL

Flags Windows processes that reference SYSVOL \policies paths in their command line.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
Markus Neis, Jonhnathan Ribeiro, oscd.community (SigmaHQ), DRL 1.1
Published
2018-04-09
Updated
2026-07-30

ATT&CK techniques

Cred Access
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

Identifies Windows processes whose command line contains both the SYSVOL path and the policies directory, indicating access to Group Policy content stored in SYSVOL. Attackers and administrators may interact with these locations to enumerate, modify, or stage policy-related files as part of broader domain abuse. The rule relies on process creation telemetry with access to the full command line string.

Related detections4 linkedT1552.006 — drag to rearrange
Malicious Group Policy Preferences Credential Hunting via Findstr by UAT-8837
Suspicious SYSVOL Group Policy Preferences Access via Share Audit
Windows: findstr.exe LSASS keyword matching for process reconnaissance
Windows: Findstr searches GPP cpassword in SYSVOL XML
Windows Process Creation: Access to Domain Group Policy in SYSVOL
Pivot detection · T1552.006 · 4 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.