{"id":"e56d3073-83ff-4021-90fe-c658e0709e72","title":"Gpresult Display Group Policy Information","description":"Detects cases in which a user uses the built-in Windows utility gpresult to display the Resultant Set of Policy (RSoP) information","author":"frack113","status":"test","level":"medium","date":"2022-05-01","modified":"","tags":["attack.discovery","attack.t1615"],"technique_ids":["T1615"],"logsource":{"product":"windows","category":"process_creation"},"falsepositives":["Unknown"],"references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1615/T1615.md","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/gpresult","https://unit42.paloaltonetworks.com/emissary-trojan-changelog-did-operation-lotus-blossom-cause-it-to-evolve/","https://www.welivesecurity.com/wp-content/uploads/2020/05/ESET_Turla_ComRAT.pdf"],"source_path":"rules/windows/process_creation/proc_creation_win_gpresult_execution.yml","source_sha256":"b8bda339b93e260e7f2e2b6bc82e5d18d130eaf3efb768642b3789e80598296c","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/process_creation/proc_creation_win_gpresult_execution.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: Gpresult Display Group Policy Information\nid: e56d3073-83ff-4021-90fe-c658e0709e72\nstatus: test\ndescription: Detects cases in which a user uses the built-in Windows utility gpresult to display the Resultant Set of Policy (RSoP) information\nreferences:\n    - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1615/T1615.md\n    - https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/gpresult\n    - https://unit42.paloaltonetworks.com/emissary-trojan-changelog-did-operation-lotus-blossom-cause-it-to-evolve/\n    - https://www.welivesecurity.com/wp-content/uploads/2020/05/ESET_Turla_ComRAT.pdf\nauthor: frack113\ndate: 2022-05-01\ntags:\n    - attack.discovery\n    - attack.t1615\nlogsource:\n    product: windows\n    category: process_creation\ndetection:\n    selection:\n        Image|endswith: '\\gpresult.exe'\n        CommandLine|contains:\n            - '/z'\n            - '/v'\n    condition: selection\nfalsepositives:\n    - Unknown\nlevel: medium\nsimulation:\n    - type: atomic-red-team\n      name: Display group policy information via gpresult\n      technique: T1615\n      atomic_guid: 0976990f-53b1-4d3f-a185-6df5be429d3b\nregression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_gpresult_execution/info.yml\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1615","id":"T1615","name":"Group Policy Discovery","page":"techniques/enterprise/T1615/"}],"data_path":"data/detection-rules/e56d3073-83ff-4021-90fe-c658e0709e72.json","kind":"sigma"}
