Rules Contributing to Startup/Logon Script Added to Group Policy Object Alert

The following rules detect suspicious SMB traffic related to GPO script modifications. Any one or more of these will trigger the Startup/Logon Script Added to Group Policy Object Alert. Details for each rule can be viewed by clicking the More Details link in the description.

Title

Description

Startup/Logon Script added to Group Policy Object

Detects the modification of Group Policy Objects (GPO) to add a startup/logon script to users or computer objects.