Domain or Tenant Policy Modification T1484

Tactics: Defense Impairment, Privilege Escalation

Adversaries may modify the configuration settings of a domain or identity tenant to evade defenses and/or escalate privileges in centrally managed environments. Such services provide a centralized means of managing identity resources such as devices and accounts, and often include configuration settings that may apply between domains or tenants such as trust relationships, identity syncing, or identity federation.

Events covered

10 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 95 rules share fields, values, and exclusions.

Fields filtered most (107 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventID32eq 30, in 25136, 5137, 5145, 4662, 4688
EventType28eq 22, in 5, ne 1change_application_setting, UPDATE, add-federateddomain, add_trusted_domains, create_application_setting
data_stream.dataset25eq 25o365.audit, google_workspace.admin, okta.system, aws.cloudtrail, azure.auditlogs
Channel16eq 16, in 16
eventtype16eq 16
AttributeLDAPDisplayName13eq 13gpcmachineextensionnames, gpcuserextensionnames, versionnumber, displayname, dsheuristics
ObjectClass13eq 13grouppolicycontainer, domaindns, group, organizationalunit, user
event.outcome13eq 13success
Action12contains 11, eq 1*, cloudformation:*, cloudformation:create*, cloudformation:createstack, datapipeline:*
Effect12eq 12allow
Provider_Name12eq 9, in 3exchange, iam.amazonaws.com, microsoftteams, skypeforbusiness, onedrive
Resource12eq 12*
aws::eventName12in 12AttachGroupPolicy, AttachRolePolicy, AttachUserPolicy
Condition11eq 11
aws::errorCode11is_null 11

Top indicator values (398 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
EventIDeq
5136
2445
EventIDeq
5137
414
event.outcomeeq
success
13369
Effecteq
allow
1226
Resourceeq
*
1223
aws::eventNamein
AttachGroupPolicy
1217
aws::eventNamein
AttachRolePolicy
1217
aws::eventNamein
AttachUserPolicy
1217
aws::eventNamein
CreatePolicy
1214
aws::eventNamein
CreatePolicyVersion
1214
data_stream.dataseteq
o365.audit
947
data_stream.dataseteq
google_workspace.admin
618
data_stream.dataseteq
okta.system
648
event.categoryeq
web
820
AttributeLDAPDisplayNameeq
gpcmachineextensionnames
67
AttributeLDAPDisplayNameeq
gpcuserextensionnames
34
ObjectClasseq
grouppolicycontainer
66
ObjectClasseq
domaindns
44
Actioncontains
iam:*
510
Actioncontains
iam:passrole
510
Activitycontains
modified
510
Provider_Nameeq
exchange
517
admonEventTypeeq
update
55
EventDatacontains
"operationtype">%%14674
47
EventDatacontains
;0]
44
EventDatacontains
;1]
44
EventDatacontains
;2]
44
EventDatacontains
<data name="attributeldapdisplayname">gplink</data>
44
OperationTypeeq
%%14674
417
AccessListcontains
%%4417
311

Exclusions (32 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
new_aceeq
old_values
8
ProviderNamecontains
asi
2
aceTypein
*denied*
2
aceTypein
d
2
aceTypein
od
2
aceTypein
xd
2
AlertNamecontains
0275
1
AlertNamecontains
0297
1
AttributeValueeq
0
1
EventDatacontains
gc_service.exe
1
EventDatacontains
gc_worker.exe
1
EventDataregex_match
(?i)OU=Domain Controllers
1
EventDataregex_match
(?i)OU=Tier 0 Member Servers
1
EventDataregex_match
(?i)OU=Tier 1 Member Servers
1
EventDataregex_match
(?i)OU=Tier 2 End-User Accounts
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 11 rules

Elastic 31 rules

Splunk 25 rules

Kusto 23 rules

YARA-L 1 rule

Panther 4 rules