| ID | Name |
|---|---|
| ATAGS-T1081.001 | Group Policy Modification |
| ATAGS-T1081.002 | Trust Modification |
Threat Actors may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a domain, usually with the intention of escalating privileges on the domain. Group policy allows for centralized management of user and computer settings in Active Directory (AD). GPOs are containers for group policy settings made up of files stored within a predictable network path \
This type of attack technique cannot be easily mitigated with preventive controls since it is based on the abuse of system features.