Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Defense Evasion/ T1484

T1484Domain or Tenant Policy Modification

T1484 — Domain or Tenant Policy Modification is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 12 detection use cases covering it.

Defense EvasionPrivilege Escalation
View on the matrix → Filter Detection Library MITRE official spec ↗
12Use cases
0Articles
2Sub-techniques
2Tactics

Sub-techniques (2)

Use cases covering this technique (12)

Microsoft Intune DeviceManagementConfigurationPolicies ESCU actions · hunting P Active Directory Privilege Escalation Identified ESCU actions · alerting P Windows AD Dangerous Deny ACL Modification ESCU actions · alerting P Windows AD Dangerous Group ACL Modification ESCU actions · alerting P Windows AD Dangerous User ACL Modification ESCU actions · alerting P Windows AD DCShadow Privileges ACL Addition ESCU actions · alerting P Windows AD Domain Replication ACL Addition ESCU actions · alerting P Windows AD Domain Root ACL Deletion ESCU actions · alerting P Windows AD Domain Root ACL Modification ESCU actions · alerting P Windows AD Hidden OU Creation ESCU actions · alerting P Windows AD Object Owner Updated ESCU actions · alerting P Windows AD Self DACL Assignment ESCU actions · alerting P