[OOTB] Group policy hijacked: PAYLOAD ransomware
<html lang="en">
<body>
  
  <p>
	The Group Policy Hijacked: PAYLOAD Ransomware rule package contains rules that detect suspicious creation or modification of files in the SYSVOL share on a domain controller, as well as changes to critical attributes and settings of domain Group Policies. Some rules may require tuning if they trigger on legitimate activity, such as synchronization between domain controllers or the configuration of a new Group Policy.<br>
	For the detection rules to function correctly, ensure that events from Windows systems are collected in full, including events with the following IDs: Sysmon 11 and Security 4663, 5136, 4657.
  </p>

</body>
</html>