{
  "id": "839f5014-636c-4a8d-9439-69996d3904b2",
  "name": "[OOTB] Group policy hijacked: PAYLOAD ransomware",
  "version": 1,
  "releasedAt": 1789736764202,
  "changelogs": [
    {
      "version": 1,
      "released_at": "2026-09-18T13:06:04Z",
      "items": [
        {
          "text": {
            "en": "Initial release",
            "ru": "Первый релиз"
          }
        }
      ]
    }
    ],
  "description": "The Group Policy Hijacked: PAYLOAD Ransomware rule package contains rules that detect suspicious creation or modification of files in the SYSVOL share on a domain controller, as well as changes to critical attributes and settings of domain Group Policies. Some rules may require tuning if they trigger on legitimate activity, such as synchronization between domain controllers or the configuration of a new Group Policy.\nFor the detection rules to function correctly, ensure that events from Windows systems are collected in full, including events with the following IDs: Sysmon 11 and Security 4663, 5136, 4657.",
  "localization": {
    "ru": {
      "description": "Пакет Group policy hijacked: PAYLOAD ransomware содержит правила, детектирующие подозрительное создание или изменение файлов в общей папке sysvol на контроллере домена, изменение критичных атрибутов и настроек групповых политик домена. Некоторые правила могут потребовать корректировки в случае срабатывания на легитимную активность, например, синхронизация между контроллерами домена и настройка новой групповой политики.\nДля корректной работы правил обнаружения необходимо убедиться, что события с Windows-систем поступают в полном объеме, включая события с идентификаторами: Sysmon 11 и Security 4663, 5136, 4657."
    }
  },
  "resourceIds": [
    "61c86f4d-322c-453a-9d02-1001a90de3b5",
    "638f07f3-a1ec-4880-b73f-0d3212d9700c",
    "ef7fdad3-890f-4d00-afc1-c8b4fe8612e3"
  ],
  "emergency": true
}

