gpresult or various publicly available PowerShell functions, such as Get-DomainGPO and Get-DomainGPOLocalGroup, to gather information on Group Policy settings. Adversaries may use this information to shape follow-on behaviors, including determining potential attack paths within the target network as well as opportunities to manipulate Group Policy settings (i.e. [Domain or Tenant Policy Modification](https://attack.mitre.org/techniques/T1484)) for their benefit.| Product | Dependencies | Data source | Access required | Protocol | Data Collected | Notes |
|---|---|---|---|---|---|---|
| Tenable Identity Exposure | Active Directory | Authenticated AD user | LDAP/S(389/636) | Group Policy objects | ||
| Tenable Identity Exposure | Active Directory | Authenticated AD user | LDAP/S(389/636) | Organizational Unit objects | ||
| Tenable Identity Exposure | Active Directory | Standard AD User | LDAP | List of Computers, Domain Users, Groups and Memberships |
Framework: MITRE ATT&CK
Family: Discovery
Technique: Group Policy Discovery
Products Required: Tenable Identity Exposure