Group Policy Object Modified - GPO Attribute Modification T1484.001

Detects modifications to sensitive Group Policy Object (GPO) attributes, specifically those related to file system paths, machine/user extensions, or version numbers, using Windows Security Event ID 5136. These attributes are often targeted during GPO modification to establish persistence, escalate privileges, or deploy malicious configurations across a domain.