Group Policy Abuse Detection

This rule detects potential abuse of Group Policy Objects (GPOs) by identifying multiple changes (3 or more) to GPO-related objects within a short timeframe. It specifically looks for Event ID 5136 (Directory Service Changes) where the ObjectClass is either 'groupPolicyContainer' or 'gPCFileSysPath'. This could indicate an adversary modifying GPOs to achieve persistence, privilege escalation, or other malicious objectives.