Gentlemen Ransomware GPO Manipulation - Domain-Wide Deployment via gpupdate/gpedit or AD EventCode 5136

This rule monitors for two distinct behaviors: direct modification of Group Policy Object (GPO) containers within Active Directory and suspicious execution of GPO management tools (gpupdate.exe or gpedit.msc) across multiple hosts in a short timeframe. AD modification events are flagged as critical, while elevated tool execution patterns are flagged as high or medium risk based on host prevalence.