GPP cpassword exposure: SYSVOL file access or extraction tool usage

Detects unauthorized access or decryption attempts related to Group Policy Preferences (GPP) files stored in the SYSVOL share. Attackers often target these files to retrieve credentials stored in the 'cpassword' attribute, which can be decrypted using publicly known keys.