Ransomware Series: GPO Abuse for Mass Ransomware Deployment via Startup Script or Scheduled Task

Detects unauthorized modifications to Group Policy Objects (GPO) involving critical attributes (such as SYSVOL paths or extension configurations) combined with the creation of new script or executable files in the SYSVOL Scripts folder. This behavior is indicative of potential GPO tampering to gain persistence or facilitate large-scale execution, such as ransomware deployment via GPOs.