Activity timeline
T1484.001 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 4 reports, and 14 of the 14 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1484.001 Group Policy Modification is catalogued by MITRE ATT&CK under the Privilege Escalation and Defense Impairment tactics in the Enterprise matrix, as a sub-technique of T1484 Domain or Tenant Policy Modification. Threadlinqs maps 14 of 2623 tracked threats (0.5%) to it; by severity that is 5 critical, 7 high, 2 medium.
Threats that use T1484.001 most often also use T1685 Disable or Modify Tools (11 threats), T1190 Exploit Public-Facing Application (10 threats), T1003.001 LSASS Memory (9 threats), T1021.002 SMB/Windows Admin Shares (9 threats), T1059.001 PowerShell (8 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
6 tracked threat actors appear in the threats that use T1484.001; the most frequent are Qilin (2), Storm-2603 (2), The Gentlemen (2), Akira (1), Static Tundra (1).
Mitigations
MITRE ATT&CK lists 2 mitigations for T1484.001.
Data sources
Telemetry that can reveal T1484.001, per MITRE ATT&CK.
- Active Directory — Active Directory Object Creation, Active Directory Object Deletion, Active Directory Object Modification
- Command — Command Execution
Threat actors using it
Tracked threats
14 tracked threats use T1484.001.
- Warlock Ransomware Attackers Hit Water and Telecom Operators via SharePoint ToolShell Exploitation (Longlegs…critical
- Microsoft Defender Antivirus Exclusion Abuse: Attackers Set and Hide Exclusions…medium
- Ransomware Incidents Surge 4.7% in Japan H1 2026: The Gentlemen and Qilin Lead, AI-Assisted Tooling Observedhigh
- ORB Networks and Nation-State CNI Targeting: Destructive Wiper Attack on Polish Energy Infrastructure via…high
- Qilin Ransomware Group Claims Cyberattack on ATF (DOJ) — Standalone Investigation-Target System Breached…high
- "Download More RAM" Attack Bypasses Windows VBS and Disables Defender Through Memory Aliasing (CVE-2026-23670)medium
- CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV Catalogcritical
- The Gentlemen RaaS overtakes Qilin as #1 ransomware operation, wields GentleKiller EDR-killer framework…high
- The Gentlemen Ransomware: Worm-Like Self-Propagation and Network-Wide Encryption via Storm-2697's RaaS…critical
- CVE-2026-45659: SharePoint Deserialization RCE Added to CISA KEV Amid Storm-2603 Exploitationhigh
- Akira Ransomware Kill Chain — SSLVPN Credential Stuffing → Kerberoasting → RDP Lateral → vssadmin Shadow…high
- SHADOW-AETHER-040 & SHADOW-AETHER-064 — Agentic AI-Driven Intrusion Campaigns Targeting LATAM Government and…critical
- Qilin (Agenda) Ransomware Hits Romanian Oil Pipeline Operator Conpet — 4,000km Critical Infrastructure, ~1TB…critical
- BaBlock/Rorschach Ransomware Hits Sapienza University of Rome — Femwar02 Affiliate First Appearance, Fastest…high
Detection coverage
Threadlinqs maintains 37 detection rules mapped to T1484.001 (SPL 8, KQL 17, Sigma 12). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1484 Domain or Tenant Policy Modification — 30 tracked threats at the technique level.