Ransomware Series: GPO Abuse for Mass Ransomware Deployment

This rule detects the deployment of suspicious executables or scripts (e.g., .exe, .bat, .ps1, .vbs) via Group Policy (GPO) paths or through GPO-related processes like gpscript.exe and gpupdate.exe. This activity is consistent with using GPOs to distribute and execute malicious binaries across a domain, often a precursor to ransomware deployment.