03/27/2023 20:59:15.428 dcName=ar-win-dc.attackrange.local admonEventType=Update Names: objectCategory=CN=Group-Policy-Container,CN=Schema,CN=Configuration,DC=attackrange,DC=local name={2C4C7CD3-7AA5-4E84-89B5-CE9FC75611D4} displayName=Malicious GPO distinguishedName=CN={2C4C7CD3-7AA5-4E84-89B5-CE9FC75611D4},CN=Policies,CN=System,DC=attackrange,DC=local cn={2C4C7CD3-7AA5-4E84-89B5-CE9FC75611D4} Object Details: objectGUID=3e7ae4de-29a6-41c1-b27c-bf9548b0444c whenChanged=08:59.15 PM, Mon 03/27/2023 whenCreated=08:59.15 PM, Mon 03/27/2023 objectClass=top|container|groupPolicyContainer Event Details: uSNChanged=90165 uSNCreated=90160 instanceType=4 Additional Details: dSCorePropagationData=16010101000000.0Z gPCFileSysPath=\\attackrange.local\SysVol\attackrange.local\Policies\{2C4C7CD3-7AA5-4E84-89B5-CE9FC75611D4} gPCFunctionalityVersion=2 versionNumber=0 flags=0 showInAdvancedViewOnly=TRUE