ARP Around and Find Out: Hijacking GPO UNC Paths for…
ID: 87e4ca55-a523-5d6f-a737-162d52f85a86
STIX ID: report--87e4ca55-a523-5d6f-a737-162d52f85a86
Feed Name: TrustedSec blog
This report demonstrates practical TTPs for abusing the Active Directory WriteGPLink permission and UNC-referenced GPO resources to achieve SYSTEM code execution and capture/relay NTLM authentication by combining GPO linking with ARP spoofing; it covers three attacks (MSI deployment spoofing, drive-map spoofing with WebDAV downgrade and NTLM relay, and logon/startup script spoofing), lab procedures, tooling, limitations, and mitigations such as enforcing SMB/LDAP signing, auditing AD ACLs, and hardening layer-2 controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
