logo

ARP Around and Find Out: Hijacking GPO UNC Paths for…

ID: 87e4ca55-a523-5d6f-a737-162d52f85a86

STIX ID: report--87e4ca55-a523-5d6f-a737-162d52f85a86

Feed Name: TrustedSec blog

Threat Score
70/100

Date Published: 2026-04-30

Date Updated: 2026-05-01

...
...

This report demonstrates practical TTPs for abusing the Active Directory WriteGPLink permission and UNC-referenced GPO resources to achieve SYSTEM code execution and capture/relay NTLM authentication by combining GPO linking with ARP spoofing; it covers three attacks (MSI deployment spoofing, drive-map spoofing with WebDAV downgrade and NTLM relay, and logon/startup script spoofing), lab procedures, tooling, limitations, and mitigations such as enforcing SMB/LDAP signing, auditing AD ACLs, and hardening layer-2 controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.