logo

Weaponizing Group Policy Objects Access

ID: a20b5d92-5f54-5145-97b3-62626cf638d6

STIX ID: report--a20b5d92-5f54-5145-97b3-62626cf638d6

Feed Name: TrustedSec blog

Threat Score
70/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

This report provides a step-by-step offensive technique for abusing Active Directory Group Policy: an attacker with plaintext credentials and SOCKS access can modify a GPO (adding Files.xml and adjusting GPT.ini and gPCMachineExtensionNames extension GUID pairs) to force Domain Controllers to retrieve files from an attacker-controlled share, with the potential to copy and execute binaries. The guide covers required permissions, how to discover and set extension pairs, PowerView commands used, cautions about breaking GPO processing, and defensive recommendations such as auditing GPO permission changes (Event ID 5136) and regularly reviewing GPO permissions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.