Weaponizing Group Policy Objects Access
ID: a20b5d92-5f54-5145-97b3-62626cf638d6
STIX ID: report--a20b5d92-5f54-5145-97b3-62626cf638d6
Feed Name: TrustedSec blog
This report provides a step-by-step offensive technique for abusing Active Directory Group Policy: an attacker with plaintext credentials and SOCKS access can modify a GPO (adding Files.xml and adjusting GPT.ini and gPCMachineExtensionNames extension GUID pairs) to force Domain Controllers to retrieve files from an attacker-controlled share, with the potential to copy and execute binaries. The guide covers required permissions, how to discover and set extension pairs, PowerView commands used, cautions about breaking GPO processing, and defensive recommendations such as auditing GPO permission changes (Event ID 5136) and regularly reviewing GPO permissions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
