Living off the land, GPO style
ID: e7600c9b-a79b-518d-b352-06e34d9c1515
STIX ID: report--e7600c9b-a79b-518d-b352-06e34d9c1515
Feed Name: Pen Test Partners Blog
This research post demonstrates how to edit Active Directory Group Policy Objects from a non-domain-joined system using native Windows MMC snap-ins by injecting C# EasyHook-based hooks (DGPOEdit) that spoof domain context (intercepting GetUserNameEx) and transparently rewrite DFS-based SYSVOL paths to a specific domain controller at the NtCreateFile layer. The approach maintains use of native tooling, leverages Kerberos tickets, and avoids modifying hosts files or custom open-source tools, enabling reliable off-domain GPO management despite the snap-ins’ domain-join checks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
