Hide the threat – GPO lateral movement
ID: b119a30d-35ef-5f32-bb81-e5d098adcd8f
STIX ID: report--b119a30d-35ef-5f32-bb81-e5d098adcd8f
Feed Name: Intrinsec Blog
This technical guide details controlled use of Active Directory Group Policy Objects for lateral movement and privilege changes, contrasting in-script filtering, item-level targeting, and security filtering, and walking through manual and tool-assisted (SharpGPO, GroupPolicyBackdoor, SharpGPOAbuse) creation, configuration, and linking of GPOs; it highlights relevant SYSVOL artifacts (`Groups.xml`, `Registry.pol`, `GptTmpl.inf`) and validation with `gpresult`, emphasizing precise scoping to specific hosts while noting that detection considerations are out of scope.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
