Group Policy objects (GPOs) push configuration (and, usefully for an attacker, scheduled tasks, scripts, and group membership) to the users and computers they are linked to. A principal who can edit a GPO can run code on everything that GPO applies to. Enumeration here answers three questions: what GPOs exist, what they are linked to (so you know the blast radius), and who can modify them.
Mapping GPOs to their targets#
GPOs are linked to sites, domains, and organizational units via the gPLink attribute on the container. To know who a GPO affects, map GPO to link to the objects under that container:
# PowerView
Get-DomainGPO -Properties displayname,gpcfilesyspath
Get-DomainOU -Properties name,gplink
Get-DomainGPO -Identity '{GUID}' | Get-DomainOU # resolve a GPO to its linked OUs
Get-DomainComputer -SearchBase 'OU=Workstations,DC=example,DC=local' # who is under that OU
# From Linux
nxc ldap <dc> -u user -p pass --gpo
ldapsearch ... '(objectClass=groupPolicyContainer)' displayName gPCFileSysPath
The gPCFileSysPath points at the GPO's files in SYSVOL (\\domain\SYSVOL\domain\Policies\{GUID}), readable by any domain user, which is where Group Policy Preferences passwords historically leaked.
Finding editable GPOs#
The escalation path is a GPO whose DACL grants a principal you control write access (WriteProperty/GenericWrite/GenericAll). Enumerate GPO permissions the same way as any object ACL:
Get-DomainGPO | Get-DomainObjectAcl -ResolveGUIDs |
? { $_.ActiveDirectoryRights -match 'WriteProperty|GenericWrite|GenericAll' }
BloodHound draws this as a GenericWrite/GPOAbuse edge from the principal to the GPO, and then shows every computer and user the GPO reaches.
Exploitation notes#
- Prioritize GPOs linked to OUs that contain privileged or many computers; editing a GPO linked to a Domain Controllers OU is domain-critical.
- A readable
SYSVOLpolicy tree is worth grepping forcpassword(Group Policy Preferences) and for scripts referencing credentials. - Enumeration identifies the editable, high-reach GPO; the actual abuse (immediate scheduled task, script, or group membership push) is covered in the Group Policy section.
Tools#
- PowerView
Get-DomainGPO/Get-DomainOU: GPO and OU mapping with ACLs. - NetExec (nxc) ldap --gpo: GPO listing from Linux.
- BloodHound: GPO-to-target reach and editable-GPO edges.
References#
- The Hacker Recipes: Group policies
- Microsoft: Group Policy architecture and gPLink