GPO Abuse
Group Policy Objects
PS > Get-ADComputer -Filter * | % {Invoke-GPUpdate -Computer $_.name -Force -RandomDelayInMinutes 0}Hunt for GPOs
PS > .\SharpView.exe Get-DomainGPO -Properties displayNamePS > .\SharpView.exe Get-DomainGPO -UserIdentity snovvcrash -Properties DisplayName
PS > .\SharpView.exe Get-DomainGPO -ComputerIdentity WS01 -Properties DisplayName
Or
Cmd > gpresult /r /user snovvcrash [/h gpos-snovvcrash.html]
Cmd > gpresult /r /s WS01 [/h gpos-ws01.html]Permissions Abuse
Recon
Immediate Scheduled Tasks
GPOImmediateTask
GPOwned + pyGPOAbuse
GPPrefRegistryValue
WMI Filters
GPO Abuse via NTLM Relay
Tools
GroupPolicyBackdoor
Last updated