Gpo Abuse

Exploits Group Policy Objects for code execution, privilege escalation, and lateral movement in Active Directory. Covers GPO enumeration (GPOHound, BloodHound, PowerView), exploitation via immediate tasks, logon scripts, and registry modifications (SharpGPOAbuse, PowerGPOAbuse, pyGPOAbuse, GroupPolicyBackdoor), SYSVOL/NETLOGON logon script poisoning, and GPP password extraction.

blacklanternsecurity 09a0011 15.4 KB Updated

File contents

blacklanternsecurity/red-run/tree/main/skills/ad/gpo-abuse commit 09a0011d3e

Frequently asked questions

npx skillmds@latest add blacklanternsecurity/gpo-abuse