Auditing Group Policy And Sysvol Trust

Audit trust placed in group policy content and the domain policy share, where a low-privileged principal can write a policy object, its files on the domain share, or its link, causing that policy to run scripts, set scheduled tasks, install software, or change security settings on every machine the policy applies to, or where a stored credential or an unsigned policy file lets any domain user act on the policy. Use when policy objects, their share files, or their links may be writable by non-administrators or carry stored secrets. Covers writable policy content, writable links and scope, embedded credentials, and unsigned or world-readable policy files. The low-privileged write to policy content or link is the source, the machines applying the policy are the sink, and running attacker-chosen policy on those machines is the bug.

UnboundCompute Updated

File contents

UnboundCompute/security-agent-skills/tree/main/skills/auditing-group-policy-and-sysvol-trust commit 45c563eeae

Frequently asked questions

npx skillmds@latest add unboundcompute/auditing-group-policy-and-sysvol-trust