GPOddity

GPOddityarrow-up-right combines NTLM relaying with the modification of a GPO:

  1. The target user has WriteDACL over a GPO

  2. Relay credentials of the target user for modifying the path of the GP template (gPCFileSysPath)

  3. Load a malicious template from an attacker-controlled location

The GPOddity attack (image taken from the CRTParrow-up-right course).

The target user has WriteDACL over a GPO:

Last updated

Was this helpful?