[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fu4qW6M0FUlM5oXT0MzLWK8aRMTzIL3YAosv8C_f4CYw":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},1004,"What are the two main exploitation approaches for remote execution via GPO scheduled tasks?","If you have domain administrator privileges or edit permissions on a GPO, you can either (1) create a new GPO with a malicious scheduled task, or (2) modify an existing GPO that already contains scheduled tasks by replacing the `ScheduledTasks.xml` file. Both approaches require forcing a client policy refresh (e.g., `Invoke-GPUpdate`) and later cleaning up traces. The prerequisite is control over GPO editing, often achieved after domain compromise.","\u003Cp>If you have domain administrator privileges or edit permissions on a GPO, you can either (1) create a new GPO with a malicious scheduled task, or (2) modify an existing GPO that already contains scheduled tasks by replacing the `ScheduledTasks.xml` file. Both approaches require forcing a client policy refresh (e.g., `Invoke-GPUpdate`) and later cleaning up traces. The prerequisite is control over GPO editing, often achieved after domain compromise.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fdomain-penetration-remote-execution-via-scheduled-tasks-in-gpo\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-are-the-two-main-exploitation-approaches-for-remote-execution-via-gpo-sched-1777481110004","exploitation, GPO modification, ScheduledTasks.xml, Invoke-GPUpdate, domain penetration",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},246,"Domain Penetration - Remote Execution via Scheduled Tasks in GPO","domain-penetration-remote-execution-via-scheduled-tasks-in-gpo","Learn how to exploit GPO scheduled tasks for remote execution in domain environments, covering GPMC, command-line methods, and Group Policy refresh techniques.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In a previous article, \"Penetration Basics - Using Scheduled Tasks in Windows,\" the usage of scheduled tasks was introduced. In a domain environment, remote execution of scheduled tasks can also be achieved through Group Policy Objects (GPO). This article will introduce this method and analyze exploitation approaches.\u003C\u002Fp>\u003Ch2>0x01 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to Scheduled Tasks in GPO\u003C\u002Fli>\u003Cli>Remote Execution of Scheduled Tasks via Group Policy Management Console (GPMC)\u003C\u002Fli>\u003Cli>Remote Execution of Scheduled Tasks via Command Line\u003C\u002Fli>\u003Cli>Creating a New GPO for Remote Execution\u003C\u002Fli>\u003Cli>Modifying an Existing GPO for Remote Execution\u003C\u002Fli>\u003Cli>Common Operations on GPO\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recommended reading materials:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.harmj0y.net\u002Fblog\u002Fredteaming\u002Fabusing-gpo-permissions\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fadsecurity.org\u002F?p=2716\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.sicherheitsforschung-magdeburg.de\u002Fuploads\u002Fjournal\u002FMJS_052_Willi_GPO.pdf\u003C\u002Fp>\u003Cp>GPO stands for Group Policy Objects, used to store policies in Active Directory.\u003C\u002Fp>\u003Cp>Starting from Windows Server 2008, GPO began supporting scheduled tasks, facilitating the management of computers and users in the domain.\u003C\u002Fp>\u003Cp>By default, group policies for domain users are updated every 90 minutes with a random offset of 0-30 minutes, while group policies for domain controllers are updated every 5 minutes.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Group policies can be forced to update via command.\u003C\u002Fp>\u003Cp>Default group policy storage location: \\\\\u003Cdomain>\\SYSVOL\\\u003Cdomain>\\Policies\\, accessible by all hosts within the domain.\u003C\u002Fdomain>\u003C\u002Fdomain>\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>A previous article, 'Domain Penetration - Restoring Passwords Saved in Group Policies via SYSVOL', introduced this file location.\u003C\u002Fp>\u003Cp>There are two default group policies, each corresponding to a folder:\u003C\u002Fp>\u003Cp>{6AC1786C-016F-11D2-945F-00C04fB984F9} corresponds to Default Domain Controllers Policy\u003C\u002Fp>\u003Cp>{31B2F340-016D-11D2-945F-00C04FB984F9} corresponds to Default Domain Policy\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016178928_0_f38bfb417c.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Remote Execution of Scheduled Tasks via Group Policy Management Console (GPMC)\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>On the domain controller, location: Administrative Tools -&gt; Group Policy Management\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016181424_1_8419120247.jpeg\">\u003C\u002Fp>\u003Cp>Select the domain test.local, right-click, select the first option, create a GPO, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016182408_2_3bc197e2f7.jpeg\">\u003C\u002Fp>\u003Cp>Enter the name TestGPO1, which creates a global GPO that applies to all domain users\u003C\u002Fp>\u003Cp>Select TestGPO1, right-click, Edit...\u003C\u002Fp>\u003Cp>User Configuration -&gt; Preferences -&gt; Control Panel Settings -&gt; Scheduled Tasks\u003C\u002Fp>\u003Cp>New -&gt; Immediate Task (Windows Vista and later), as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016183329_3_6d84448f0f.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Immediate Tasks are executed each time Group Policy refreshes.\u003C\u002Fp>\u003Cp>For differences between the four types of scheduled tasks, refer to the official documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fprevious-versions\u002Fwindows\u002Fit-pro\u002Fwindows-server-2008-R2-and-2008\u002Fcc770904(v%3dws.11)\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>You can also navigate to Computer Configuration -&gt; Preferences -&gt; Control Panel Settings -&gt; Scheduled Tasks\u003C\u002Fp>\u003Cp>Next, set up the scheduled task according to the prompts.\u003C\u002Fp>\u003Cp>For testing convenience, the action performed outputs the execution result to a file, as shown below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016184679_4_b20e63537c.jpeg\">\u003C\u002Fp>\u003Cp>The Group Policy Object (GPO) corresponding to this has the ID {7D85A2EF-F525-4D8C-B12D-F2825F3A1224}. The configuration information for the scheduled tasks is stored in the file ScheduledTasks.xml located at \\\\test.com\\SYSVOL\\test.com\\Policies\\{7D85A2EF-F525-4D8C-B12D-F2825F3A1224}\\User\\Preferences\\ScheduledTasks.\u003C\u002Fp>\u003Cp>For domain-joined hosts, you can wait 90 minutes for Group Policy to update automatically, or execute the following command on the client to force a Group Policy refresh:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gpupdate \u002Fforce\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The default method for clients to update Group Policy:\u003C\u002Fp>\u003Cp>Reads the version of the Group Policy from the domain shared directory at \\\\\u003Cdomain.com>\\Policies\\\u003Cgpo id=\"\">\\GPT.ini. If this version is higher than the locally stored Group Policy version, the client will update its local Group Policy.\u003C\u002Fgpo>\u003C\u002Fdomain.com>\u003C\u002Fp>\u003Cp>Each time Group Policy is modified, the Version in \\\\\u003Cdomain.com>\\Policies\\\u003Cgpo id=\"\">\\GPT.ini is incremented.\u003C\u002Fgpo>\u003C\u002Fdomain.com>\u003C\u002Fp>\u003Cp>If the domain controller forces a client to refresh Group Policy, it will not compare the version from the domain shared directory.\u003C\u002Fp>\u003Ch2>0x04 Remote execution of scheduled tasks via command line\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Domain Controller System: Windows Server 2012 R2 x64\u003C\u002Fp>\u003Cp>Domain Name: test.com\u003C\u002Fp>\u003Ch3>1. Create a GPO\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>New-GPO -Name TestGPO1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Link the GPO to the domain test.com\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>New-GPLink -Name TestGPO1 -Target \"dc=test,dc=com\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The two commands can be abbreviated as one command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>new-gpo -name TestGPO1 | new-gplink -Target \"dc=test,dc=com\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Obtain the ID 0bfd3f0c-21a1-4eca-8a5e-1f0bd4dc64dc via command line echo\u003C\u002Fp>\u003Ch3>3. Create a scheduled task\u003C\u002Fh3>\u003Cp>Scheduled tasks created via Group Policy Management Console (GPMC) are automatically registered\u003C\u002Fp>\u003Cp>Currently, I have not found an interface to register scheduled tasks, so I can only look for a workaround\u003C\u002Fp>\u003Cp>Fortunately, I eventually found a workaround solution, with the steps as follows:\u003C\u002Fp>\u003Ch4>(1) Export the GPO\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Backup-Gpo -Name TestGPO1 -Path C:\\test\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Create the configuration file for the scheduled task, ScheduledTasks.xml\u003C\u002Fh4>\u003Cp>Path is \\\\\u003Cdomain.com>\\Policies\\\u003Cgpo id=\"\">\\DomainSysvol\\GPO\\User\\Preferences\\ScheduledTasks\\ScheduledTasks.xml\u003C\u002Fgpo>\u003C\u002Fdomain.com>\u003C\u002Fp>\u003Ch4>(3) Modify Backup.xml and gpreport.xml\u003C\u002Fh4>\u003Cp>Add the configuration information for the scheduled task\u003C\u002Fp>\u003Ch4>(4) Restore the GPO\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-GPO -BackupId \u003Cbackupid> -TargetName TestGPO1 -Path C:\\test\u003C\u002Fbackupid>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The complete implementation code has been open-sourced, download address is as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The next article will detail the principles and script implementation specifics\u003C\u002Fp>\u003Cp>Script command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>New-GPOImmediateTask -TaskName Debugging -GPODisplayName TestGPO -SysPath '\\\\dc.test.com\\sysvol\\test.com' -CommandArguments '-c \"123 | Out-File C:\\test\\debug.txt\"'\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The script automatically performs the following operations:\u003C\u002Fp>\u003Cul>\u003Cli>Back up TestGPO to the current directory\u003C\u002Fli>\u003Cli>Modify Backup.xml and gpreport.xml in the backup folder\u003C\u002Fli>\u003Cli>Generate the file ScheduledTasks.xml in the backup folder\u003C\u002Fli>\u003Cli>Restore TestGPO\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>4. Force client to refresh group policy\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Invoke-GPUpdate -Computer \"TEST\\COMPUTER-01\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Windows Server 2008 R2 does not support this command by default, Windows Server 2012 supports it\u003C\u002Fp>\u003Cp>The client's firewall needs to allow the following connections:\u003C\u002Fp>\u003Cul>\u003Cli>Remote Scheduled Tasks Management (RPC)\u003C\u002Fli>\u003Cli>Remote Scheduled Tasks Management (RPC-ERMAP)\u003C\u002Fli>\u003Cli>Windows Management Instrumentation (WMI-IN)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Official documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fpowershell\u002Fmodule\u002Fgrouppolicy\u002Finvoke-gpupdate?view=win10-ps\u003C\u002Fp>\u003Ch3>5. Delete GPO\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Remove-GPO -Name TestGPO1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Deleting GPO via right-click in Group Policy Management Console (GPMC) does not remove the corresponding folder, while Remove-GPO does\u003C\u002Fp>\u003Ch2>0x05 Exploitation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Prerequisite: Obtained domain administrator privileges or edit permissions for a specific Group Policy\u003C\u002Fp>\u003Cp>General operations are as follows:\u003C\u002Fp>\u003Cp>Load the GroupPolicy module:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module GroupPolicy –verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Retrieve contents of all GPOs:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-GPO -All\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export all GPOs as a single HTML report:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-GPOReport -All -ReportType html -Path C:\\GposReport\\GposReport.html\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export each GPO as a separate HTML report:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-GPO -All | %{\u003Cbr>Get-GPOReport -name $_.displayname -ReportType html -path (\"c:\\GPOReports\\\"+$_.displayname+\".html\")\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>View the permission settings for a specified GPO:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-GPPermission -Name \"TestGPO1\" -All \u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Back up a specified GPO:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Backup-Gpo -Name TestGPO1 -Path C:\\GpoBackups\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Back up all GPOs:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Backup-Gpo -All -Path \"c:\\GpoBackups\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Restore a specified GPO:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Restore-GPO -Name TestGPO1 -Path C:\\GpoBackups\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Restore all GPOs:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Restore-GPO -All -Path \"c:\\GpoBackups\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Depending on the situation, there are two exploitation approaches:\u003C\u002Fp>\u003Ch3>1. Create a new Group Policy and set up a scheduled task to achieve remote execution\u003C\u002Fh3>\u003Cul>\u003Cli>Create a new GPO\u003C\u002Fli>\u003Cli>Backup GPO\u003C\u002Fli>\u003Cli>Modify Backup.xml and gpreport.xml\u003C\u002Fli>\u003Cli>Create ScheduledTasks.xml\u003C\u002Fli>\u003Cli>Restore GPO\u003C\u002Fli>\u003Cli>Force client policy refresh\u003C\u002Fli>\u003Cli>Clean up operational traces\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>2. Modify existing Group Policy, replace scheduled tasks\u003C\u002Fh3>\u003Cp>If the domain controller already has policies configured with scheduled tasks\u003C\u002Fp>\u003Cp>No need to register, just modify ScheduledTasks.xml\u003C\u002Fp>\u003Ch2>0x06 Common GPO Operations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Create OU:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>New-ADOrganizationalUnit -Name OUTest1 -Path \"dc=test,dc=com\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>View all computers in the current domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dsquery computer\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Obtain result \"CN=Computer1,CN=Computers,DC=test,DC=com\"\u003C\u002Fp>\u003Cp>Add this computer to OU=OUTest1:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dsmove \"CN=Computer1,CN=Computers,DC=test,DC=com\" -newparent OU=OUTest1,dc=test,dc=com\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Query computers in OU=OUTest1:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dsquery computer OU=OUTest1,dc=test,dc=com\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Create GPO and link:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>new-gpo -name TestGPO | new-gplink -Target \"OU=OUTest1,dc=test,dc=com\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Restore:\u003C\u002Fp>\u003Cp>Remove computer Computer1 from OU=OUTest1\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dsmove \"CN=Computer1,OU=OUTest1,DC=test,DC=com\" -newparent CN=Computers,dc=test,dc=com\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Delete OU=OUTest1:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>set-ADOrganizationalUnit -Identity \"OU=OUTest1,dc=test,dc=com\" -ProtectedFromAccidentalDeletion $false\u003Cbr>Remove-ADOrganizationalUnit -Identity \"OU=OUTest1,dc=test,dc=com\" -Recursive -Confirm:$False\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces methods for remote execution using scheduled tasks in GPO, analyzes exploitation approaches, and demonstrates the creation, modification, and deletion of GPO and scheduled tasks via command line.\u003C\u002Fp>\u003Ch2>0x08 Supplement\u003C\u002Fh2>\u003Cp>I noticed that harmj0y's blog mentioned situations where his script might not work:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.harmj0y.net\u002Fblog\u002Fredteaming\u002Fabusing-gpo-permissions\u002F\u003C\u002Fp>\u003Cp>Personally, I believe this is because the created scheduled tasks were not registered. Using my modified script should resolve this issue. If readers have new suggestions, feedback is welcome.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In a previous article, \"Penetration Basics - Using Scheduled Tasks in Windows,\" the usage of scheduled tasks was introduced. In a domain environment, remote execution of scheduled tasks can also be achieved through Group Policy Objects (GPO). This article will introduce this method and analyze exploitation approaches.\u003C\u002Fp>\u003Ch2>0x01 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to Scheduled Tasks in GPO\u003C\u002Fli>\u003Cli>Remote Execution of Scheduled Tasks via Group Policy Management Console (GPMC)\u003C\u002Fli>\u003Cli>Remote Execution of Scheduled Tasks via Command Line\u003C\u002Fli>\u003Cli>Creating a New GPO for Remote Execution\u003C\u002Fli>\u003Cli>Modifying an Existing GPO for Remote Execution\u003C\u002Fli>\u003Cli>Common Operations on GPO\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recommended reading materials:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.harmj0y.net\u002Fblog\u002Fredteaming\u002Fabusing-gpo-permissions\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fadsecurity.org\u002F?p=2716\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.sicherheitsforschung-magdeburg.de\u002Fuploads\u002Fjournal\u002FMJS_052_Willi_GPO.pdf\u003C\u002Fp>\u003Cp>GPO stands for Group Policy Objects, used to store policies in Active Directory.\u003C\u002Fp>\u003Cp>Starting from Windows Server 2008, GPO began supporting scheduled tasks, facilitating the management of computers and users in the domain.\u003C\u002Fp>\u003Cp>By default, group policies for domain users are updated every 90 minutes with a random offset of 0-30 minutes, while group policies for domain controllers are updated every 5 minutes.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Group policies can be forced to update via command.\u003C\u002Fp>\u003Cp>Default group policy storage location: \\\\\u003Cdomain>\\SYSVOL\\\u003Cdomain>\\Policies\\, accessible by all hosts within the domain.\u003C\u002Fdomain>\u003C\u002Fdomain>\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>A previous article, 'Domain Penetration - Restoring Passwords Saved in Group Policies via SYSVOL', introduced this file location.\u003C\u002Fp>\u003Cp>There are two default group policies, each corresponding to a folder:\u003C\u002Fp>\u003Cp>{6AC1786C-016F-11D2-945F-00C04fB984F9} corresponds to Default Domain Controllers Policy\u003C\u002Fp>\u003Cp>{31B2F340-016D-11D2-945F-00C04FB984F9} corresponds to Default Domain Policy\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016178928_0_f38bfb417c-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Remote Execution of Scheduled Tasks via Group Policy Management Console (GPMC)\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>On the domain controller, location: Administrative Tools -&gt; Group Policy Management\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016181424_1_8419120247-1.jpeg\">\u003C\u002Fp>\u003Cp>Select the domain test.local, right-click, select the first option, create a GPO, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016182408_2_3bc197e2f7-1.jpeg\">\u003C\u002Fp>\u003Cp>Enter the name TestGPO1, which creates a global GPO that applies to all domain users\u003C\u002Fp>\u003Cp>Select TestGPO1, right-click, Edit...\u003C\u002Fp>\u003Cp>User Configuration -&gt; Preferences -&gt; Control Panel Settings -&gt; Scheduled Tasks\u003C\u002Fp>\u003Cp>New -&gt; Immediate Task (Windows Vista and later), as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016183329_3_6d84448f0f-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Immediate Tasks are executed each time Group Policy refreshes.\u003C\u002Fp>\u003Cp>For differences between the four types of scheduled tasks, refer to the official documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fprevious-versions\u002Fwindows\u002Fit-pro\u002Fwindows-server-2008-R2-and-2008\u002Fcc770904(v%3dws.11)\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>You can also navigate to Computer Configuration -&gt; Preferences -&gt; Control Panel Settings -&gt; Scheduled Tasks\u003C\u002Fp>\u003Cp>Next, set up the scheduled task according to the prompts.\u003C\u002Fp>\u003Cp>For testing convenience, the action performed outputs the execution result to a file, as shown below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016184679_4_b20e63537c-1.jpeg\">\u003C\u002Fp>\u003Cp>The Group Policy Object (GPO) corresponding to this has the ID {7D85A2EF-F525-4D8C-B12D-F2825F3A1224}. The configuration information for the scheduled tasks is stored in the file ScheduledTasks.xml located at \\\\test.com\\SYSVOL\\test.com\\Policies\\{7D85A2EF-F525-4D8C-B12D-F2825F3A1224}\\User\\Preferences\\ScheduledTasks.\u003C\u002Fp>\u003Cp>For domain-joined hosts, you can wait 90 minutes for Group Policy to update automatically, or execute the following command on the client to force a Group Policy refresh:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gpupdate \u002Fforce\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The default method for clients to update Group Policy:\u003C\u002Fp>\u003Cp>Reads the version of the Group Policy from the domain shared directory at \\\\\u003Cdomain.com>\\Policies\\\u003Cgpo id=\"\">\\GPT.ini. If this version is higher than the locally stored Group Policy version, the client will update its local Group Policy.\u003C\u002Fgpo>\u003C\u002Fdomain.com>\u003C\u002Fp>\u003Cp>Each time Group Policy is modified, the Version in \\\\\u003Cdomain.com>\\Policies\\\u003Cgpo id=\"\">\\GPT.ini is incremented.\u003C\u002Fgpo>\u003C\u002Fdomain.com>\u003C\u002Fp>\u003Cp>If the domain controller forces a client to refresh Group Policy, it will not compare the version from the domain shared directory.\u003C\u002Fp>\u003Ch2>0x04 Remote execution of scheduled tasks via command line\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Domain Controller System: Windows Server 2012 R2 x64\u003C\u002Fp>\u003Cp>Domain Name: test.com\u003C\u002Fp>\u003Ch3>1. Create a GPO\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>New-GPO -Name TestGPO1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Link the GPO to the domain test.com\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>New-GPLink -Name TestGPO1 -Target \"dc=test,dc=com\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The two commands can be abbreviated as one command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>new-gpo -name TestGPO1 | new-gplink -Target \"dc=test,dc=com\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Obtain the ID 0bfd3f0c-21a1-4eca-8a5e-1f0bd4dc64dc via command line echo\u003C\u002Fp>\u003Ch3>3. Create a scheduled task\u003C\u002Fh3>\u003Cp>Scheduled tasks created via Group Policy Management Console (GPMC) are automatically registered\u003C\u002Fp>\u003Cp>Currently, I have not found an interface to register scheduled tasks, so I can only look for a workaround\u003C\u002Fp>\u003Cp>Fortunately, I eventually found a workaround solution, with the steps as follows:\u003C\u002Fp>\u003Ch4>(1) Export the GPO\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Backup-Gpo -Name TestGPO1 -Path C:\\test\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Create the configuration file for the scheduled task, ScheduledTasks.xml\u003C\u002Fh4>\u003Cp>Path is \\\\\u003Cdomain.com>\\Policies\\\u003Cgpo id=\"\">\\DomainSysvol\\GPO\\User\\Preferences\\ScheduledTasks\\ScheduledTasks.xml\u003C\u002Fgpo>\u003C\u002Fdomain.com>\u003C\u002Fp>\u003Ch4>(3) Modify Backup.xml and gpreport.xml\u003C\u002Fh4>\u003Cp>Add the configuration information for the scheduled task\u003C\u002Fp>\u003Ch4>(4) Restore the GPO\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-GPO -BackupId \u003Cbackupid> -TargetName TestGPO1 -Path C:\\test\u003C\u002Fbackupid>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The complete implementation code has been open-sourced, download address is as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The next article will detail the principles and script implementation specifics\u003C\u002Fp>\u003Cp>Script command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>New-GPOImmediateTask -TaskName Debugging -GPODisplayName TestGPO -SysPath '\\\\dc.test.com\\sysvol\\test.com' -CommandArguments '-c \"123 | Out-File C:\\test\\debug.txt\"'\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The script automatically performs the following operations:\u003C\u002Fp>\u003Cul>\u003Cli>Back up TestGPO to the current directory\u003C\u002Fli>\u003Cli>Modify Backup.xml and gpreport.xml in the backup folder\u003C\u002Fli>\u003Cli>Generate the file ScheduledTasks.xml in the backup folder\u003C\u002Fli>\u003Cli>Restore TestGPO\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>4. Force client to refresh group policy\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Invoke-GPUpdate -Computer \"TEST\\COMPUTER-01\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Windows Server 2008 R2 does not support this command by default, Windows Server 2012 supports it\u003C\u002Fp>\u003Cp>The client's firewall needs to allow the following connections:\u003C\u002Fp>\u003Cul>\u003Cli>Remote Scheduled Tasks Management (RPC)\u003C\u002Fli>\u003Cli>Remote Scheduled Tasks Management (RPC-ERMAP)\u003C\u002Fli>\u003Cli>Windows Management Instrumentation (WMI-IN)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Official documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fpowershell\u002Fmodule\u002Fgrouppolicy\u002Finvoke-gpupdate?view=win10-ps\u003C\u002Fp>\u003Ch3>5. Delete GPO\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Remove-GPO -Name TestGPO1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Deleting GPO via right-click in Group Policy Management Console (GPMC) does not remove the corresponding folder, while Remove-GPO does\u003C\u002Fp>\u003Ch2>0x05 Exploitation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Prerequisite: Obtained domain administrator privileges or edit permissions for a specific Group Policy\u003C\u002Fp>\u003Cp>General operations are as follows:\u003C\u002Fp>\u003Cp>Load the GroupPolicy module:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module GroupPolicy –verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Retrieve contents of all GPOs:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-GPO -All\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export all GPOs as a single HTML report:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-GPOReport -All -ReportType html -Path C:\\GposReport\\GposReport.html\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export each GPO as a separate HTML report:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-GPO -All | %{\u003Cbr>Get-GPOReport -name $_.displayname -ReportType html -path (\"c:\\GPOReports\\\"+$_.displayname+\".html\")\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>View the permission settings for a specified GPO:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-GPPermission -Name \"TestGPO1\" -All \u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Back up a specified GPO:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Backup-Gpo -Name TestGPO1 -Path C:\\GpoBackups\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Back up all GPOs:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Backup-Gpo -All -Path \"c:\\GpoBackups\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Restore a specified GPO:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Restore-GPO -Name TestGPO1 -Path C:\\GpoBackups\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Restore all GPOs:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Restore-GPO -All -Path \"c:\\GpoBackups\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Depending on the situation, there are two exploitation approaches:\u003C\u002Fp>\u003Ch3>1. Create a new Group Policy and set up a scheduled task to achieve remote execution\u003C\u002Fh3>\u003Cul>\u003Cli>Create a new GPO\u003C\u002Fli>\u003Cli>Backup GPO\u003C\u002Fli>\u003Cli>Modify Backup.xml and gpreport.xml\u003C\u002Fli>\u003Cli>Create ScheduledTasks.xml\u003C\u002Fli>\u003Cli>Restore GPO\u003C\u002Fli>\u003Cli>Force client policy refresh\u003C\u002Fli>\u003Cli>Clean up operational traces\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>2. Modify existing Group Policy, replace scheduled tasks\u003C\u002Fh3>\u003Cp>If the domain controller already has policies configured with scheduled tasks\u003C\u002Fp>\u003Cp>No need to register, just modify ScheduledTasks.xml\u003C\u002Fp>\u003Ch2>0x06 Common GPO Operations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Create OU:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>New-ADOrganizationalUnit -Name OUTest1 -Path \"dc=test,dc=com\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>View all computers in the current domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dsquery computer\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Obtain result \"CN=Computer1,CN=Computers,DC=test,DC=com\"\u003C\u002Fp>\u003Cp>Add this computer to OU=OUTest1:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dsmove \"CN=Computer1,CN=Computers,DC=test,DC=com\" -newparent OU=OUTest1,dc=test,dc=com\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Query computers in OU=OUTest1:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dsquery computer OU=OUTest1,dc=test,dc=com\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Create GPO and link:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>new-gpo -name TestGPO | new-gplink -Target \"OU=OUTest1,dc=test,dc=com\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Restore:\u003C\u002Fp>\u003Cp>Remove computer Computer1 from OU=OUTest1\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dsmove \"CN=Computer1,OU=OUTest1,DC=test,DC=com\" -newparent CN=Computers,dc=test,dc=com\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Delete OU=OUTest1:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>set-ADOrganizationalUnit -Identity \"OU=OUTest1,dc=test,dc=com\" -ProtectedFromAccidentalDeletion $false\u003Cbr>Remove-ADOrganizationalUnit -Identity \"OU=OUTest1,dc=test,dc=com\" -Recursive -Confirm:$False\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces methods for remote execution using scheduled tasks in GPO, analyzes exploitation approaches, and demonstrates the creation, modification, and deletion of GPO and scheduled tasks via command line.\u003C\u002Fp>\u003Ch2>0x08 Supplement\u003C\u002Fh2>\u003Cp>I noticed that harmj0y's blog mentioned situations where his script might not work:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.harmj0y.net\u002Fblog\u002Fredteaming\u002Fabusing-gpo-permissions\u002F\u003C\u002Fp>\u003Cp>Personally, I believe this is because the created scheduled tasks were not registered. Using my modified script should resolve this issue. If readers have new suggestions, feedback is welcome.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",468,"Onedaysec",6,"published","2026-02-02T07:25:19.986Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Remote Execution via GPO Scheduled Tasks in Domain Penetration","GPO scheduled tasks, domain penetration, remote execution, Group Policy Objects, Active Directory exploitation, SYSVOL, gpupdate, Windows security",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46,47],1006,1005,1003,1002,{"title":39,"description":39,"image":39},"2026-07-24T15:37:10.273Z","2026-07-23T16:02:24.821Z","draft","2026-07-23T16:16:03.400Z"]