[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fDg9k61urxNf02lftZPGjEk51dTbPoak3eMIoeHyJb4o":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},1002,"What is the advantage of using Group Policy Objects (GPO) to deploy scheduled tasks in a domain environment?","GPO-based scheduled tasks allow an administrator to centrally deploy and manage scheduled tasks across all computers or users in an Active Directory domain. By creating or modifying a GPO, you can define an immediate task that runs each time Group Policy refreshes, enabling remote execution without manual intervention on each target. For more details on the underlying technique, see the [Domain Penetration - Remote Execution via Scheduled Tasks in GPO](\u002Fnews\u002Fdomain-penetration-remote-execution-via-scheduled-tasks-in-gpo) article.","\u003Cp>GPO-based scheduled tasks allow an administrator to centrally deploy and manage scheduled tasks across all computers or users in an Active Directory domain. By creating or modifying a GPO, you can define an immediate task that runs each time Group Policy refreshes, enabling remote execution without manual intervention on each target. For more details on the underlying technique, see the [Domain Penetration - Remote Execution via Scheduled Tasks in GPO](\u002Fnews\u002Fdomain-penetration-remote-execution-via-scheduled-tasks-in-gpo) article.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fdomain-penetration-remote-execution-via-scheduled-tasks-in-gpo\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-the-advantage-of-using-group-policy-objects-gpo-to-deploy-scheduled-task-1777481109871","GPO, scheduled tasks, remote execution, Group Policy, Active Directory, domain",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},246,"Domain Penetration - Remote Execution via Scheduled Tasks in GPO","domain-penetration-remote-execution-via-scheduled-tasks-in-gpo","Learn how to exploit GPO scheduled tasks for remote execution in domain environments, covering GPMC, command-line methods, and Group Policy refresh techniques.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In a previous article, \"Penetration Basics - Using Scheduled Tasks in Windows,\" the usage of scheduled tasks was introduced. In a domain environment, remote execution of scheduled tasks can also be achieved through Group Policy Objects (GPO). This article will introduce this method and analyze exploitation approaches.\u003C\u002Fp>\u003Ch2>0x01 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to Scheduled Tasks in GPO\u003C\u002Fli>\u003Cli>Remote Execution of Scheduled Tasks via Group Policy Management Console (GPMC)\u003C\u002Fli>\u003Cli>Remote Execution of Scheduled Tasks via Command Line\u003C\u002Fli>\u003Cli>Creating a New GPO for Remote Execution\u003C\u002Fli>\u003Cli>Modifying an Existing GPO for Remote Execution\u003C\u002Fli>\u003Cli>Common Operations on GPO\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recommended reading materials:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.harmj0y.net\u002Fblog\u002Fredteaming\u002Fabusing-gpo-permissions\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fadsecurity.org\u002F?p=2716\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.sicherheitsforschung-magdeburg.de\u002Fuploads\u002Fjournal\u002FMJS_052_Willi_GPO.pdf\u003C\u002Fp>\u003Cp>GPO stands for Group Policy Objects, used to store policies in Active Directory.\u003C\u002Fp>\u003Cp>Starting from Windows Server 2008, GPO began supporting scheduled tasks, facilitating the management of computers and users in the domain.\u003C\u002Fp>\u003Cp>By default, group policies for domain users are updated every 90 minutes with a random offset of 0-30 minutes, while group policies for domain controllers are updated every 5 minutes.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Group policies can be forced to update via command.\u003C\u002Fp>\u003Cp>Default group policy storage location: \\\\\u003Cdomain>\\SYSVOL\\\u003Cdomain>\\Policies\\, accessible by all hosts within the domain.\u003C\u002Fdomain>\u003C\u002Fdomain>\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>A previous article, 'Domain Penetration - Restoring Passwords Saved in Group Policies via SYSVOL', introduced this file location.\u003C\u002Fp>\u003Cp>There are two default group policies, each corresponding to a folder:\u003C\u002Fp>\u003Cp>{6AC1786C-016F-11D2-945F-00C04fB984F9} corresponds to Default Domain Controllers Policy\u003C\u002Fp>\u003Cp>{31B2F340-016D-11D2-945F-00C04FB984F9} corresponds to Default Domain Policy\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016178928_0_f38bfb417c.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Remote Execution of Scheduled Tasks via Group Policy Management Console (GPMC)\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>On the domain controller, location: Administrative Tools -&gt; Group Policy Management\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016181424_1_8419120247.jpeg\">\u003C\u002Fp>\u003Cp>Select the domain test.local, right-click, select the first option, create a GPO, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016182408_2_3bc197e2f7.jpeg\">\u003C\u002Fp>\u003Cp>Enter the name TestGPO1, which creates a global GPO that applies to all domain users\u003C\u002Fp>\u003Cp>Select TestGPO1, right-click, Edit...\u003C\u002Fp>\u003Cp>User Configuration -&gt; Preferences -&gt; Control Panel Settings -&gt; Scheduled Tasks\u003C\u002Fp>\u003Cp>New -&gt; Immediate Task (Windows Vista and later), as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016183329_3_6d84448f0f.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Immediate Tasks are executed each time Group Policy refreshes.\u003C\u002Fp>\u003Cp>For differences between the four types of scheduled tasks, refer to the official documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fprevious-versions\u002Fwindows\u002Fit-pro\u002Fwindows-server-2008-R2-and-2008\u002Fcc770904(v%3dws.11)\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>You can also navigate to Computer Configuration -&gt; Preferences -&gt; Control Panel Settings -&gt; Scheduled Tasks\u003C\u002Fp>\u003Cp>Next, set up the scheduled task according to the prompts.\u003C\u002Fp>\u003Cp>For testing convenience, the action performed outputs the execution result to a file, as shown below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016184679_4_b20e63537c.jpeg\">\u003C\u002Fp>\u003Cp>The Group Policy Object (GPO) corresponding to this has the ID {7D85A2EF-F525-4D8C-B12D-F2825F3A1224}. The configuration information for the scheduled tasks is stored in the file ScheduledTasks.xml located at \\\\test.com\\SYSVOL\\test.com\\Policies\\{7D85A2EF-F525-4D8C-B12D-F2825F3A1224}\\User\\Preferences\\ScheduledTasks.\u003C\u002Fp>\u003Cp>For domain-joined hosts, you can wait 90 minutes for Group Policy to update automatically, or execute the following command on the client to force a Group Policy refresh:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gpupdate \u002Fforce\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The default method for clients to update Group Policy:\u003C\u002Fp>\u003Cp>Reads the version of the Group Policy from the domain shared directory at \\\\\u003Cdomain.com>\\Policies\\\u003Cgpo id=\"\">\\GPT.ini. If this version is higher than the locally stored Group Policy version, the client will update its local Group Policy.\u003C\u002Fgpo>\u003C\u002Fdomain.com>\u003C\u002Fp>\u003Cp>Each time Group Policy is modified, the Version in \\\\\u003Cdomain.com>\\Policies\\\u003Cgpo id=\"\">\\GPT.ini is incremented.\u003C\u002Fgpo>\u003C\u002Fdomain.com>\u003C\u002Fp>\u003Cp>If the domain controller forces a client to refresh Group Policy, it will not compare the version from the domain shared directory.\u003C\u002Fp>\u003Ch2>0x04 Remote execution of scheduled tasks via command line\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Domain Controller System: Windows Server 2012 R2 x64\u003C\u002Fp>\u003Cp>Domain Name: test.com\u003C\u002Fp>\u003Ch3>1. Create a GPO\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>New-GPO -Name TestGPO1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Link the GPO to the domain test.com\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>New-GPLink -Name TestGPO1 -Target \"dc=test,dc=com\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The two commands can be abbreviated as one command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>new-gpo -name TestGPO1 | new-gplink -Target \"dc=test,dc=com\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Obtain the ID 0bfd3f0c-21a1-4eca-8a5e-1f0bd4dc64dc via command line echo\u003C\u002Fp>\u003Ch3>3. Create a scheduled task\u003C\u002Fh3>\u003Cp>Scheduled tasks created via Group Policy Management Console (GPMC) are automatically registered\u003C\u002Fp>\u003Cp>Currently, I have not found an interface to register scheduled tasks, so I can only look for a workaround\u003C\u002Fp>\u003Cp>Fortunately, I eventually found a workaround solution, with the steps as follows:\u003C\u002Fp>\u003Ch4>(1) Export the GPO\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Backup-Gpo -Name TestGPO1 -Path C:\\test\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Create the configuration file for the scheduled task, ScheduledTasks.xml\u003C\u002Fh4>\u003Cp>Path is \\\\\u003Cdomain.com>\\Policies\\\u003Cgpo id=\"\">\\DomainSysvol\\GPO\\User\\Preferences\\ScheduledTasks\\ScheduledTasks.xml\u003C\u002Fgpo>\u003C\u002Fdomain.com>\u003C\u002Fp>\u003Ch4>(3) Modify Backup.xml and gpreport.xml\u003C\u002Fh4>\u003Cp>Add the configuration information for the scheduled task\u003C\u002Fp>\u003Ch4>(4) Restore the GPO\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-GPO -BackupId \u003Cbackupid> -TargetName TestGPO1 -Path C:\\test\u003C\u002Fbackupid>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The complete implementation code has been open-sourced, download address is as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The next article will detail the principles and script implementation specifics\u003C\u002Fp>\u003Cp>Script command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>New-GPOImmediateTask -TaskName Debugging -GPODisplayName TestGPO -SysPath '\\\\dc.test.com\\sysvol\\test.com' -CommandArguments '-c \"123 | Out-File C:\\test\\debug.txt\"'\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The script automatically performs the following operations:\u003C\u002Fp>\u003Cul>\u003Cli>Back up TestGPO to the current directory\u003C\u002Fli>\u003Cli>Modify Backup.xml and gpreport.xml in the backup folder\u003C\u002Fli>\u003Cli>Generate the file ScheduledTasks.xml in the backup folder\u003C\u002Fli>\u003Cli>Restore TestGPO\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>4. Force client to refresh group policy\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Invoke-GPUpdate -Computer \"TEST\\COMPUTER-01\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Windows Server 2008 R2 does not support this command by default, Windows Server 2012 supports it\u003C\u002Fp>\u003Cp>The client's firewall needs to allow the following connections:\u003C\u002Fp>\u003Cul>\u003Cli>Remote Scheduled Tasks Management (RPC)\u003C\u002Fli>\u003Cli>Remote Scheduled Tasks Management (RPC-ERMAP)\u003C\u002Fli>\u003Cli>Windows Management Instrumentation (WMI-IN)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Official documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fpowershell\u002Fmodule\u002Fgrouppolicy\u002Finvoke-gpupdate?view=win10-ps\u003C\u002Fp>\u003Ch3>5. Delete GPO\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Remove-GPO -Name TestGPO1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Deleting GPO via right-click in Group Policy Management Console (GPMC) does not remove the corresponding folder, while Remove-GPO does\u003C\u002Fp>\u003Ch2>0x05 Exploitation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Prerequisite: Obtained domain administrator privileges or edit permissions for a specific Group Policy\u003C\u002Fp>\u003Cp>General operations are as follows:\u003C\u002Fp>\u003Cp>Load the GroupPolicy module:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module GroupPolicy –verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Retrieve contents of all GPOs:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-GPO -All\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export all GPOs as a single HTML report:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-GPOReport -All -ReportType html -Path C:\\GposReport\\GposReport.html\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export each GPO as a separate HTML report:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-GPO -All | %{\u003Cbr>Get-GPOReport -name $_.displayname -ReportType html -path (\"c:\\GPOReports\\\"+$_.displayname+\".html\")\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>View the permission settings for a specified GPO:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-GPPermission -Name \"TestGPO1\" -All \u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Back up a specified GPO:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Backup-Gpo -Name TestGPO1 -Path C:\\GpoBackups\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Back up all GPOs:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Backup-Gpo -All -Path \"c:\\GpoBackups\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Restore a specified GPO:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Restore-GPO -Name TestGPO1 -Path C:\\GpoBackups\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Restore all GPOs:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Restore-GPO -All -Path \"c:\\GpoBackups\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Depending on the situation, there are two exploitation approaches:\u003C\u002Fp>\u003Ch3>1. Create a new Group Policy and set up a scheduled task to achieve remote execution\u003C\u002Fh3>\u003Cul>\u003Cli>Create a new GPO\u003C\u002Fli>\u003Cli>Backup GPO\u003C\u002Fli>\u003Cli>Modify Backup.xml and gpreport.xml\u003C\u002Fli>\u003Cli>Create ScheduledTasks.xml\u003C\u002Fli>\u003Cli>Restore GPO\u003C\u002Fli>\u003Cli>Force client policy refresh\u003C\u002Fli>\u003Cli>Clean up operational traces\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>2. Modify existing Group Policy, replace scheduled tasks\u003C\u002Fh3>\u003Cp>If the domain controller already has policies configured with scheduled tasks\u003C\u002Fp>\u003Cp>No need to register, just modify ScheduledTasks.xml\u003C\u002Fp>\u003Ch2>0x06 Common GPO Operations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Create OU:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>New-ADOrganizationalUnit -Name OUTest1 -Path \"dc=test,dc=com\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>View all computers in the current domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dsquery computer\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Obtain result \"CN=Computer1,CN=Computers,DC=test,DC=com\"\u003C\u002Fp>\u003Cp>Add this computer to OU=OUTest1:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dsmove \"CN=Computer1,CN=Computers,DC=test,DC=com\" -newparent OU=OUTest1,dc=test,dc=com\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Query computers in OU=OUTest1:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dsquery computer OU=OUTest1,dc=test,dc=com\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Create GPO and link:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>new-gpo -name TestGPO | new-gplink -Target \"OU=OUTest1,dc=test,dc=com\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Restore:\u003C\u002Fp>\u003Cp>Remove computer Computer1 from OU=OUTest1\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dsmove \"CN=Computer1,OU=OUTest1,DC=test,DC=com\" -newparent CN=Computers,dc=test,dc=com\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Delete OU=OUTest1:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>set-ADOrganizationalUnit -Identity \"OU=OUTest1,dc=test,dc=com\" -ProtectedFromAccidentalDeletion $false\u003Cbr>Remove-ADOrganizationalUnit -Identity \"OU=OUTest1,dc=test,dc=com\" -Recursive -Confirm:$False\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces methods for remote execution using scheduled tasks in GPO, analyzes exploitation approaches, and demonstrates the creation, modification, and deletion of GPO and scheduled tasks via command line.\u003C\u002Fp>\u003Ch2>0x08 Supplement\u003C\u002Fh2>\u003Cp>I noticed that harmj0y's blog mentioned situations where his script might not work:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.harmj0y.net\u002Fblog\u002Fredteaming\u002Fabusing-gpo-permissions\u002F\u003C\u002Fp>\u003Cp>Personally, I believe this is because the created scheduled tasks were not registered. Using my modified script should resolve this issue. If readers have new suggestions, feedback is welcome.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In a previous article, \"Penetration Basics - Using Scheduled Tasks in Windows,\" the usage of scheduled tasks was introduced. In a domain environment, remote execution of scheduled tasks can also be achieved through Group Policy Objects (GPO). This article will introduce this method and analyze exploitation approaches.\u003C\u002Fp>\u003Ch2>0x01 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to Scheduled Tasks in GPO\u003C\u002Fli>\u003Cli>Remote Execution of Scheduled Tasks via Group Policy Management Console (GPMC)\u003C\u002Fli>\u003Cli>Remote Execution of Scheduled Tasks via Command Line\u003C\u002Fli>\u003Cli>Creating a New GPO for Remote Execution\u003C\u002Fli>\u003Cli>Modifying an Existing GPO for Remote Execution\u003C\u002Fli>\u003Cli>Common Operations on GPO\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recommended reading materials:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.harmj0y.net\u002Fblog\u002Fredteaming\u002Fabusing-gpo-permissions\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fadsecurity.org\u002F?p=2716\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.sicherheitsforschung-magdeburg.de\u002Fuploads\u002Fjournal\u002FMJS_052_Willi_GPO.pdf\u003C\u002Fp>\u003Cp>GPO stands for Group Policy Objects, used to store policies in Active Directory.\u003C\u002Fp>\u003Cp>Starting from Windows Server 2008, GPO began supporting scheduled tasks, facilitating the management of computers and users in the domain.\u003C\u002Fp>\u003Cp>By default, group policies for domain users are updated every 90 minutes with a random offset of 0-30 minutes, while group policies for domain controllers are updated every 5 minutes.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Group policies can be forced to update via command.\u003C\u002Fp>\u003Cp>Default group policy storage location: \\\\\u003Cdomain>\\SYSVOL\\\u003Cdomain>\\Policies\\, accessible by all hosts within the domain.\u003C\u002Fdomain>\u003C\u002Fdomain>\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>A previous article, 'Domain Penetration - Restoring Passwords Saved in Group Policies via SYSVOL', introduced this file location.\u003C\u002Fp>\u003Cp>There are two default group policies, each corresponding to a folder:\u003C\u002Fp>\u003Cp>{6AC1786C-016F-11D2-945F-00C04fB984F9} corresponds to Default Domain Controllers Policy\u003C\u002Fp>\u003Cp>{31B2F340-016D-11D2-945F-00C04FB984F9} corresponds to Default Domain Policy\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016178928_0_f38bfb417c-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Remote Execution of Scheduled Tasks via Group Policy Management Console (GPMC)\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>On the domain controller, location: Administrative Tools -&gt; Group Policy Management\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016181424_1_8419120247-1.jpeg\">\u003C\u002Fp>\u003Cp>Select the domain test.local, right-click, select the first option, create a GPO, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016182408_2_3bc197e2f7-1.jpeg\">\u003C\u002Fp>\u003Cp>Enter the name TestGPO1, which creates a global GPO that applies to all domain users\u003C\u002Fp>\u003Cp>Select TestGPO1, right-click, Edit...\u003C\u002Fp>\u003Cp>User Configuration -&gt; Preferences -&gt; Control Panel Settings -&gt; Scheduled Tasks\u003C\u002Fp>\u003Cp>New -&gt; Immediate Task (Windows Vista and later), as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016183329_3_6d84448f0f-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Immediate Tasks are executed each time Group Policy refreshes.\u003C\u002Fp>\u003Cp>For differences between the four types of scheduled tasks, refer to the official documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fprevious-versions\u002Fwindows\u002Fit-pro\u002Fwindows-server-2008-R2-and-2008\u002Fcc770904(v%3dws.11)\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>You can also navigate to Computer Configuration -&gt; Preferences -&gt; Control Panel Settings -&gt; Scheduled Tasks\u003C\u002Fp>\u003Cp>Next, set up the scheduled task according to the prompts.\u003C\u002Fp>\u003Cp>For testing convenience, the action performed outputs the execution result to a file, as shown below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016184679_4_b20e63537c-1.jpeg\">\u003C\u002Fp>\u003Cp>The Group Policy Object (GPO) corresponding to this has the ID {7D85A2EF-F525-4D8C-B12D-F2825F3A1224}. The configuration information for the scheduled tasks is stored in the file ScheduledTasks.xml located at \\\\test.com\\SYSVOL\\test.com\\Policies\\{7D85A2EF-F525-4D8C-B12D-F2825F3A1224}\\User\\Preferences\\ScheduledTasks.\u003C\u002Fp>\u003Cp>For domain-joined hosts, you can wait 90 minutes for Group Policy to update automatically, or execute the following command on the client to force a Group Policy refresh:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gpupdate \u002Fforce\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The default method for clients to update Group Policy:\u003C\u002Fp>\u003Cp>Reads the version of the Group Policy from the domain shared directory at \\\\\u003Cdomain.com>\\Policies\\\u003Cgpo id=\"\">\\GPT.ini. If this version is higher than the locally stored Group Policy version, the client will update its local Group Policy.\u003C\u002Fgpo>\u003C\u002Fdomain.com>\u003C\u002Fp>\u003Cp>Each time Group Policy is modified, the Version in \\\\\u003Cdomain.com>\\Policies\\\u003Cgpo id=\"\">\\GPT.ini is incremented.\u003C\u002Fgpo>\u003C\u002Fdomain.com>\u003C\u002Fp>\u003Cp>If the domain controller forces a client to refresh Group Policy, it will not compare the version from the domain shared directory.\u003C\u002Fp>\u003Ch2>0x04 Remote execution of scheduled tasks via command line\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Domain Controller System: Windows Server 2012 R2 x64\u003C\u002Fp>\u003Cp>Domain Name: test.com\u003C\u002Fp>\u003Ch3>1. Create a GPO\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>New-GPO -Name TestGPO1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Link the GPO to the domain test.com\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>New-GPLink -Name TestGPO1 -Target \"dc=test,dc=com\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The two commands can be abbreviated as one command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>new-gpo -name TestGPO1 | new-gplink -Target \"dc=test,dc=com\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Obtain the ID 0bfd3f0c-21a1-4eca-8a5e-1f0bd4dc64dc via command line echo\u003C\u002Fp>\u003Ch3>3. Create a scheduled task\u003C\u002Fh3>\u003Cp>Scheduled tasks created via Group Policy Management Console (GPMC) are automatically registered\u003C\u002Fp>\u003Cp>Currently, I have not found an interface to register scheduled tasks, so I can only look for a workaround\u003C\u002Fp>\u003Cp>Fortunately, I eventually found a workaround solution, with the steps as follows:\u003C\u002Fp>\u003Ch4>(1) Export the GPO\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Backup-Gpo -Name TestGPO1 -Path C:\\test\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Create the configuration file for the scheduled task, ScheduledTasks.xml\u003C\u002Fh4>\u003Cp>Path is \\\\\u003Cdomain.com>\\Policies\\\u003Cgpo id=\"\">\\DomainSysvol\\GPO\\User\\Preferences\\ScheduledTasks\\ScheduledTasks.xml\u003C\u002Fgpo>\u003C\u002Fdomain.com>\u003C\u002Fp>\u003Ch4>(3) Modify Backup.xml and gpreport.xml\u003C\u002Fh4>\u003Cp>Add the configuration information for the scheduled task\u003C\u002Fp>\u003Ch4>(4) Restore the GPO\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-GPO -BackupId \u003Cbackupid> -TargetName TestGPO1 -Path C:\\test\u003C\u002Fbackupid>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The complete implementation code has been open-sourced, download address is as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The next article will detail the principles and script implementation specifics\u003C\u002Fp>\u003Cp>Script command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>New-GPOImmediateTask -TaskName Debugging -GPODisplayName TestGPO -SysPath '\\\\dc.test.com\\sysvol\\test.com' -CommandArguments '-c \"123 | Out-File C:\\test\\debug.txt\"'\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The script automatically performs the following operations:\u003C\u002Fp>\u003Cul>\u003Cli>Back up TestGPO to the current directory\u003C\u002Fli>\u003Cli>Modify Backup.xml and gpreport.xml in the backup folder\u003C\u002Fli>\u003Cli>Generate the file ScheduledTasks.xml in the backup folder\u003C\u002Fli>\u003Cli>Restore TestGPO\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>4. Force client to refresh group policy\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Invoke-GPUpdate -Computer \"TEST\\COMPUTER-01\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Windows Server 2008 R2 does not support this command by default, Windows Server 2012 supports it\u003C\u002Fp>\u003Cp>The client's firewall needs to allow the following connections:\u003C\u002Fp>\u003Cul>\u003Cli>Remote Scheduled Tasks Management (RPC)\u003C\u002Fli>\u003Cli>Remote Scheduled Tasks Management (RPC-ERMAP)\u003C\u002Fli>\u003Cli>Windows Management Instrumentation (WMI-IN)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Official documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fpowershell\u002Fmodule\u002Fgrouppolicy\u002Finvoke-gpupdate?view=win10-ps\u003C\u002Fp>\u003Ch3>5. Delete GPO\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Remove-GPO -Name TestGPO1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Deleting GPO via right-click in Group Policy Management Console (GPMC) does not remove the corresponding folder, while Remove-GPO does\u003C\u002Fp>\u003Ch2>0x05 Exploitation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Prerequisite: Obtained domain administrator privileges or edit permissions for a specific Group Policy\u003C\u002Fp>\u003Cp>General operations are as follows:\u003C\u002Fp>\u003Cp>Load the GroupPolicy module:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module GroupPolicy –verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Retrieve contents of all GPOs:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-GPO -All\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export all GPOs as a single HTML report:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-GPOReport -All -ReportType html -Path C:\\GposReport\\GposReport.html\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export each GPO as a separate HTML report:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-GPO -All | %{\u003Cbr>Get-GPOReport -name $_.displayname -ReportType html -path (\"c:\\GPOReports\\\"+$_.displayname+\".html\")\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>View the permission settings for a specified GPO:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-GPPermission -Name \"TestGPO1\" -All \u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Back up a specified GPO:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Backup-Gpo -Name TestGPO1 -Path C:\\GpoBackups\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Back up all GPOs:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Backup-Gpo -All -Path \"c:\\GpoBackups\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Restore a specified GPO:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Restore-GPO -Name TestGPO1 -Path C:\\GpoBackups\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Restore all GPOs:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Restore-GPO -All -Path \"c:\\GpoBackups\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Depending on the situation, there are two exploitation approaches:\u003C\u002Fp>\u003Ch3>1. Create a new Group Policy and set up a scheduled task to achieve remote execution\u003C\u002Fh3>\u003Cul>\u003Cli>Create a new GPO\u003C\u002Fli>\u003Cli>Backup GPO\u003C\u002Fli>\u003Cli>Modify Backup.xml and gpreport.xml\u003C\u002Fli>\u003Cli>Create ScheduledTasks.xml\u003C\u002Fli>\u003Cli>Restore GPO\u003C\u002Fli>\u003Cli>Force client policy refresh\u003C\u002Fli>\u003Cli>Clean up operational traces\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>2. Modify existing Group Policy, replace scheduled tasks\u003C\u002Fh3>\u003Cp>If the domain controller already has policies configured with scheduled tasks\u003C\u002Fp>\u003Cp>No need to register, just modify ScheduledTasks.xml\u003C\u002Fp>\u003Ch2>0x06 Common GPO Operations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Create OU:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>New-ADOrganizationalUnit -Name OUTest1 -Path \"dc=test,dc=com\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>View all computers in the current domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dsquery computer\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Obtain result \"CN=Computer1,CN=Computers,DC=test,DC=com\"\u003C\u002Fp>\u003Cp>Add this computer to OU=OUTest1:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dsmove \"CN=Computer1,CN=Computers,DC=test,DC=com\" -newparent OU=OUTest1,dc=test,dc=com\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Query computers in OU=OUTest1:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dsquery computer OU=OUTest1,dc=test,dc=com\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Create GPO and link:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>new-gpo -name TestGPO | new-gplink -Target \"OU=OUTest1,dc=test,dc=com\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Restore:\u003C\u002Fp>\u003Cp>Remove computer Computer1 from OU=OUTest1\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dsmove \"CN=Computer1,OU=OUTest1,DC=test,DC=com\" -newparent CN=Computers,dc=test,dc=com\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Delete OU=OUTest1:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>set-ADOrganizationalUnit -Identity \"OU=OUTest1,dc=test,dc=com\" -ProtectedFromAccidentalDeletion $false\u003Cbr>Remove-ADOrganizationalUnit -Identity \"OU=OUTest1,dc=test,dc=com\" -Recursive -Confirm:$False\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces methods for remote execution using scheduled tasks in GPO, analyzes exploitation approaches, and demonstrates the creation, modification, and deletion of GPO and scheduled tasks via command line.\u003C\u002Fp>\u003Ch2>0x08 Supplement\u003C\u002Fh2>\u003Cp>I noticed that harmj0y's blog mentioned situations where his script might not work:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.harmj0y.net\u002Fblog\u002Fredteaming\u002Fabusing-gpo-permissions\u002F\u003C\u002Fp>\u003Cp>Personally, I believe this is because the created scheduled tasks were not registered. Using my modified script should resolve this issue. If readers have new suggestions, feedback is welcome.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",468,"Onedaysec",6,"published","2026-02-02T07:25:19.986Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Remote Execution via GPO Scheduled Tasks in Domain Penetration","GPO scheduled tasks, domain penetration, remote execution, Group Policy Objects, Active Directory exploitation, SYSVOL, gpupdate, Windows security",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,47,4],1006,1005,1004,1003,{"title":39,"description":39,"image":39},"2026-07-24T15:37:10.273Z","2026-07-23T16:02:24.821Z","draft","2026-07-23T16:16:02.472Z"]