[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fTBkU550gcAQ4ir_20lyNkoWRLEtFglK6EUdI1DvbNi8":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},643,"What is the manual method of modifying the Default Domain Policy GPO to execute a logon script without using automated tools?","First, upload the script to `\\\\test.com\\sysvol\\test.com\\Policies\\{GPO_GUID}\\USER\\Scripts\\Logon`. Then create a hidden file `scripts.ini` in the same `Scripts` folder with content like `[Logon] 0CmdLine=test1.bat 0Parameters=`. Next, increment the `Version` value in `GPT.INI` by 65536 (e.g., from 3 to 65539). Finally, update the Active Directory database (e.g., using SharpGPOAbuse or by modifying the backup XML). This forces clients to process the new script on their next policy refresh.","\u003Cp>First, upload the script to `\\\\test.com\\sysvol\\test.com\\Policies\\{GPO_GUID}\\USER\\Scripts\\Logon`. Then create a hidden file `scripts.ini` in the same `Scripts` folder with content like `[Logon] 0CmdLine=test1.bat 0Parameters=`. Next, increment the `Version` value in `GPT.INI` by 65536 (e.g., from 3 to 65539). Finally, update the Active Directory database (e.g., using SharpGPOAbuse or by modifying the backup XML). This forces clients to process the new script on their next policy refresh.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fdomain-penetration-remote-execution-via-scripts-in-gpo\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-the-manual-method-of-modifying-the-default-domain-policy-gpo-to-execute--1777482609817","Default Domain Policy, GPO modification, scripts.ini, GPT.INI, manual exploitation",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},159,"Domain Penetration - Remote Execution via Scripts in GPO","domain-penetration-remote-execution-via-scripts-in-gpo","Learn how to perform remote script execution via Group Policy Objects (GPO) in domain environments, including methods using GPMC and command-line tools.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The previous article 'Domain Penetration - Remote Execution via Scheduled Tasks in GPO' introduced the method of remote execution through domain Group Policy Object scheduled tasks. This article will introduce a similar alternative method: remote execution via scripts in domain Group Policy Object.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Remote script execution via Group Policy Management Console (GPMC)\u003C\u002Fli>\u003Cli>Remote script execution via command line\u003C\u002Fli>\u003Cli>Creating new GPO for remote execution\u003C\u002Fli>\u003Cli>Modifying existing GPO for remote execution\u003C\u002Fli>\u003Cli>Implementation details\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Remote Script Execution via Group Policy Management Console (GPMC)\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Create GPO\u003C\u002Fh3>\u003Cp>On the domain controller, location: Administrative Tools -&gt; Group Policy Management\u003C\u002Fp>\u003Cp>If you want it to apply to the entire domain, select the domain test.com, right-click, choose 'Create a GPO in this domain, and Link it here...', as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017285247_0_ba4f6b6ffc.png\">\u003C\u002Fp>\u003Cp>If you want it to apply to specific objects, select the pre-created OU, right-click, choose 'Create a GPO in this domain, and Link it here...', as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017317202_1_f52e723386.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Additional note:\u003C\u002Fstrong>Location to create an OU: Administrative Tools -&gt; Active Directory Users and Computers\u003C\u002Fp>\u003Ch3>2. Configure GPO\u003C\u002Fh3>\u003Cp>Select the created GPO, right-click, choose 'Edit...'\u003C\u002Fp>\u003Ch4>(1) Specify scripts to execute during Startup\u002FShutdown\u002FLogon\u002FLogoff\u003C\u002Fh4>\u003Cp>Startup\u002FShutdown location is Computer Configuration -&gt; Windows Settings -&gt; Scripts(Startup\u002FShutdown), applies to computer startup and shutdown events within the domain\u003C\u002Fp>\u003Cp>Logon\u002FLogoff location is User Configuration -&gt; Windows Settings -&gt; Scripts(Logon\u002FLogoff), applies to domain user logon and logoff events\u003C\u002Fp>\u003Cp>Here, configuring the logon script for user test1 as an example, select Login, upload the script to be executed to the domain shared folder, default location: \\\\test.com\\SysVol\\test.com\\Policies\\{A4C54BE4-A5D1-42F3-8288-529FACD8E5CF}\\User\\Scripts\\Logon, configure the logon execution script as logon1.bat, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017362608_2_d578343ba2.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Uploading scripts directly to \\\\test.com\\SysVol\\test.com\\Policies\\{A4C54BE4-A5D1-42F3-8288-529FACD8E5CF}\\User\\Scripts\\Logon will not take effect; the script to be executed must be specified in Logon.\u003C\u002Fp>\u003Ch4>(2) Wait for domain group policy update\u003C\u002Fh4>\u003Cp>By default, domain group policies update every 90 minutes with a random offset of 0-30 minutes, while domain controller group policies update every 5 minutes.\u003C\u002Fp>\u003Cp>To improve testing efficiency, you can execute the command gpupdate \u002Fforce on the client to force a group policy update.\u003C\u002Fp>\u003Ch4>(3) Wait for script execution to trigger\u003C\u002Fh4>\u003Cp>Logging in as user test1 on Computer01, it was found that the script logon1.bat was executed.\u003C\u002Fp>\u003Ch2>0x03 Remote script execution via command line\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Apply to the entire domain\u003C\u002Fh3>\u003Ch4>(1) Create a GPO\u003C\u002Fh4>\u003Cp>PowerShell command: New-GPO -Name TestGPO1\u003C\u002Fp>\u003Ch4>(2) Link the GPO to the domain test.com\u003C\u002Fh4>\u003Cp>PowerShell command: New-GPLink -Name TestGPO1 -Target \"dc=test,dc=com\"\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The two commands can be combined into one: new-gpo -name TestGPO1 | new-gplink -Target \"dc=test,dc=com\"\u003C\u002Fp>\u003Ch4>(3) Executing scripts via SharpGPOAbuse configuration\u003C\u002Fh4>\u003Cp>Command example: SharpGPOAbuse.exe --AddUserScript --ScriptName StartupScript.bat --ScriptContents \"cmd.exe \u002Fc echo 1 &gt; c:\\GPOAbuse.txt\" --GPOName \"TestGPO1\"\u003C\u002Fp>\u003Cp>Here, targeting specific users can also be achieved by modifying the .bat file content to check usernames. Example command for filtering user test1: SharpGPOAbuse.exe --AddUserScript --ScriptName StartupScript.bat --ScriptContents \"if %username%==test1 cmd.exe \u002Fc echo 1 &gt; c:\\GPOAbuse.txt\" --GPOName \"TestGPO1\"\u003C\u002Fp>\u003Ch4>(4) Wait for domain group policy update\u003C\u002Fh4>\u003Cp>By default, domain group policies update every 90 minutes with a random offset of 0-30 minutes\u003C\u002Fp>\u003Ch4>(5) Wait for script execution trigger\u003C\u002Fh4>\u003Ch4>(6) Delete GPO\u003C\u002Fh4>\u003Cp>Powershell command: Remove-GPO -Name TestGPO1\u003C\u002Fp>\u003Ch3>2. Targeting specific objects\u003C\u002Fh3>\u003Ch4>(1) Create OU\u003C\u002Fh4>\u003Cp>Powershell command: New-ADOrganizationalUnit -Name OUtest2 -Path \"DC=test,DC=com\"\u003C\u002Fp>\u003Ch4>(2) Confirm location of user test1\u003C\u002Fh4>\u003Cp>cmd command: dsquery user -name test1\u003C\u002Fp>\u003Cp>Return result:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\"CN=test1,CN=Users,DC=test,DC=com\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) Move the specified user test1 to the newly created OU OUtest2\u003C\u002Fh4>\u003Cp>cmd command: dsmove \"CN=test1,CN=Users,DC=test,DC=com\" -newparent \"OU=OUtest2,DC=test,DC=com\"\u003C\u002Fp>\u003Cp>Alternatively, use the cmd command: dsquery user -name test1 | dsmove -newparent \"OU=OUtest2,DC=test,DC=com\"\u003C\u002Fp>\u003Ch4>(4) Create a GPO and link it to the specified OU\u003C\u002Fh4>\u003Cp>Powershell command: new-gpo -name TestGPO2 | new-gplink -Target \"OU=OUtest2,DC=test,DC=com\"\u003C\u002Fp>\u003Ch4>(5) Set the execution script via SharpGPOAbuse\u003C\u002Fh4>\u003Cp>Command example: SharpGPOAbuse.exe --AddUserScript --ScriptName StartupScript.bat --ScriptContents \"cmd.exe \u002Fc echo 1 &gt; c:\\GPOAbuse2.txt\" --GPOName \"TestGPO2\"\u003C\u002Fp>\u003Ch4>(6) Wait for domain group policy update\u003C\u002Fh4>\u003Cp>By default, domain group policies update every 90 minutes with a random offset of 0-30 minutes\u003C\u002Fp>\u003Ch4>(7) Wait for script execution to trigger\u003C\u002Fh4>\u003Ch4>(8) Delete the GPO\u003C\u002Fh4>\u003Cp>Powershell command: Remove-GPO -Name TestGPO2\u003C\u002Fp>\u003Ch4>(9) Move user test1 out of the OU back to its original location\u003C\u002Fh4>\u003Cp>cmd command: dsquery user -name test1 | dsmove -newparent \"CN=Users,DC=test,DC=com\"\u003C\u002Fp>\u003Ch4>(10) Delete the OU\u003C\u002Fh4>\u003Cp>Powershell command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Set-ADOrganizationalUnit -Identity \"OU=OUtest2,DC=test,DC=com\" -ProtectedFromAccidentalDeletion $false\u003Cbr>Remove-ADOrganizationalUnit -Identity \"OU=OUtest2,DC=test,DC=com\" -Recursive -Confirm:$False\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Modify existing GPO to achieve remote execution\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>There are two group policies by default, each folder corresponds to one group policy:\u003C\u002Fp>\u003Cp>{6AC1786C-016F-11D2-945F-00C04fB984F9} corresponds to Default Domain Controllers Policy\u003C\u002Fp>\u003Cp>{31B2F340-016D-11D2-945F-00C04FB984F9} corresponds to Default Domain Policy\u003C\u002Fp>\u003Cp>The default exploitable group policy is Default Domain Policy, which is divided into two parts: manual modification and automatic implementation through programs\u003C\u002Fp>\u003Ch3>1. Manual modification\u003C\u002Fh3>\u003Ch4>(1) Obtain the GPO guid\u003C\u002Fh4>\u003Cp>Powershell command: get-GPO -Name \"Default Domain Policy\"\u003C\u002Fp>\u003Cp>Obtain Id as 31b2f340-016d-11d2-945f-00c04fb984f9\u003C\u002Fp>\u003Ch4>(2) Upload the user login script to be executed\u003C\u002Fh4>\u003Cp>Upload the test script test1.bat to \\\\test.com\\sysvol\\test.com\\Policies\\{31B2F340-016D-11D2-945F-00C04FB984F9}\\USER\\Scripts\\Logon\u003C\u002Fp>\u003Ch4>(3) Enable User Logon Script\u003C\u002Fh4>\u003Cp>Create file \\\\test.com\\sysvol\\test.com\\Policies\\{31B2F340-016D-11D2-945F-00C04FB984F9}\\USER\\Scripts\\scripts.ini, set as hidden file, with content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>[Logon]\u003Cbr>0CmdLine=test1.bat\u003Cbr>0Parameters=\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(4) Modify Version Information\u003C\u002Fh4>\u003Cp>Modify file \\\\test.com\\sysvol\\test.com\\Policies\\{31B2F340-016D-11D2-945F-00C04FB984F9}\\GPT.INI, add 65536 to the original value of Version as the new value\u003C\u002Fp>\u003Cp>Specifically, under default configuration, the Version value in \\\\test.com\\sysvol\\test.com\\Policies\\{31B2F340-016D-11D2-945F-00C04FB984F9}\\GPT.INI is 3, and it needs to be changed to 65539 during the first modification\u003C\u002Fp>\u003Ch4>(5) Update Database Information\u003C\u002Fh4>\u003Cp>Requires programming implementation, code can be referenced at https:\u002F\u002Fgithub.com\u002FFSecureLABS\u002FSharpGPOAbuse\u002Fblob\u002Fmaster\u002FSharpGPOAbuse\u002FProgram.cs#L189\u003C\u002Fp>\u003Cp>Of course, this operation can also be achieved by modifying files, but the process is more cumbersome. The specific approach is as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Backup GPO\u003C\u002Fli>\u003Cli>Modify Backup.xml\u003C\u002Fli>\u003Cli>Modify gpreport.xml\u003C\u002Fli>\u003Cli>Restore GPO\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>(6) Wait for domain group policy update\u003C\u002Fh4>\u003Cp>By default, domain group policies update every 90 minutes with a random offset of 0-30 minutes\u003C\u002Fp>\u003Ch4>(7) Wait for trigger script execution\u003C\u002Fh4>\u003Ch3>2. Implementation via program\u003C\u002Fh3>\u003Cp>Can be achieved via SharpGPOAbuse, example command: SharpGPOAbuse.exe --AddUserScript --ScriptName StartupScript.bat --ScriptContents \"cmd.exe \u002Fc echo 1 &gt; c:\\GPOAbuse.txt\" --GPOName \"Default Domain Policy\"\u003C\u002Fp>\u003Ch2>0x05 Direct execution of remote scripts\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>When we choose to directly execute the bat file in the group policy folder, a prompt will appear indicating it cannot be executed, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017392006_3_f4d0e1630f.png\">\u003C\u002Fp>\u003Cp>This can be allowed by modifying the registry, the corresponding command is: reg add HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Associations \u002Fv ModRiskFileTypes \u002Ft REG_SZ \u002Fd .bat \u002Ff\u003C\u002Fp>\u003Cp>This operation can also be achieved by configuring domain group policy, located at: User Configuration -&gt; Administrative Templates -&gt; Windows Components -&gt; Attachment Manager -&gt; Inclusion list for moderate risk file types, select Enabled, set the suffix to .bat, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017417677_4_d083fc0f38.png\">\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces methods for remote execution via scripts in domain group policies (Group Policy Object), sharing implementation details and exploitation ideas.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The previous article 'Domain Penetration - Remote Execution via Scheduled Tasks in GPO' introduced the method of remote execution through domain Group Policy Object scheduled tasks. This article will introduce a similar alternative method: remote execution via scripts in domain Group Policy Object.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Remote script execution via Group Policy Management Console (GPMC)\u003C\u002Fli>\u003Cli>Remote script execution via command line\u003C\u002Fli>\u003Cli>Creating new GPO for remote execution\u003C\u002Fli>\u003Cli>Modifying existing GPO for remote execution\u003C\u002Fli>\u003Cli>Implementation details\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Remote Script Execution via Group Policy Management Console (GPMC)\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Create GPO\u003C\u002Fh3>\u003Cp>On the domain controller, location: Administrative Tools -&gt; Group Policy Management\u003C\u002Fp>\u003Cp>If you want it to apply to the entire domain, select the domain test.com, right-click, choose 'Create a GPO in this domain, and Link it here...', as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017285247_0_ba4f6b6ffc-1.png\">\u003C\u002Fp>\u003Cp>If you want it to apply to specific objects, select the pre-created OU, right-click, choose 'Create a GPO in this domain, and Link it here...', as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017317202_1_f52e723386-1.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Additional note:\u003C\u002Fstrong>Location to create an OU: Administrative Tools -&gt; Active Directory Users and Computers\u003C\u002Fp>\u003Ch3>2. Configure GPO\u003C\u002Fh3>\u003Cp>Select the created GPO, right-click, choose 'Edit...'\u003C\u002Fp>\u003Ch4>(1) Specify scripts to execute during Startup\u002FShutdown\u002FLogon\u002FLogoff\u003C\u002Fh4>\u003Cp>Startup\u002FShutdown location is Computer Configuration -&gt; Windows Settings -&gt; Scripts(Startup\u002FShutdown), applies to computer startup and shutdown events within the domain\u003C\u002Fp>\u003Cp>Logon\u002FLogoff location is User Configuration -&gt; Windows Settings -&gt; Scripts(Logon\u002FLogoff), applies to domain user logon and logoff events\u003C\u002Fp>\u003Cp>Here, configuring the logon script for user test1 as an example, select Login, upload the script to be executed to the domain shared folder, default location: \\\\test.com\\SysVol\\test.com\\Policies\\{A4C54BE4-A5D1-42F3-8288-529FACD8E5CF}\\User\\Scripts\\Logon, configure the logon execution script as logon1.bat, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017362608_2_d578343ba2-1.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Uploading scripts directly to \\\\test.com\\SysVol\\test.com\\Policies\\{A4C54BE4-A5D1-42F3-8288-529FACD8E5CF}\\User\\Scripts\\Logon will not take effect; the script to be executed must be specified in Logon.\u003C\u002Fp>\u003Ch4>(2) Wait for domain group policy update\u003C\u002Fh4>\u003Cp>By default, domain group policies update every 90 minutes with a random offset of 0-30 minutes, while domain controller group policies update every 5 minutes.\u003C\u002Fp>\u003Cp>To improve testing efficiency, you can execute the command gpupdate \u002Fforce on the client to force a group policy update.\u003C\u002Fp>\u003Ch4>(3) Wait for script execution to trigger\u003C\u002Fh4>\u003Cp>Logging in as user test1 on Computer01, it was found that the script logon1.bat was executed.\u003C\u002Fp>\u003Ch2>0x03 Remote script execution via command line\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Apply to the entire domain\u003C\u002Fh3>\u003Ch4>(1) Create a GPO\u003C\u002Fh4>\u003Cp>PowerShell command: New-GPO -Name TestGPO1\u003C\u002Fp>\u003Ch4>(2) Link the GPO to the domain test.com\u003C\u002Fh4>\u003Cp>PowerShell command: New-GPLink -Name TestGPO1 -Target \"dc=test,dc=com\"\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The two commands can be combined into one: new-gpo -name TestGPO1 | new-gplink -Target \"dc=test,dc=com\"\u003C\u002Fp>\u003Ch4>(3) Executing scripts via SharpGPOAbuse configuration\u003C\u002Fh4>\u003Cp>Command example: SharpGPOAbuse.exe --AddUserScript --ScriptName StartupScript.bat --ScriptContents \"cmd.exe \u002Fc echo 1 &gt; c:\\GPOAbuse.txt\" --GPOName \"TestGPO1\"\u003C\u002Fp>\u003Cp>Here, targeting specific users can also be achieved by modifying the .bat file content to check usernames. Example command for filtering user test1: SharpGPOAbuse.exe --AddUserScript --ScriptName StartupScript.bat --ScriptContents \"if %username%==test1 cmd.exe \u002Fc echo 1 &gt; c:\\GPOAbuse.txt\" --GPOName \"TestGPO1\"\u003C\u002Fp>\u003Ch4>(4) Wait for domain group policy update\u003C\u002Fh4>\u003Cp>By default, domain group policies update every 90 minutes with a random offset of 0-30 minutes\u003C\u002Fp>\u003Ch4>(5) Wait for script execution trigger\u003C\u002Fh4>\u003Ch4>(6) Delete GPO\u003C\u002Fh4>\u003Cp>Powershell command: Remove-GPO -Name TestGPO1\u003C\u002Fp>\u003Ch3>2. Targeting specific objects\u003C\u002Fh3>\u003Ch4>(1) Create OU\u003C\u002Fh4>\u003Cp>Powershell command: New-ADOrganizationalUnit -Name OUtest2 -Path \"DC=test,DC=com\"\u003C\u002Fp>\u003Ch4>(2) Confirm location of user test1\u003C\u002Fh4>\u003Cp>cmd command: dsquery user -name test1\u003C\u002Fp>\u003Cp>Return result:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\"CN=test1,CN=Users,DC=test,DC=com\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) Move the specified user test1 to the newly created OU OUtest2\u003C\u002Fh4>\u003Cp>cmd command: dsmove \"CN=test1,CN=Users,DC=test,DC=com\" -newparent \"OU=OUtest2,DC=test,DC=com\"\u003C\u002Fp>\u003Cp>Alternatively, use the cmd command: dsquery user -name test1 | dsmove -newparent \"OU=OUtest2,DC=test,DC=com\"\u003C\u002Fp>\u003Ch4>(4) Create a GPO and link it to the specified OU\u003C\u002Fh4>\u003Cp>Powershell command: new-gpo -name TestGPO2 | new-gplink -Target \"OU=OUtest2,DC=test,DC=com\"\u003C\u002Fp>\u003Ch4>(5) Set the execution script via SharpGPOAbuse\u003C\u002Fh4>\u003Cp>Command example: SharpGPOAbuse.exe --AddUserScript --ScriptName StartupScript.bat --ScriptContents \"cmd.exe \u002Fc echo 1 &gt; c:\\GPOAbuse2.txt\" --GPOName \"TestGPO2\"\u003C\u002Fp>\u003Ch4>(6) Wait for domain group policy update\u003C\u002Fh4>\u003Cp>By default, domain group policies update every 90 minutes with a random offset of 0-30 minutes\u003C\u002Fp>\u003Ch4>(7) Wait for script execution to trigger\u003C\u002Fh4>\u003Ch4>(8) Delete the GPO\u003C\u002Fh4>\u003Cp>Powershell command: Remove-GPO -Name TestGPO2\u003C\u002Fp>\u003Ch4>(9) Move user test1 out of the OU back to its original location\u003C\u002Fh4>\u003Cp>cmd command: dsquery user -name test1 | dsmove -newparent \"CN=Users,DC=test,DC=com\"\u003C\u002Fp>\u003Ch4>(10) Delete the OU\u003C\u002Fh4>\u003Cp>Powershell command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Set-ADOrganizationalUnit -Identity \"OU=OUtest2,DC=test,DC=com\" -ProtectedFromAccidentalDeletion $false\u003Cbr>Remove-ADOrganizationalUnit -Identity \"OU=OUtest2,DC=test,DC=com\" -Recursive -Confirm:$False\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Modify existing GPO to achieve remote execution\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>There are two group policies by default, each folder corresponds to one group policy:\u003C\u002Fp>\u003Cp>{6AC1786C-016F-11D2-945F-00C04fB984F9} corresponds to Default Domain Controllers Policy\u003C\u002Fp>\u003Cp>{31B2F340-016D-11D2-945F-00C04FB984F9} corresponds to Default Domain Policy\u003C\u002Fp>\u003Cp>The default exploitable group policy is Default Domain Policy, which is divided into two parts: manual modification and automatic implementation through programs\u003C\u002Fp>\u003Ch3>1. Manual modification\u003C\u002Fh3>\u003Ch4>(1) Obtain the GPO guid\u003C\u002Fh4>\u003Cp>Powershell command: get-GPO -Name \"Default Domain Policy\"\u003C\u002Fp>\u003Cp>Obtain Id as 31b2f340-016d-11d2-945f-00c04fb984f9\u003C\u002Fp>\u003Ch4>(2) Upload the user login script to be executed\u003C\u002Fh4>\u003Cp>Upload the test script test1.bat to \\\\test.com\\sysvol\\test.com\\Policies\\{31B2F340-016D-11D2-945F-00C04FB984F9}\\USER\\Scripts\\Logon\u003C\u002Fp>\u003Ch4>(3) Enable User Logon Script\u003C\u002Fh4>\u003Cp>Create file \\\\test.com\\sysvol\\test.com\\Policies\\{31B2F340-016D-11D2-945F-00C04FB984F9}\\USER\\Scripts\\scripts.ini, set as hidden file, with content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>[Logon]\u003Cbr>0CmdLine=test1.bat\u003Cbr>0Parameters=\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(4) Modify Version Information\u003C\u002Fh4>\u003Cp>Modify file \\\\test.com\\sysvol\\test.com\\Policies\\{31B2F340-016D-11D2-945F-00C04FB984F9}\\GPT.INI, add 65536 to the original value of Version as the new value\u003C\u002Fp>\u003Cp>Specifically, under default configuration, the Version value in \\\\test.com\\sysvol\\test.com\\Policies\\{31B2F340-016D-11D2-945F-00C04FB984F9}\\GPT.INI is 3, and it needs to be changed to 65539 during the first modification\u003C\u002Fp>\u003Ch4>(5) Update Database Information\u003C\u002Fh4>\u003Cp>Requires programming implementation, code can be referenced at https:\u002F\u002Fgithub.com\u002FFSecureLABS\u002FSharpGPOAbuse\u002Fblob\u002Fmaster\u002FSharpGPOAbuse\u002FProgram.cs#L189\u003C\u002Fp>\u003Cp>Of course, this operation can also be achieved by modifying files, but the process is more cumbersome. The specific approach is as follows:\u003C\u002Fp>\u003Cul>\u003Cli>Backup GPO\u003C\u002Fli>\u003Cli>Modify Backup.xml\u003C\u002Fli>\u003Cli>Modify gpreport.xml\u003C\u002Fli>\u003Cli>Restore GPO\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>(6) Wait for domain group policy update\u003C\u002Fh4>\u003Cp>By default, domain group policies update every 90 minutes with a random offset of 0-30 minutes\u003C\u002Fp>\u003Ch4>(7) Wait for trigger script execution\u003C\u002Fh4>\u003Ch3>2. Implementation via program\u003C\u002Fh3>\u003Cp>Can be achieved via SharpGPOAbuse, example command: SharpGPOAbuse.exe --AddUserScript --ScriptName StartupScript.bat --ScriptContents \"cmd.exe \u002Fc echo 1 &gt; c:\\GPOAbuse.txt\" --GPOName \"Default Domain Policy\"\u003C\u002Fp>\u003Ch2>0x05 Direct execution of remote scripts\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>When we choose to directly execute the bat file in the group policy folder, a prompt will appear indicating it cannot be executed, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017392006_3_f4d0e1630f-1.png\">\u003C\u002Fp>\u003Cp>This can be allowed by modifying the registry, the corresponding command is: reg add HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Associations \u002Fv ModRiskFileTypes \u002Ft REG_SZ \u002Fd .bat \u002Ff\u003C\u002Fp>\u003Cp>This operation can also be achieved by configuring domain group policy, located at: User Configuration -&gt; Administrative Templates -&gt; Windows Components -&gt; Attachment Manager -&gt; Inclusion list for moderate risk file types, select Enabled, set the suffix to .bat, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017417677_4_d083fc0f38-1.png\">\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces methods for remote execution via scripts in domain group policies (Group Policy Object), sharing implementation details and exploitation ideas.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",858,"Onedaysec",5,"published","2026-02-02T07:38:21.454Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Domain Penetration: Remote Execution via GPO Scripts","domain penetration, GPO scripts, remote execution, Group Policy, SharpGPOAbuse, Active Directory",null,false,[],{"docs":43,"hasNextPage":40},[44,4,45,46],644,642,641,{"title":39,"description":39,"image":39},"2026-07-24T15:37:12.155Z","2026-07-23T16:01:53.682Z","draft","2026-07-23T16:13:56.895Z"]