Active Directory GPO Abuse
Write access to a GPO linked to Domain Computers OU is code execution on every workstation. Write access to a Domain Controllers OU GPO is SYSTEM on every DC. Finding writable GPOs is a pre-DA win most environments don't detect. Full chain: find, exploit, persist, detect.
Members Only Content
This article is exclusively available to registered members of LazyHackers. Login or subscribe to read.