DEF CON 33 - Turning your Active Directory into the attacker’s C2 - Quentin Roland, Wilfried Bécard

DEF CON 33 - Turning your Active Directory into the attacker’s C2 - Quentin Roland, Wilfried Bécard

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 43:04

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The presentation demonstrates how Group Policy Objects (GPOs) are powerful yet underutilized attack vectors in Active Directory exploitation, often overlooked by security professionals 0:19.

Key Takeaways:
• GPOs consist of two components: Group Policy Container (LDAP part) and Group Policy Template (SMB part), tied together by a GUID 3:36
• GPO enumeration reveals valuable security insights including group memberships, privilege assignments, and connection restrictions for stealthy lateral movement 9:52
• The speakers developed GPOParser tool to overcome limitations in existing tools like Bloodhound when analyzing GPO configurations 17:02
• Three exploitation techniques are presented: standard GPO exploitation with group-policy-backdoor.py, NTLM relaying with gpod tool, and poisoning GPO links with UNED tool 20:00

The speakers emphasize that GPO-related risks are underestimated in Active Directory security, and their tools provide defenders with better understanding of potential attack surfaces 42:25.

Sources:

  • 0:19 Introduction to GPOs as overlooked attack vectors
  • 3:36 Explanation of GPO components (LDAP and SMB parts)
  • 9:52 Value of GPO enumeration for security insights
  • 17:02 Introduction of GPOParser tool to overcome existing tool limitations
  • 20:00 Overview of GPO exploitation techniques
  • 42:25 Conclusion about

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Uh anyway, you all ready? >> Yeah, we are. >> Without further ado, Quinton and Will are going to wow you for the next 45 minutes. So, let's give it up for them. [Applause] >> Thank you. >> Hi everyone. Welcome to our talk turning your active directory into the attacker. Sha is not that bad. Today we'll talk about group policy object enumeration and exploitation. Let's first introduce ourselves. My name is Wilfred with my colleague Quentin or K in French. We do pentest and red team at Sactive and is and this is the first time at for us at Defcon. So let's start by quick introduction. Uh during an assessment one of colleagues said well yeah we have an account that can modify a GPU that applies to domain controllers but let us check for the ADCs first. So they enumerate DCS, they find out the…