
Offensive GPO dumping and analysis tool that leverages and enriches BloodHound data
GPOHound is a tool for dumping and analysing Group Policy Objects (GPOs) extracted from the SYSVOL share.
It provides a structured, formalized format to help uncover misconfigurations, insecure settings, and privilege escalation paths in Active Directory environments.
The tool integrates with BloodHound's Neo4j database, using it as an LDAP-like source for Active Directory information while also enriching it by adding new relationships (edges) and node properties based on the analysis.
Dumps GPOs in a structured JSON or tree format
Handles multiple domains
Resolves GPO names with GPO GUIDs
Filters output by GPO files, GPO GUIDs, and domains
Searches in key/value pairs using regex
Groups settings by impacted object (e.g., Local Groups, Registry)
Detects members added to local privileged groups
Detects insecure registry settings, stored credentials, and privilege rights
Supports decrypting VNC credentials and GPP passwords
Finds domains, containers, and OUs affected by GPOs
Gets GPOs applied to a specific user, computer, OU, container, or domain
Enriches BloodHound data with relationships and properties
git clone "https://github.com/cogiceo/GPOHound"
cd GPOHound
pip install .
pipx install "git+https://github.com/cogiceo/GPOHound"
You need to setup Neo4j APOC for BloodHound data enrichment:
If you're using the standard Neo4j installation, you can enable APOC by copying the APOC jar file to the plugin folder and then restart Neo4j:
cp /var/lib/neo4j/labs/apoc-* /var/lib/neo4j/plugins/
neo4j restart
If you are installing Neo4j with "Docker Compose", add the environment variable NEO4J_PLUGINS=["apoc"]:
neo4j:
image: neo4j:latest
environment:
- NEO4J_PLUGINS=["apoc"]
For more details or alternate installation methods, refer to the official APOC Documentation.
To visualize the relationships and properties added by GPOHound, you can import the custom queries from the customqueries.json file into BloodHound. By default, this file is located at ~/.config/bloodhound/customqueries.json.
Start by downloading the SYSVOL contents from the domain controller.
Download the full SYSVOL:
gpohound sysvol --dc $DC_HOST -d $DOMAIN -u $USER -p $PASSWORD
Download only the GPOs:
gpohound sysvol --dc $DC_HOST -d $DOMAIN -u $USER -p $PASSWORD --gpos
Download with exclusions:
gpohound sysvol --dc $DC_HOST -u $USER -p $PASSWORD --exclude '/Policydefinitions/','/scripts/' --max-size 100
Retrieve all required data from LDAP :
gpohound ldap --dc $DC_HOST -d $DOMAIN -u $USER -p $PASSWORD
For BloodHound data enrichment, you must collect BloodHound data using a collector such as bloodhound.py or SharpHound.exe and import the gathered data into the BloodHound interface.
Sample GPOHound files are available in example.zip. Extract them with unzip example.zip.
See CONFIG.md for instructions on customizing default values and configurations.
gpohound --neo4j-user $USER --neo4j-pass $PASS dump
gpohound --neo4j-user $USER --neo4j-pass $PASS analysis
gpohound parse "gpos/sysvols/$DOMAIN/Policies/{31B2F340-016D-11D2-945F-00C04FB984F9}/MACHINE/Registry.pol"
gpohound dump
gpohound dump --list
gpohound dump --guid 31B2F340-016D-11D2-945F-00C04FB984F9
gpohound dump --policies scripts psscripts
gpohound dump --search 'VNC.*Server' --show
gpohound analysis
gpohound analysis --affected
gpohound analysis --trustee 'SRV01.SEVENKINGDOMS.LOCAL'
gpohound analysis --trustee 'SRV01.SEVENKINGDOMS.LOCAL' --list
gpohound analysis --trustee 'SRV01.SEVENKINGDOMS.LOCAL' --dump
gpohound analysis --enrich
gpohound analysis --enrich-ce
[!IMPORTANT]
- Conditions like security filters, WMI filters, and item-level targeting are not interpreted.
- GPO conflicts are not simulated, to avoid missing valid settings.
Detection of users assigned to privileged local groups during logon
Detection of renamed built-in privileged local groups.
Detection of trustees added to privileged local groups using "Preference Process Variables" (e.g., %ComputerName%, %DomainName%)
Detection of abusable trustees using sAMAccountName hijacking
Detection of any trustees added to privileged local groups:
Default privileged trustees, as well as service accounts with SIDs starting with S-1-5-8, are excluded from analysis.
| Group | Edge |
|---|
| Administrators | AdminTo |
| Remote Desktop Users | CanRDP |
| Distributed COM Users | ExecuteDCOM |
| Remote Management Users | CanPSRemote |
| Backup Operators | CanPrivEsc |
| Print Operators | CanPrivEsc |
| Network Configuration Operators | CanPrivEsc |
| Analysis | Property |
|---|
| "Everyone" group includes "Anonymous Logon" | — |
| SMB server session signing is not enabled | smbSigningEnabled: false |
| SMB server session signing is not required | smbSigningRequired: false |
| NTLMv1 authentication is supported | NTLMv1Support: true |
| Windows automatic logon default password | — |
| VNC credentials (Generic: RealVNC, TightVNC, TigerVNC, etc.) | *VNC*PASS* (various) |
| FileZilla stored passwords | — |
| PuTTY proxy password | — |
| TeamViewer stored credentials | — |
| WinSCP saved sessions | — |
| Picasa stored password | — |
| Privilege | Description | Edge |
|---|
| SeDebugPrivilege | Allows user to debug and interact with any process | CanPrivEsc |
| SeBackupPrivilege | Grants access to sensitive files | CanPrivEsc |
| SeRestorePrivilege | Bypasses object permissions during restore | CanPrivEsc |
| SeAssignPrimaryTokenPrivilege | Enables token impersonation for SYSTEM escalation | CanPrivEsc |
| SeImpersonatePrivilege | Allows creation of process under another user’s context | CanPrivEsc |
| SeTakeOwnershipPrivilege | Lets users take ownership of system objects | CanPrivEsc |
| SeTcbPrivilege | Grants the ability to act as part of the OS | CanPrivEsc |
| SeCreateTokenPrivilege | Permits creation of authentication tokens | CanPrivEsc |
| SeLoadDriverPrivilege | Authorizes driver loading/unloading | CanPrivEsc |
| SeManageVolumePrivilege | Grants volume or disk management privileges | CanPrivEsc |
| SeEnableDelegationPrivilege | Enable computer and user accounts to be trusted for delegation |