Skip to content

Releases: n0troot/SharpGPOwned

v1.2

Choose a tag to compare

@n0troot n0troot released this 25 May 18:14

Cross-domain targeting and machine account authentication for both tools.

Downloads

File Contents
SharpGPOwned-v1.2.zip GPOwned.exe + GPRecon.exe + Xblsv.dll
SharpGPOwned-v1.2-Standalone.zip GPOwned.exe + GPRecon.exe (DLL embedded, single-file)

Changelog

  • GPRecon — --domain / -d: target a remote domain's LDAP and SYSVOL
  • GPRecon — --username / -u + --password / -pw: query as a specific user
  • GPRecon — --machineaccount / --ma + --machinepassword / --mp: query as a machine account ($ appended automatically, accepts PC01, PC01$, or DOMAIN\PC01)
  • GPOwned — --machineaccount / --ma + --machinepassword / --mp: authenticate to AD and SYSVOL as a machine account using LOGON_NEW_CREDENTIALS (runas /netonly style)
  • GPOwned — fix: --domain previously only changed the SYSVOL path; it now also derives the correct domainDN for all LDAP queries
  • Build — fix: added missing Microsoft.CSharp reference to Shared.csproj (required for dynamic in SDK-style .NET 4.8 projects)

See README for full usage.

v1.1

Choose a tag to compare

@n0troot n0troot released this 13 May 13:39

Standalone builds with Xblsv.dll embedded; GPRecon now shows the write-access principal (user/group) for each writable GPO - no additional LDAP queries.

Downloads

File Contents
SharpGPOwned-v1.1.zip GPOwned.exe + GPRecon.exe + Xblsv.dll
SharpGPOwned-v1.1-Standalone.zip GPOwned.exe + GPRecon.exe (DLL embedded, single-file)

See README for full usage.

v1.0

Choose a tag to compare

@n0troot n0troot released this 13 May 09:17

Initial release.

Contents

  • GPOwned.exe - GPO exploitation tool
  • GPRecon.exe - GPO enumeration tool
  • GPOwned.Shared.dll - required shared library

Drop all three in the same directory and run from an AD-joined host.

See README for full usage.