pyGPOAbuse-ScheduledTask
NEWpyGPOAbuse is a partial Linux/Python implementation of SharpGPOAbuse that abuses write access to a GPO by adding an immediate scheduled task to its Machine (or User) preferences, executing an arbitrary command as SYSTEM on hosts in scope at the next policy refresh. You authenticate with a password or NT hash and target the GPO by its GUID (-gpo-id), which you can obtain from PowerView's Get-DomainGPO or ldapsearch. It is ideal when operating from a Linux box with no Windows tooling; use --cleanup afterwards to remove the planted task. Command Reference: Domain: test.local Username: john Password: password123 NT hash: 2a3de7fe356ee524cc9f3d579f2e0aa7 DC IP: 10.10.10.1