THREAT OPS › Threat News › Simulating legitimate Active Directory services on the network: the case of GPO exploitation
Simulating legitimate Active Directory services on the network: the case of GPO exploitation
Simulating legitimate Active Directory services on an internal network is a powerful and versatile capability that can be leveraged in various contexts. Many examples of exploits relying on the ability to simulate working LDAP and/or SMB services can be cited, such as Group Policy Object exploitation or, more recently, the Certighost (CVE-2026-54121) ADCS flaw.
This is something that we started w
Indicators of compromise
- CVE-2026-54121cve