THREATOPS
THREAT OPSThreat News › Simulating legitimate Active Directory services on the network: the case of GPO exploitation

Simulating legitimate Active Directory services on the network: the case of GPO exploitation

medsynacktiv

Simulating legitimate Active Directory services on an internal network is a powerful and versatile capability that can be leveraged in various contexts. Many examples of exploits relying on the ability to simulate working LDAP and/or SMB services can be cited, such as Group Policy Object exploitation or, more recently, the Certighost (CVE-2026-54121) ADCS flaw.

This is something that we started w

Indicators of compromise

Original source: https://www.synacktiv.com/en/publications/simulating-legitimate-active-directory-services-on-the-network-the-case-of-gpo.html