Group Policy Preferences (T1552.006)

View on ATT&CK

In Playbook

Associated Tactics

  • Credential Access

Credential Access (TA0006)

The adversary is trying to steal account names and passwords. Credential Access consists of techniques for stealing credentials like account names and passwords. Techniques used to get credentials include keylogging or credential dumping. Using legitimate credentials can give adversaries access to systems, make them harder to detect, and provide the opportunity to create more accounts to help achieve their goals.

View on ATT&CK

Procedure Examples

Description Source(s)
Campbell, C. (2012, May 24). GPP Password Retrieval with PowerShell. Retrieved April 11, 2018. Obscuresecurity Get-GPPPassword
Microsoft. (2016, August 31). Group Policy Preferences. Retrieved March 9, 2020. Microsoft GPP 2016
Microsoft. (n.d.). 2.2.1.1.4 Password Encryption. Retrieved April 11, 2018. Microsoft GPP Key
Sean Metcalf. (2015, December 28). Finding Passwords in SYSVOL & Exploiting Group Policy Preferences. Retrieved February 17, 2020. ADSecurity Finding Passwords in SYSVOL