GPO abuse TL;DR: Write access to a GPO linked at the right OU → code execution on every machine in scope. Stub — to be filled in. What it is TODO Preconditions / where it applies TODO Technique TODO Detection and defence TODO References TODO