PostgreSQL + Group Policy Preferences




The finished scenario consists of:

  • Lures in the form of a Group Policy Preferences file storing database login data
  • PostgreSQL database requiring valid login information to be entered

The bait can be placed on Windows workstations and servers. The bait is detected by the tools:

  • PowerSploit
  • GhostPack
  • Metasploit
