Gpscript.exe

Used by group policy to process scripts

Paths

  • C:\Windows\System32\gpscript.exe
  • C:\Windows\SysWOW64\gpscript.exe

Commands

Execute

Executes logon scripts configured in Group Policy.

Use case: Add local group policy logon script to execute file and hide from defensive counter measures

Privileges: Administrator

Gpscript /logon

Execute

Executes startup scripts configured in Group Policy

Use case: Add local group policy logon script to execute file and hide from defensive counter measures

Privileges: Administrator

Gpscript /startup

Detection

Resources