INNER CODE UNIT · Python
bloodhound41patch
idnahacks/GoodHound · goodhound/neodb.py:31
def bloodhound41patch(graph):
"""Bloodhound 4.1 doesn't automatically tag non highvalue items with the attribute."""
logging.info('Patching for Bloodhound 4.1')
hvpatch="""match (n:Base) where n.highvalue is NULL set n.highvalue = FALSE"""
graph.run(hvpatch)
def set_hv_for_dcsyncers(graph):
"""Searches for AD principals that can perform a DCSync attack and sets their highvalue property to TRUE if they're not already a member of a HighValue group."""
logging.info('Searching for paths to targets that can perform a DCSync attack.')
hvusersquery="""match (n)-[:MemberOf*1..]->(g:Group {highvalue:true}) with n as hv match (hv {highvalue:false}) return distinct(hv.name) as name"""
hvusers=graph.run(hvusersquery).data()
dcsyncusersquery="""MATCH (n1)-[:MemberOf|GetChanges*1..]->(u:Domain) WITH n1,u MATCH (n1)-[:MemberOf|GetChangesAll*1..]->(u) WITH n1,u MATCH p = (n1)-[:MemberOf|GetChanges|GetChangesAll*1..]->(u) RETURN distinct(n1.objectid) as sid, n1.name as name"""
dcsyncusers=graph.run(dcsyncusersquery).data()
for u in dcsyncusers:
name = u.get("name")
sid = u.get("sid")
#fix any objects that have a null name
if name == None: