INNER CODE UNIT · Python

bloodhound41patch

idnahacks/GoodHound · goodhound/neodb.py:31

def bloodhound41patch(graph):
    """Bloodhound 4.1 doesn't automatically tag non highvalue items with the attribute."""
    logging.info('Patching for Bloodhound 4.1')
    hvpatch="""match (n:Base) where n.highvalue is NULL set n.highvalue = FALSE"""
    graph.run(hvpatch)

def set_hv_for_dcsyncers(graph):
    """Searches for AD principals that can perform a DCSync attack and sets their highvalue property to TRUE if they're not already a member of a HighValue group."""
    logging.info('Searching for paths to targets that can perform a DCSync attack.')
    hvusersquery="""match (n)-[:MemberOf*1..]->(g:Group {highvalue:true}) with n as hv match (hv {highvalue:false}) return distinct(hv.name) as name"""
    hvusers=graph.run(hvusersquery).data()
    dcsyncusersquery="""MATCH (n1)-[:MemberOf|GetChanges*1..]->(u:Domain) WITH n1,u MATCH (n1)-[:MemberOf|GetChangesAll*1..]->(u) WITH n1,u MATCH p = (n1)-[:MemberOf|GetChanges|GetChangesAll*1..]->(u) RETURN distinct(n1.objectid) as sid, n1.name as name"""
    dcsyncusers=graph.run(dcsyncusersquery).data()
    for u in dcsyncusers:
        name = u.get("name")
        sid = u.get("sid")
        #fix any objects that have a null name
        if name == None:

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…