INNER CODE UNIT · Python

set_hv_for_dcsyncers

idnahacks/GoodHound · goodhound/neodb.py:37

def set_hv_for_dcsyncers(graph):
    """Searches for AD principals that can perform a DCSync attack and sets their highvalue property to TRUE if they're not already a member of a HighValue group."""
    logging.info('Searching for paths to targets that can perform a DCSync attack.')
    hvusersquery="""match (n)-[:MemberOf*1..]->(g:Group {highvalue:true}) with n as hv match (hv {highvalue:false}) return distinct(hv.name) as name"""
    hvusers=graph.run(hvusersquery).data()
    dcsyncusersquery="""MATCH (n1)-[:MemberOf|GetChanges*1..]->(u:Domain) WITH n1,u MATCH (n1)-[:MemberOf|GetChangesAll*1..]->(u) WITH n1,u MATCH p = (n1)-[:MemberOf|GetChanges|GetChangesAll*1..]->(u) RETURN distinct(n1.objectid) as sid, n1.name as name"""
    dcsyncusers=graph.run(dcsyncusersquery).data()
    for u in dcsyncusers:
        name = u.get("name")
        sid = u.get("sid")
        #fix any objects that have a null name
        if name == None:
            name = sid
        if name not in hvusers:
            addhighvaluequery="""MATCH (n {name:"%s"}) set n.highvalue=true""" %name
            graph.run(addhighvaluequery)

def cost(graph):

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…