INNER CODE UNIT · Python
set_hv_for_dcsyncers
idnahacks/GoodHound · goodhound/neodb.py:37
def set_hv_for_dcsyncers(graph):
"""Searches for AD principals that can perform a DCSync attack and sets their highvalue property to TRUE if they're not already a member of a HighValue group."""
logging.info('Searching for paths to targets that can perform a DCSync attack.')
hvusersquery="""match (n)-[:MemberOf*1..]->(g:Group {highvalue:true}) with n as hv match (hv {highvalue:false}) return distinct(hv.name) as name"""
hvusers=graph.run(hvusersquery).data()
dcsyncusersquery="""MATCH (n1)-[:MemberOf|GetChanges*1..]->(u:Domain) WITH n1,u MATCH (n1)-[:MemberOf|GetChangesAll*1..]->(u) WITH n1,u MATCH p = (n1)-[:MemberOf|GetChanges|GetChangesAll*1..]->(u) RETURN distinct(n1.objectid) as sid, n1.name as name"""
dcsyncusers=graph.run(dcsyncusersquery).data()
for u in dcsyncusers:
name = u.get("name")
sid = u.get("sid")
#fix any objects that have a null name
if name == None:
name = sid
if name not in hvusers:
addhighvaluequery="""MATCH (n {name:"%s"}) set n.highvalue=true""" %name
graph.run(addhighvaluequery)
def cost(graph):