INNER CODE UNIT · Python
totalusers
idnahacks/GoodHound · goodhound/neodb.py:76
def totalusers(graph):
"""Calculate the total users in the dataset."""
totalenablednonadminsquery="""match (u:User {highvalue:FALSE, enabled:TRUE}) return count(u)"""
totalenablednonadminusers = int(graph.run(totalenablednonadminsquery).evaluate())
return totalenablednonadminusers
def getscandate(graph):
"""Find the date that the Sharphound collection was run based on the most recent lastlogondate timestamp of the Domain Controllers"""
scandate_query="""WITH '(?i)ldap/.*' as regex_one WITH '(?i)gc/.*' as regex_two MATCH (n:Computer) WHERE ANY(item IN n.serviceprincipalnames WHERE item =~ regex_two OR item =~ regex_two ) return n.lastlogontimestamp as date order by date desc limit 1"""
scandate = int(graph.run(scandate_query).evaluate())
scandatenice = (datetime.fromtimestamp(scandate)).strftime("%Y-%m-%d")
return scandate, scandatenice
def warmupdb(graph, args):
if not args.quiet:
print("Warming up database")
warmupdbquery = """MATCH (n) OPTIONAL MATCH (n)-[r]->() RETURN count(n.name) + count(r.isacl)"""
graph.run(warmupdbquery)