INNER CODE UNIT · Python

totalusers

idnahacks/GoodHound · goodhound/neodb.py:76

def totalusers(graph):
    """Calculate the total users in the dataset."""
    totalenablednonadminsquery="""match (u:User {highvalue:FALSE, enabled:TRUE}) return count(u)"""
    totalenablednonadminusers = int(graph.run(totalenablednonadminsquery).evaluate())
    return totalenablednonadminusers

def getscandate(graph):
    """Find the date that the Sharphound collection was run based on the most recent lastlogondate timestamp of the Domain Controllers"""
    scandate_query="""WITH '(?i)ldap/.*' as regex_one WITH '(?i)gc/.*' as regex_two MATCH (n:Computer) WHERE ANY(item IN n.serviceprincipalnames WHERE item =~ regex_two OR item =~ regex_two ) return n.lastlogontimestamp as date order by date desc limit 1"""
    scandate = int(graph.run(scandate_query).evaluate())
    scandatenice = (datetime.fromtimestamp(scandate)).strftime("%Y-%m-%d")
    return scandate, scandatenice

def warmupdb(graph, args):
    if not args.quiet:
        print("Warming up database")
    warmupdbquery = """MATCH (n) OPTIONAL MATCH (n)-[r]->() RETURN count(n.name) + count(r.isacl)"""
    graph.run(warmupdbquery)

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…