BloodHoundAD / SharpHound2

The Old BloodHound C# Ingestor (Deprecated)
509 stars 113 forks source link

Sharphound ignores inherited "Reset password"-access when applied via OU to "Descendant User objects" #58

Closed bravo2day closed 5 years ago

bravo2day commented 5 years ago

Sharphound.exe: 80F8EDE906A1237FBE6DA83591A66C0A1EA75B0EF1D8CCDDCD67C3BA1498057C (latest)

This works and is written to the csv: Access: Write all properties Applies to: this object and all descendant objects

Access: "Reset password". Applies to: this object only

The following permissions are ignored and not written to the csv:

Access: "Reset password" Applies to: Descendant User objects

The same seems to apply to situations where the permissions are set to apply to "Descendant Computer objects".

rvazarkar commented 5 years ago

Fixed in https://github.com/BloodHoundAD/SharpHound/commit/95e6cb46fc84f12eb873e3cba38f27ecf99d1be4