SpecterOps / BloodHound

Six Degrees of Domain Admin
https://bloodhoundenterprise.io/
Apache License 2.0
1.1k stars 109 forks source link

Include Account Operators group in Tier Zero default #615

Open lbrauns opened 5 months ago

lbrauns commented 5 months ago

Description:

Account Operators are not classified as Tier 0:

image

Component(s) Affected:

Steps to Reproduce:

  1. Go to [specific page or endpoint]
  2. Click on [button/element/etc.]
  3. Enter [input/data]
  4. See error at [this point]

Expected Behavior:

Account Operators are defined as Tier 0 by some cool dudes who created a table: https://specterops.github.io/TierZeroTable/

Actual Behavior:

Account Operators are not classified as Tier 0, producing a LOT of false positives.

Environment Information:

BloodHound: Enterprise v5.9.0 / Community v5.9.0

Contributor Checklist:

lbrauns commented 5 months ago

Just noticed, the KRBTGT account is not added to Tier 0? I am pretty confident that is Tier 0 :)

image