netwrix / pingcastle

PingCastle - Get Active Directory Security at 80% in 20% of the time
https://www.pingcastle.com
Other
2.35k stars 292 forks source link

Admin Groups - Domain Administrators - view only contains user objects #136

Closed Biker4658 closed 1 year ago

Biker4658 commented 2 years ago

During a red team a 'cluster node account' that had been added to the domain administrator group in the past was abused. (fyi: this account was added WITHOUT business or technical justification!) After executing PingCastle, this account did not show in the administrators view ... Seen the sensitivity of it being member of the Domain Administrators, should this be 'flagged' ?

vletoux commented 2 years ago

If it cannot be seen by PingCastle, there may be a permission issue. Also accounts not located into the same domain cannot be resolved. If you have a specific case I suggest you contact support@pingcastle.com with all the detail so the team can understand the root problem.