Legacy-AzureHound.ps1 icon indicating copy to clipboard operation
Legacy-AzureHound.ps1 copied to clipboard

does AzureHound get all data required ?

Open commandline-be opened this issue 3 years ago • 1 comments

hey,

Thanks for this interesting project BloodHand and the SharpHound and AzureHound collectors. Not entirely sure to log this for BloodHound or for AzureHound. These tools are new to me.

Using version 4.0.3 for BloodHound and AzureHound Beta

The data collected by AzureHound appears limited by the Azure AD configuration for the domain user. I could not find any such restriction documented so i'd rather ask here.

In Bloodhound, none of the queries return data, selecting a user and selecting "shortest path to here' does return data.

I notice there is just one ADGroup visible 'all users' which i don't consider as expected either.

I'd appreciate your feedback on this topic

commandline-be avatar Sep 15 '21 19:09 commandline-be

I think you have to use custom queries for AzureHound. Try this link for some

https://hausec.com/2020/11/23/azurehound-cypher-cheatsheet/#comments

Return All Azure Users that are part of the ‘Global Administrator’ Role

MATCH p =(n)-[r:AZGlobalAdmin*1..]->(m) RETURN p

kpomeroy1979 avatar Sep 27 '21 20:09 kpomeroy1979