/// Map the `groupType` attribute to the scope string BloodHound expects.
///
/// Only the scope bits matter here; `GROUP_TYPE_SECURITY_ENABLED` (0x80000000)
/// distinguishes security from distribution groups and is not part of the scope.
/// <https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-adts>