Skip to main content

Module localgroup

Module localgroup 

Source
Expand description

Local-group collection module for RustHound-CE (issue #69 - LocalGroups) https://bloodhound.specterops.io/resources/edges/admin-to https://github.com/g0h4n/LocalGroups-rs

Runs AFTER the LDAP phase, from modules::run_modules, and only when the collection method contacts machines (NOT DCOnly / LdapOnly).

SAMR / SamrOpenAlias + SamrGetMembersInAlias -> Computer.LocalGroups

RID 544 Administrators -> AdminTo RID 555 Remote Desktop Users -> CanRDP RID 562 Distributed COM Users -> ExecuteDCOM RID 580 Remote Management Users -> CanPSRemote

Same SharpHound-style behaviour as the sessions module: 445 pre-check, active-computer filter, bounded concurrency, no machine contact under DCOnly. Authentication reuses the SMB transport (password, pass the hash, pass the ticket), so nothing new is needed there.

Modules§

samr
SAMR alias branch: the two opnums the dcerpc crate does not ship.
types
Internal types for the local-group module.

Functions§

run
Entry point, called from modules::run_modules.