Expand description
Local-group collection module for RustHound-CE (issue #69 - LocalGroups) https://bloodhound.specterops.io/resources/edges/admin-to https://github.com/g0h4n/LocalGroups-rs
Runs AFTER the LDAP phase, from modules::run_modules, and only when the
collection method contacts machines (NOT DCOnly / LdapOnly).
SAMR / SamrOpenAlias + SamrGetMembersInAlias -> Computer.LocalGroups
RID 544 Administrators -> AdminTo RID 555 Remote Desktop Users -> CanRDP RID 562 Distributed COM Users -> ExecuteDCOM RID 580 Remote Management Users -> CanPSRemote
Same SharpHound-style behaviour as the sessions module: 445 pre-check, active-computer filter, bounded concurrency, no machine contact under DCOnly. Authentication reuses the SMB transport (password, pass the hash, pass the ticket), so nothing new is needed there.
Modules§
- samr
- SAMR alias branch: the two opnums the
dcerpccrate does not ship. - types
- Internal types for the local-group module.
Functions§
- run
- Entry point, called from
modules::run_modules.