Skip to content

Feature: Collect local user privileges on machines #1998

@ncha-syn

Description

@ncha-syn

Feature Description

Currently, only the "SeRemoteInteractiveLogonRight" access token privilege is collected and displayed in the UI. It would be cool to have other rights of interest.

Are you intending to implement this feature?

yes

Current Behavior

It only supports the "SeRemoteInteractiveLogonRight" privilege.

Desired Behavior

It would support more local privileges edges allowing you to quickly identity Local Privilege Escalation vectors related to access tokens.

Use Case

This feature would allow BloodHound-CE users to quickly identify users that have high impact local privileges on computers.

Implementation Suggestions

Additional Information

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requesttriageThis issue requires triaging

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions