Skip to content

AdminTo and GPO Security Filtering does not match #180

@tecxx

Description

@tecxx

Hello,
sharphound 2.7.2.
in our Tier1 there is a GPO that grants group SECSCCMSITESERVERS local admin on one server (srv012).

Image

this is done via security filtering:

Image

bloodhound shows us that all tier1 servers have this group as local admin, which is incorrect
Image

it looks like the collector is not honoring GPO security filtering correctly. did something change in one of the recent collector versions, because we're pretty sure this did not show up beginning of year?

edit: to be sure not to make a mistake, i unlinked the GPO and ran the collector, incorrect adminto-links are gone, then added the GPO and ran collector once more - adminto-links are back.

thanks!
RR

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions