Theory
collects data from (who is in a group, who is logged into which computer, which ACL they have access to) and builds a relationship graph. The attack is no longer "where is a weak account" — but finding a path in the graph from the node you control to the Admins group.
Edges you must know
- MemberOf — group membership.
- AdminTo — a user/group is admin on a computer.
- HasSession — a user is currently logged into a computer (an opportunity to steal credentials from memory).
- CanRDP / CanPSRemote — remote access to a computer.
- — replication right on the domain — the prize.
- WriteDacl / AddMember / AddKeyCredentialLink — rights for "self-upgrade" in the chain.
Chain: bob, HasSession, WORKSTATION1, AdminTo, svc_helpdesk, CanRDP, SRV-APP1, MemberOf, G-Deploy, DCSync, CORP.LOCAL. Each arrow is an Edge (relationship). Defense: run the same query and break every path before the attacker.
Practice — collecting the graph
Import the zip into and check: Pre-built Analytics → "Find Shortest Paths to Admins".
Reading the path step by step
Example path: bob → HasSession → WORKSTATION1 → AdminTo → svc_helpdesk → CanRDP → SRV-APP1 → MemberOf → G-Deploy → → CORP.LOCAL.
- 1. bob is logged onto WORKSTATION1 (HasSession) — if we control bob, there are additional credentials in the computer's memory to steal.
- 2. svc_helpdesk is admin on WORKSTATION1 (AdminTo) — with rights on the computer, we extract svc_helpdesk's hash from SAM/.
- 3. svc_helpdesk can RDP to SRV-APP1 (CanRDP) and is logged on there — additional credentials in memory.
- 4. Whoever is logged onto SRV-APP1 belongs to G-Deploy, which holds on the domain.
- 5. = domain takeover — we pull all hashes via replication.
Useful Cypher queries
Detection and defense — BloodHound is also a defensive tool
- Run "Shortest Paths to Admins" before the attacker — breaking every path (removing AdminTo, rotating a password, killing a stale session) is real mitigation.
- Find exactly these edges in the logs: which svc_helpdesk logs in via RDP to servers (4624 Type 10), who runs without a reason.
Mitigation
- Fix edges: remove unnecessary AdminTo, disable unneeded delegation, keep a small number of holders.
- For every service account with high privileges — least privilege, PAW for management, and monitoring of every use.
- Return to the graph after the fix and verify the path is gone — proof the mitigation worked.