Microsoft Exchange has been a thorn in the side of any organization that has ever attempted to remove attack Attack Paths to total domain control, as a compromise of Exchange almost certainly grants this ability. In this post:
❓ What permissions does your Exchange deployment hold?
Andy and Jonas are back for part three of our “Defining the Undefined: What is Tier Zero” webinar series (Part One: watch or read, Part Two: watch or read)! In this webinar:
🎁 Welcome special guest Thomas Naunheim of glueckkanja will join the discussion
☁️ The first of the series focused on EntraID!
📚 Lots of knowledge to be shared and fun to be had
File Ingest now supports .ZIP format and large files - by popular demand, BloodHound can now directly ingest .zip archives in the File Ingest feature, and the size limits have been removed from the UI. With this change, your browser’s ability to package the uploaded file will remain the limiting factor in uploading large datasets directly through the UI.
Clear database option - Did you accidentally upload bad data or need to start fresh?BloodHound has you covered with the built-in ability to clear various data! As the warning below shows, changes in this section are irreversible. These options are available to users with the Administrator role under the Administration -> Database Management section.
ADCS ESC4 Attack Path - ADCS is the gift that keeps giving, and this release includes coverage for ADCS ESC4. For BloodHound Enterprise customers, this will include additional findings for ESC4 paths from those who should not have full control of your environment.
[BHE Only] BUILTIN\Users group will now appear within Large Default Groups findings