Domain Admins
Find all Domain Admin users.allShortestPaths returns only the shortest paths, not every path).
Documentation Index
Fetch the complete documentation index at: /llms.txt
Use this file to discover all available pages before exploring further.
Common BloodHound Cypher queries for attack path analysis in Active Directory.
MATCH (u:User)-[:MemberOf*1..]->(g:Group) WHERE g.name =~ "(?i)domain admins@.*" RETURN u
MATCH p=shortestPath((u:User {owned: true})-[*1..]->(g:Group)) WHERE g.name =~ "(?i)domain admins@.*" RETURN p
allShortestPaths returns only the shortest paths, not every path).
MATCH p=allShortestPaths((u:User {owned: true})-[*1..]->(g:Group)) WHERE g.name =~ "(?i)domain admins@.*" RETURN p
MATCH (u:User {hasspn: true}) RETURN u.name, u.serviceprincipalnames
MATCH (u:User {hasspn: true}) MATCH p=shortestPath((u)-[*1..]->(g:Group)) WHERE g.name =~ "(?i)domain admins@.*" RETURN p
MATCH (u:User {dontreqpreauth: true}) RETURN u.name
MATCH (c:Computer {unconstraineddelegation: true}) RETURN c.name
MATCH (u:User {unconstraineddelegation: true}) RETURN u.name
MATCH (n) WHERE n.allowedtodelegate IS NOT NULL RETURN n.name, n.allowedtodelegate
MATCH (n)-[r:GenericAll]->(d:Domain) RETURN n.name, type(r), d.name
MATCH p=(u {owned: true})-[r:GenericAll|GenericWrite|WriteOwner|WriteDacl|AllExtendedRights|ForceChangePassword|AddMember]->(n) RETURN p
MATCH (n1)-[:MemberOf|GetChanges*1..]->(d:Domain) WITH n1, d
MATCH (n1)-[:MemberOf|GetChangesAll*1..]->(d)
RETURN n1.name, d.name
MATCH (u:User)-[:AdminTo]->(c:Computer) RETURN u.name, c.name
MATCH (g:Group)-[:AdminTo]->(c:Computer) WHERE g.name =~ "(?i)domain users@.*" RETURN c.name
MATCH (u:User)-[:CanRDP]->(c:Computer) RETURN u.name, c.name
MATCH (g:Group)-[:CanRDP]->(c:Computer) WHERE g.name =~ "(?i)domain users@.*" RETURN c.name
MATCH p=shortestPath((u:User {owned: true})-[*1..]->(n {highvalue: true})) WHERE u <> n RETURN p
MATCH (n {highvalue: true}) RETURN n.name, labels(n)
MATCH (u:User {name: "[email protected]"}) SET u.owned = true RETURN u
MATCH (c:Computer {name: "[email protected]"}) SET c.owned = true RETURN c
MATCH p=shortestPath((o {owned: true})-[*1..]->(h {highvalue: true})) WHERE o <> h RETURN p