Repository navigation
Update registry collection methods - #58
Conversation
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the You can disable this status message by setting the WalkthroughEdits to docs/collect-data/permissions.mdx standardize registry path formatting, restructure DC and CA registry sections, add specific keys (e.g., VulnerableChannelAllowList, RoleSeparationEnabled), switch EditFlags to use an Active Policy placeholder path, and make minor spacing/link formatting adjustments. Changes
Estimated code review effort🎯 2 (Simple) | ⏱️ ~10 minutes Possibly related PRs
Suggested labels
Suggested reviewers
Poem
Pre-merge checks (3 passed)✅ Passed checks (3 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@coderabbitai review |
✅ Actions performedReview triggered.
|
There was a problem hiding this comment.
Actionable comments posted: 1
🧹 Nitpick comments (1)
docs/collect-data/permissions.mdx (1)
108-110: Tighten wording for accuracy and flow.Minor phrasing tweaks improve clarity; no change in meaning.
-SharpHound collects the registry key values `Kdc\StrongCertificateBindingEnforcement` and `Schannel\CertificateMappingMethods` (described [here](https://support.microsoft.com/en-us/topic/kb5014754-certificate-based-authentication-changes-on-windows-domain-controllers-ad2c23b0-15d8-4340-a468-4d4f3b188f16)) to determine the allowed certificate mapping methods by the DCs. The BloodHound ADCS edges ESC6, ESC9, and ESC10 require this data to be collected. +SharpHound collects the registry values `Kdc\StrongCertificateBindingEnforcement` and `Schannel\CertificateMappingMethods` (described [here](https://support.microsoft.com/en-us/topic/kb5014754-certificate-based-authentication-changes-on-windows-domain-controllers-ad2c23b0-15d8-4340-a468-4d4f3b188f16)) to determine the allowed certificate mapping methods on domain controllers (DCs). The BloodHound ADCS edges ESC6, ESC9, and ESC10 require this data to be collected. -SharpHound Enterprise additionally collects the `VulnerableChannelAllowList` value under `SYSTEM\CurrentControlSet\Services\Netlogon\Parameters` (described [here](https://support.microsoft.com/en-us/topic/how-to-manage-the-changes-in-netlogon-secure-channel-connections-associated-with-cve-2020-1472-f7e8cc17-0309-1d6a-304e-5ba73cd1a11e#theGroupPolicy)) to determine accounts allowed Netlogon secure channel without secure RPC. +SharpHound Enterprise additionally collects the `VulnerableChannelAllowList` value under `SYSTEM\CurrentControlSet\Services\Netlogon\Parameters` (described [here](https://support.microsoft.com/en-us/topic/how-to-manage-the-changes-in-netlogon-secure-channel-connections-associated-with-cve-2020-1472-f7e8cc17-0309-1d6a-304e-5ba73cd1a11e#theGroupPolicy)) to determine which accounts are allowed to use Netlogon secure channel connections without secure RPC.
jeff-matthews
left a comment
There was a problem hiding this comment.
Looks good. I just made a couple of minor editorial suggestions.
Describe collection of additional DC reg key.
Corresponding PRs:
Add netlogon reg key by JonasBK · Pull Request #244 · SpecterOps/SharpHoundCommon
Add netlogon reg key by JonasBK · Pull Request #61 · SpecterOps/sharphound-enterprise
Add netlogon reg key by JonasBK · Pull Request #170 · SpecterOps/SharpHound
Add netlogon DC property by JonasBK · Pull Request #1845 · SpecterOps/BloodHound
Also fixed a couple of related things:
Screenshots:

Summary by CodeRabbit
Documentation
Chores