This article outlines the ADLocalGroup node in BloodHound, it describes the node’s properties and possible incoming/outgoing edges.

Representation

The ADLocalGroup node represents a local group on a domain computer.

Node properties

The node supports the properties of the table. Three types of property names will be used, depending on where the property is found:

  • Entity Panel: Name shown in the BloodHound UI.
  • Database: Name stored in the BloodHound database and returned by the BloodHound API. This is to be used when running Cypher queries.
  • Directory: Name collected from the directory the node is stored in, for example, the LDAP name for an Active Directory property.
Entity PanelDatabaseDirectoryDescription
Object IDobjectid-The object’s unique identifier in the directory.
Last Collected by BloodHoundlastseen-When the object was last collected and ingested in BloodHound.
-nameGroup name + computer FQDNName of the group + @ + the FQDN of the computer which it exists on.

Edges

The following edge types may be linked to/from this node. See the edges documentation for more information on the edge types.

Incoming edges

Edge typeEntity panel category
MemberOfLocalGroup-

Outgoing edges

Edge typeEntity panel category
LocalToComputer-