This article outlines the ADLocalUser node in BloodHound, it describes the node's properties and possible incoming/outgoing edges.
Representation
The ADLocalUser node represents a local user on a domain computer.
Node properties
The node supports the properties of the table. Three types of property names will be used, depending on where the property is found:
- Entity Panel: Name shown in the BloodHound UI.
- Database: Name stored in the BloodHound database and returned by the BloodHound API. This is to be used when running Cypher queries.
- Directory: Name collected from the directory the node is stored in, for example, the LDAP name for an Active Directory property.
Entity Panel | Database | Directory | Description |
Object ID |
objectid |
- | The object's unique identifier in the directory. |
Last Collected by BloodHound | lastseen | - | When the object was last collected and ingested in BloodHound. |
- | name | Group name + computer FQDN | Name of the group + @ + the FQDN of the computer which it exists on. |
Edges
The following edge types may be linked from this node. See the edges documentation for more information on the edge types.
Incoming edges
Edge type | Entity panel category |
MemberOfLocalGroup | - |
Updated