SpecterOps / SpecterOps/BloodHound

Editable notes feature to "Pwned Objects"

Open
#237 0 comments 3 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

enhancement ticketed
Dominant language
Go
Stars
3.4k
Forks
376
Avg merge
2d 7h
Merged PRs (30d)
97

Description

Feature Description:

It would be very helpful if there was a feature that would allow users to add notes next to "Pwned Objects". Auditors could add credentials (hashes/passwords) or even upload tokens (tickets/certificates) These would be useful for engagements in large environments. Moreover, auditors could add useful notes for "Pwned Objects" (e.g "Password reuse in another domain")

Current Behavior:

Currently BloodHoundCE does not offer any option to add notes to nodes.

Desired Behavior:

BloodHoundCE should add the option of adding notes next to nodes.

Use Case:

Auditors could easily access Pwned Objects credentials and quickly deploy them to perform post-exploitation actions.

Implementation Suggestions:

Additional Information:

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No files, tests, or entry points are named. Start by locating the Pwned Objects node view and the model or storage path for node-associated data; clarify note visibility, credential and token handling, persistence, and access controls before implementing, then add coverage for creating, displaying, and retrieving notes.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
full-stack
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.