The logic for adding members to the special ENTERPRISE DOMAIN CONTROLLERS group with the well-known SID of S-1-5-9 is to include all machine accounts with Unconstrained Delegation which I believe are causing false positives. The offending line is referenced below.
|
if computer.properties().unconstraineddelegation().to_owned() |
The function also references Bloodhound.py functionality which doesn't do this so I was wondering if there is rationale behind this?