mark_owned
Mark an Active Directory principal as attacker-owned to track it in BloodHound, storing the flag app-side without writing to the database.
Instructions
Mark a principal (by name/objectid) as attacker-owned (stored app-side, not written to the DB).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| target | Yes |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |