bloodhound.md (11336B)
1 --- 2 title: "BloodHound & Other Active Directory Enumeration Tools" 3 section: "Windows" 4 sectionSlug: "windows-hardening" 5 sourcePath: "src/windows-hardening/active-directory-methodology/bloodhound.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/active-directory-methodology/bloodhound.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # BloodHound & Other Active Directory Enumeration Tools 14 15 [Adws Enumeration](/hacktricks/windows-hardening/active-directory-methodology/adws-enumeration) 16 17 > NOTE: This page groups some of the most useful utilities to **enumerate** and **visualise** Active Directory relationships. For collection over the stealthy **Active Directory Web Services (ADWS)** channel check the reference above. 18 19 --- 20 21 ## AD Explorer 22 23 [AD Explorer](https://docs.microsoft.com/en-us/sysinternals/downloads/adexplorer) (Sysinternals) is an advanced **AD viewer & editor** which allows: 24 25 * GUI browsing of the directory tree 26 * Editing of object attributes & security descriptors 27 * Snapshot creation / comparison for offline analysis 28 29 ### Quick usage 30 31 1. Start the tool and connect to `dc01.corp.local` with any domain credentials. 32 2. Create an offline snapshot via `File ➜ Create Snapshot`. 33 3. Compare two snapshots with `File ➜ Compare` to spot permission drifts. 34 35 --- 36 37 ## ADRecon 38 39 [ADRecon](https://github.com/adrecon/ADRecon) extracts a large set of artefacts from a domain (ACLs, GPOs, trusts, CA templates …) and produces an **Excel report**. 40 41 ```powershell 42 # On a Windows host in the domain 43 PS C:\> .\ADRecon.ps1 -OutputDir C:\Temp\ADRecon 44 ``` 45 46 --- 47 48 ## BloodHound (graph visualisation) 49 50 [BloodHound](https://github.com/SpecterOps/BloodHound) uses graph theory to reveal hidden privilege relationships inside on-prem AD, Entra ID, and any extra attack-surface data you ingest through OpenGraph.<sup>[[1]](#references)</sup> 51 52 ### Deployment (Docker CE) 53 54 ```bash 55 curl -L https://ghst.ly/getbhce | docker compose -f - up 56 # Web UI ➜ http://localhost:8080 (user: admin / password from logs) 57 ``` 58 59 ### Collectors 60 61 * `SharpHound.exe` / `Invoke-BloodHound` – native or PowerShell variant 62 * `RustHound-CE` – cross-platform CE collector for Linux, macOS, and Windows 63 * `NetExec --bloodhound` – quick LDAP-driven collection from Linux 64 * `AzureHound` – Entra ID enumeration 65 * **SoaPy + BOFHound** – ADWS collection (see link at top) 66 67 > BloodHound CE `v8+` changed the collector output format when OpenGraph landed. After upgrading from legacy BloodHound or older CE installs, re-run discovery with current collectors before importing the data.<sup>[[1]](#references)</sup> 68 69 #### Common SharpHound modes 70 71 ```powershell 72 SharpHound.exe --CollectionMethods All # Full sweep (noisy) 73 SharpHound.exe --CollectionMethods Group,LocalAdmin,Session,Trusts,ACL 74 SharpHound.exe --Stealth --LDAP # Low noise LDAP only 75 SharpHound.exe --CollectionMethods Session --Loop --Loopduration 03:09:41 76 ``` 77 78 The collectors generate JSON which is ingested via the BloodHound GUI. 79 80 #### SharpHound from a non-domain-joined Windows host 81 82 If your operator VM is not joined to the target domain, point DNS to a DC, start a **network-only** shell, verify you can see `SYSVOL`/`NETLOGON` on a DC, and then collect against the remote domain: 83 84 ```batch 85 runas /netonly /user:CORP\svc_bh cmd.exe 86 net view \\dc01.corp.local 87 SharpHound.exe -d corp.local --CollectionMethods Group,LocalAdmin,Session,Trusts,ACL 88 ``` 89 90 This is useful for disposable jump boxes or operator workstations that should not be domain-joined. 91 92 #### Cross-platform collection from Linux/macOS 93 94 ```bash 95 # CE-compatible ZIP from Linux/macOS/Windows 96 rusthound-ce -d corp.local -u svc.collector@corp.local -p 'Passw0rd!' -z 97 98 # Quick LDAP-driven BloodHound dump from Linux 99 nxc ldap dc01.corp.local -u svc.collector -p 'Passw0rd!' --bloodhound --collection All 100 ``` 101 102 `RustHound-CE` is a good default when you want CE-compatible output from a non-Windows host.<sup>[[2]](#references)</sup> `NetExec` is convenient when you are already using it for LDAP validation or spraying and want a quick graph import. For non-AD datasets, BloodHound OpenGraph can be extended with collectors such as [ShareHound](/hacktricks/network-services-pentesting/pentesting-smb/overview).<sup>[[1]](#references)</sup> 103 104 ### ADPathFinder (OpenGraph path prioritisation) 105 106 [ADPathFinder](https://github.com/NetSPI/AD-PathFinder) sits on top of BloodHound CE/OpenGraph when the graph is too large to manually pivot. Instead of only asking whether one principal can reach one target, it calculates shortest paths from many low-privileged users and computers to high-value objects, groups paths that reuse the same edges, and surfaces the shared choke point that should be remediated first.<sup>[[4]](#references)</sup> 107 108 ```bash 109 adpathfinder --setup-bloodhound-api 110 adpathfinder -i SharpHound.zip --ad 111 adpathfinder -i SharpHound.zip MSSQLHound.zip ConfigManBearPig.zip --ad --pwd Contoso,ContosoIT --ntds ntds.txt -p hashcat.potfile 112 ``` 113 114 With `MSSQLHound` and `ConfigManBearPig` data imported, one finding can cross [AD CS](/hacktricks/windows-hardening/active-directory-methodology/ad-certificates), [MSSQL AD abuse](/hacktricks/windows-hardening/active-directory-methodology/abusing-ad-mssql), and [SCCM attack paths](/hacktricks/windows-hardening/active-directory-methodology/sccm-management-point-relay-sql-policy-secrets) instead of leaving them as separate leads.<sup>[[4]](#references)</sup> Example shared path: 115 116 ```text 117 J.REPORTER > MSSQL_HasLogin > j.reporter > MSSQL_ExecuteAs > ReportSvc > 118 MSSQL_Connect > lab-sql01.training.local > MSSQL_LinkedAsAdmin > sccmdb.training.local > 119 MSSQL_ExecuteOnHost (as DA@TRAINING.LOCAL) > SCCMDB.TRAINING.LOCAL > 120 SCCM_AssignAllPermissions > SCCM_Site(TRN) 121 ``` 122 123 - Track the **effective security context** at every edge. A path becomes domain-critical as soon as one transition executes as a privileged domain identity, even if it started from a normal user. 124 - Grouped findings are ideal for **choke-point remediation**: removing one SQL impersonation permission, linked-server trust, certificate-template abuse path, or SCCM assignment can collapse many shortest paths at once. 125 - Re-prioritise "medium" findings with **graph context**. SMB signing disabled, WebClient exposure, delegation mistakes, or NTLM-relayable SQL servers deserve higher priority when the compromised node has onward paths to Domain Admins, Domain Controllers, CAs, or SCCM site servers. 126 - If you also have `NTDS.dit` output and a hashcat potfile, `--pwd` correlates cracked passwords with BloodHound properties so you can quickly separate ordinary password reuse from cracked creds on privileged, Kerberoastable, AS-REP roastable, or path-relevant accounts. 127 128 ### Privilege & logon-right collection 129 130 Windows **token privileges** (e.g., `SeBackupPrivilege`, `SeDebugPrivilege`, `SeImpersonatePrivilege`, `SeAssignPrimaryTokenPrivilege`) can bypass DACL checks, so mapping them domain-wide exposes local LPE edges that ACL-only graphs miss. **Logon rights** (`SeInteractiveLogonRight`, `SeRemoteInteractiveLogonRight`, `SeNetworkLogonRight`, `SeServiceLogonRight`, `SeBatchLogonRight` and their `SeDeny*` counterparts) are enforced by LSA before a token even exists, and denies take precedence, so they materially gate lateral movement (RDP/SMB/scheduled task/service logon).<sup>[[3]](#references)</sup> 131 132 **Run collectors elevated** when possible: UAC creates a filtered token for interactive admins (via `NtFilterToken`), stripping sensitive privileges and marking admin SIDs as deny-only. If you enumerate privileges from a non-elevated shell, high-value privileges will be invisible and BloodHound won’t ingest the edges.<sup>[[3]](#references)</sup> 133 134 Two complementary SharpHound collection strategies now exist:<sup>[[3]](#references)</sup> 135 136 - **GPO/SYSVOL parsing (stealthy, low-privilege):** 137 1. Enumerate GPOs over LDAP (`(objectCategory=groupPolicyContainer)`) and read each `gPCFileSysPath`. 138 2. Fetch `MACHINE\Microsoft\Windows NT\SecEdit\GptTmpl.inf` from SYSVOL and parse the `[Privilege Rights]` section that maps privilege/logon-right names to SIDs. 139 3. Resolve GPO links via `gPLink` on OUs/sites/domains, list computers in the linked containers, and attribute the rights to those machines. 140 4. Upside: works with a normal user and is quiet; downside: only sees rights pushed via GPO (local tweaks are missed). 141 142 - **LSA RPC enumeration (noisy, accurate):** 143 - From a context with local admin on the target, open the Local Security Policy and call `LsaEnumerateAccountsWithUserRight` for each privilege/logon right to enumerate assigned principals over RPC. 144 - Upside: captures rights set locally or outside GPO; downside: noisy network traffic and admin requirement on every host. 145 146 **Example abuse path surfaced by these edges:** `CanRDP` ➜ host where your user also has `SeBackupPrivilege` ➜ start an elevated shell to avoid filtered tokens ➜ use backup semantics to read `SAM` and `SYSTEM` hives despite restrictive DACLs ➜ exfiltrate and run `secretsdump.py` offline to recover the local Administrator NT hash for lateral movement/privilege escalation.<sup>[[3]](#references)</sup> 147 148 ### Prioritising Kerberoasting with BloodHound 149 150 Use graph context to keep roasting targeted: 151 152 1. Collect once with an ADWS-compatible collector and work offline: 153 ```bash 154 rusthound-ce -d corp.local -u svc.collector -p 'Passw0rd!' -c All -z 155 ``` 156 2. Import the ZIP, mark the compromised principal as owned, and run built-in queries (*Kerberoastable Users*, *Shortest Paths to Domain Admins*) to surface SPN accounts with admin/infra rights. 157 3. Prioritise SPNs by blast radius; review `pwdLastSet`, `lastLogon`, and allowed encryption types before cracking. 158 4. Request only selected tickets, crack offline, then re-query BloodHound with the new access: 159 ```bash 160 netexec ldap dc01.corp.local -u svc.collector -p 'Passw0rd!' --kerberoasting kerberoast.txt --spn svc-sql 161 ``` 162 163 ## Group3r 164 165 [Group3r](https://github.com/Group3r/Group3r) enumerates **Group Policy Objects** and highlights misconfigurations. 166 167 ```bash 168 # Execute inside the domain 169 Group3r.exe -f gpo.log # -s to stdout 170 ``` 171 172 --- 173 174 ## PingCastle 175 176 [PingCastle](https://www.pingcastle.com/documentation/) performs a **health-check** of Active Directory and generates an HTML report with risk scoring. 177 178 ```powershell 179 PingCastle.exe --healthcheck --server corp.local --user bob --password "P@ssw0rd!" 180 ``` 181 182 ## References 183 184 - [1] [BloodHound Community Edition v8 Launches with OpenGraph: Identity Attack Paths Beyond Active Directory & Entra ID](https://specterops.io/blog/2025/07/29/bloodhound-community-edition-v8-launches-with-opengraph-identity-attack-paths-beyond-active-directory-entra-id/) 185 - [2] [RustHound-CE](https://github.com/g0h4n/RustHound-CE) 186 - [3] [Beyond ACLs: Mapping Windows Privilege Escalation Paths with BloodHound](https://www.synacktiv.com/en/publications/beyond-acls-mapping-windows-privilege-escalation-paths-with-bloodhound.html) 187 - [4] [ADPathFinder: OpenGraph Attack Path Mapping in BloodHound CE](https://www.netspi.com/blog/technical-blog/network-pentesting/adpathfinder-opengraph-attack-path-mapping-in-bloodhound-ce/)