daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

bloodhound.md (11336B)


      1 ---
      2 title: "BloodHound & Other Active Directory Enumeration Tools"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/active-directory-methodology/bloodhound.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/active-directory-methodology/bloodhound.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # BloodHound & Other Active Directory Enumeration Tools
     14 
     15 [Adws Enumeration](/hacktricks/windows-hardening/active-directory-methodology/adws-enumeration)
     16 
     17 > NOTE: This page groups some of the most useful utilities to **enumerate** and **visualise** Active Directory relationships.  For collection over the stealthy **Active Directory Web Services (ADWS)** channel check the reference above.
     18 
     19 ---
     20 
     21 ## AD Explorer
     22 
     23 [AD Explorer](https://docs.microsoft.com/en-us/sysinternals/downloads/adexplorer) (Sysinternals) is an advanced **AD viewer & editor** which allows:
     24 
     25 * GUI browsing of the directory tree
     26 * Editing of object attributes & security descriptors
     27 * Snapshot creation / comparison for offline analysis
     28 
     29 ### Quick usage
     30 
     31 1. Start the tool and connect to `dc01.corp.local` with any domain credentials.
     32 2. Create an offline snapshot via `File ➜ Create Snapshot`.
     33 3. Compare two snapshots with `File ➜ Compare` to spot permission drifts.
     34 
     35 ---
     36 
     37 ## ADRecon
     38 
     39 [ADRecon](https://github.com/adrecon/ADRecon) extracts a large set of artefacts from a domain (ACLs, GPOs, trusts, CA templates …) and produces an **Excel report**.
     40 
     41 ```powershell
     42 # On a Windows host in the domain
     43 PS C:\> .\ADRecon.ps1 -OutputDir C:\Temp\ADRecon
     44 ```
     45 
     46 ---
     47 
     48 ## BloodHound (graph visualisation)
     49 
     50 [BloodHound](https://github.com/SpecterOps/BloodHound) uses graph theory to reveal hidden privilege relationships inside on-prem AD, Entra ID, and any extra attack-surface data you ingest through OpenGraph.<sup>[[1]](#references)</sup>
     51 
     52 ### Deployment (Docker CE)
     53 
     54 ```bash
     55 curl -L https://ghst.ly/getbhce | docker compose -f - up
     56 # Web UI ➜ http://localhost:8080  (user: admin / password from logs)
     57 ```
     58 
     59 ### Collectors
     60 
     61 * `SharpHound.exe` / `Invoke-BloodHound` – native or PowerShell variant
     62 * `RustHound-CE` – cross-platform CE collector for Linux, macOS, and Windows
     63 * `NetExec --bloodhound` – quick LDAP-driven collection from Linux
     64 * `AzureHound` – Entra ID enumeration
     65 * **SoaPy + BOFHound** – ADWS collection (see link at top)
     66 
     67 > BloodHound CE `v8+` changed the collector output format when OpenGraph landed. After upgrading from legacy BloodHound or older CE installs, re-run discovery with current collectors before importing the data.<sup>[[1]](#references)</sup>
     68 
     69 #### Common SharpHound modes
     70 
     71 ```powershell
     72 SharpHound.exe --CollectionMethods All               # Full sweep (noisy)
     73 SharpHound.exe --CollectionMethods Group,LocalAdmin,Session,Trusts,ACL
     74 SharpHound.exe --Stealth --LDAP                      # Low noise LDAP only
     75 SharpHound.exe --CollectionMethods Session --Loop --Loopduration 03:09:41
     76 ```
     77 
     78 The collectors generate JSON which is ingested via the BloodHound GUI.
     79 
     80 #### SharpHound from a non-domain-joined Windows host
     81 
     82 If your operator VM is not joined to the target domain, point DNS to a DC, start a **network-only** shell, verify you can see `SYSVOL`/`NETLOGON` on a DC, and then collect against the remote domain:
     83 
     84 ```batch
     85 runas /netonly /user:CORP\svc_bh cmd.exe
     86 net view \\dc01.corp.local
     87 SharpHound.exe -d corp.local --CollectionMethods Group,LocalAdmin,Session,Trusts,ACL
     88 ```
     89 
     90 This is useful for disposable jump boxes or operator workstations that should not be domain-joined.
     91 
     92 #### Cross-platform collection from Linux/macOS
     93 
     94 ```bash
     95 # CE-compatible ZIP from Linux/macOS/Windows
     96 rusthound-ce -d corp.local -u svc.collector@corp.local -p 'Passw0rd!' -z
     97 
     98 # Quick LDAP-driven BloodHound dump from Linux
     99 nxc ldap dc01.corp.local -u svc.collector -p 'Passw0rd!' --bloodhound --collection All
    100 ```
    101 
    102 `RustHound-CE` is a good default when you want CE-compatible output from a non-Windows host.<sup>[[2]](#references)</sup> `NetExec` is convenient when you are already using it for LDAP validation or spraying and want a quick graph import. For non-AD datasets, BloodHound OpenGraph can be extended with collectors such as [ShareHound](/hacktricks/network-services-pentesting/pentesting-smb/overview).<sup>[[1]](#references)</sup>
    103 
    104 ### ADPathFinder (OpenGraph path prioritisation)
    105 
    106 [ADPathFinder](https://github.com/NetSPI/AD-PathFinder) sits on top of BloodHound CE/OpenGraph when the graph is too large to manually pivot. Instead of only asking whether one principal can reach one target, it calculates shortest paths from many low-privileged users and computers to high-value objects, groups paths that reuse the same edges, and surfaces the shared choke point that should be remediated first.<sup>[[4]](#references)</sup>
    107 
    108 ```bash
    109 adpathfinder --setup-bloodhound-api
    110 adpathfinder -i SharpHound.zip --ad
    111 adpathfinder -i SharpHound.zip MSSQLHound.zip ConfigManBearPig.zip --ad --pwd Contoso,ContosoIT --ntds ntds.txt -p hashcat.potfile
    112 ```
    113 
    114 With `MSSQLHound` and `ConfigManBearPig` data imported, one finding can cross [AD CS](/hacktricks/windows-hardening/active-directory-methodology/ad-certificates), [MSSQL AD abuse](/hacktricks/windows-hardening/active-directory-methodology/abusing-ad-mssql), and [SCCM attack paths](/hacktricks/windows-hardening/active-directory-methodology/sccm-management-point-relay-sql-policy-secrets) instead of leaving them as separate leads.<sup>[[4]](#references)</sup> Example shared path:
    115 
    116 ```text
    117 J.REPORTER > MSSQL_HasLogin > j.reporter > MSSQL_ExecuteAs > ReportSvc >
    118 MSSQL_Connect > lab-sql01.training.local > MSSQL_LinkedAsAdmin > sccmdb.training.local >
    119 MSSQL_ExecuteOnHost (as DA@TRAINING.LOCAL) > SCCMDB.TRAINING.LOCAL >
    120 SCCM_AssignAllPermissions > SCCM_Site(TRN)
    121 ```
    122 
    123 - Track the **effective security context** at every edge. A path becomes domain-critical as soon as one transition executes as a privileged domain identity, even if it started from a normal user.
    124 - Grouped findings are ideal for **choke-point remediation**: removing one SQL impersonation permission, linked-server trust, certificate-template abuse path, or SCCM assignment can collapse many shortest paths at once.
    125 - Re-prioritise "medium" findings with **graph context**. SMB signing disabled, WebClient exposure, delegation mistakes, or NTLM-relayable SQL servers deserve higher priority when the compromised node has onward paths to Domain Admins, Domain Controllers, CAs, or SCCM site servers.
    126 - If you also have `NTDS.dit` output and a hashcat potfile, `--pwd` correlates cracked passwords with BloodHound properties so you can quickly separate ordinary password reuse from cracked creds on privileged, Kerberoastable, AS-REP roastable, or path-relevant accounts.
    127 
    128 ### Privilege & logon-right collection
    129 
    130 Windows **token privileges** (e.g., `SeBackupPrivilege`, `SeDebugPrivilege`, `SeImpersonatePrivilege`, `SeAssignPrimaryTokenPrivilege`) can bypass DACL checks, so mapping them domain-wide exposes local LPE edges that ACL-only graphs miss. **Logon rights** (`SeInteractiveLogonRight`, `SeRemoteInteractiveLogonRight`, `SeNetworkLogonRight`, `SeServiceLogonRight`, `SeBatchLogonRight` and their `SeDeny*` counterparts) are enforced by LSA before a token even exists, and denies take precedence, so they materially gate lateral movement (RDP/SMB/scheduled task/service logon).<sup>[[3]](#references)</sup>
    131 
    132 **Run collectors elevated** when possible: UAC creates a filtered token for interactive admins (via `NtFilterToken`), stripping sensitive privileges and marking admin SIDs as deny-only. If you enumerate privileges from a non-elevated shell, high-value privileges will be invisible and BloodHound won’t ingest the edges.<sup>[[3]](#references)</sup>
    133 
    134 Two complementary SharpHound collection strategies now exist:<sup>[[3]](#references)</sup>
    135 
    136 - **GPO/SYSVOL parsing (stealthy, low-privilege):**
    137   1. Enumerate GPOs over LDAP (`(objectCategory=groupPolicyContainer)`) and read each `gPCFileSysPath`.
    138   2. Fetch `MACHINE\Microsoft\Windows NT\SecEdit\GptTmpl.inf` from SYSVOL and parse the `[Privilege Rights]` section that maps privilege/logon-right names to SIDs.
    139   3. Resolve GPO links via `gPLink` on OUs/sites/domains, list computers in the linked containers, and attribute the rights to those machines.
    140   4. Upside: works with a normal user and is quiet; downside: only sees rights pushed via GPO (local tweaks are missed).
    141 
    142 - **LSA RPC enumeration (noisy, accurate):**
    143   - From a context with local admin on the target, open the Local Security Policy and call `LsaEnumerateAccountsWithUserRight` for each privilege/logon right to enumerate assigned principals over RPC.
    144   - Upside: captures rights set locally or outside GPO; downside: noisy network traffic and admin requirement on every host.
    145 
    146 **Example abuse path surfaced by these edges:** `CanRDP` ➜ host where your user also has `SeBackupPrivilege` ➜ start an elevated shell to avoid filtered tokens ➜ use backup semantics to read `SAM` and `SYSTEM` hives despite restrictive DACLs ➜ exfiltrate and run `secretsdump.py` offline to recover the local Administrator NT hash for lateral movement/privilege escalation.<sup>[[3]](#references)</sup>
    147 
    148 ### Prioritising Kerberoasting with BloodHound
    149 
    150 Use graph context to keep roasting targeted:
    151 
    152 1. Collect once with an ADWS-compatible collector and work offline:
    153    ```bash
    154    rusthound-ce -d corp.local -u svc.collector -p 'Passw0rd!' -c All -z
    155    ```
    156 2. Import the ZIP, mark the compromised principal as owned, and run built-in queries (*Kerberoastable Users*, *Shortest Paths to Domain Admins*) to surface SPN accounts with admin/infra rights.
    157 3. Prioritise SPNs by blast radius; review `pwdLastSet`, `lastLogon`, and allowed encryption types before cracking.
    158 4. Request only selected tickets, crack offline, then re-query BloodHound with the new access:
    159    ```bash
    160    netexec ldap dc01.corp.local -u svc.collector -p 'Passw0rd!' --kerberoasting kerberoast.txt --spn svc-sql
    161    ```
    162 
    163 ## Group3r
    164 
    165 [Group3r](https://github.com/Group3r/Group3r) enumerates **Group Policy Objects** and highlights misconfigurations.
    166 
    167 ```bash
    168 # Execute inside the domain
    169 Group3r.exe -f gpo.log   # -s to stdout
    170 ```
    171 
    172 ---
    173 
    174 ## PingCastle
    175 
    176 [PingCastle](https://www.pingcastle.com/documentation/) performs a **health-check** of Active Directory and generates an HTML report with risk scoring.
    177 
    178 ```powershell
    179 PingCastle.exe --healthcheck --server corp.local --user bob --password "P@ssw0rd!"
    180 ```
    181 
    182 ## References
    183 
    184 - [1] [BloodHound Community Edition v8 Launches with OpenGraph: Identity Attack Paths Beyond Active Directory & Entra ID](https://specterops.io/blog/2025/07/29/bloodhound-community-edition-v8-launches-with-opengraph-identity-attack-paths-beyond-active-directory-entra-id/)
    185 - [2] [RustHound-CE](https://github.com/g0h4n/RustHound-CE)
    186 - [3] [Beyond ACLs: Mapping Windows Privilege Escalation Paths with BloodHound](https://www.synacktiv.com/en/publications/beyond-acls-mapping-windows-privilege-escalation-paths-with-bloodhound.html)
    187 - [4] [ADPathFinder: OpenGraph Attack Path Mapping in BloodHound CE](https://www.netspi.com/blog/technical-blog/network-pentesting/adpathfinder-opengraph-attack-path-mapping-in-bloodhound-ce/)