bloodhound-ce-python.md (9185B)
1 --- 2 title: "bloodhound-ce-python" 3 description: "pipx install bloodhound-ce # provides bloodhound-ce-python" 4 category: active-directory 5 subcategory: "Tooling & Recon" 6 tags: ["active-directory", "kerberos"] 7 tools: ["Nmap", "Impacket", "BloodHound", "faketime"] 8 difficulty: intermediate 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/bloodhound-ce-python-cheatsheet.md" 11 --- 12 # BloodHound CE Python Cheat Sheet 13 14 > [!info] What this is 15 > `bloodhound-ce-python` is the Python (impacket-based) ingestor for **BloodHound Community Edition**. It runs remotely from Linux — no domain-joined Windows host needed — and outputs JSON/zip for upload into the BHCE web UI. Based on dirkjanm's `BloodHound.py` (the `bloodhound-ce` branch). 16 17 > [!warning] CE vs legacy output are NOT interchangeable 18 > BloodHound **CE** uses a different JSON schema from legacy BloodHound. Use `bloodhound-ce-python` for CE and the older `bloodhound-python` for legacy. Uploading the wrong format silently fails or mis-parses. See BloodHound-Python_Cheatsheet for the legacy tool. 19 20 ```bash 21 pipx install bloodhound-ce # provides bloodhound-ce-python 22 # or on Kali: 23 sudo apt install bloodhound-ce-python 24 ``` 25 26 --- 27 28 ## Table of Contents 29 30 1. [Quick Start](#1-quick-start) 31 2. [Authentication](#2-authentication) 32 3. [Collection Methods (`-c`)](#3-collection-methods--c) 33 4. [DNS & Nameserver](#4-dns--nameserver) 34 5. [Kerberos & Clock Skew](#5-kerberos--clock-skew) 35 6. [Ingesting into BHCE](#6-ingesting-into-bhce) 36 7. [Questions & Answers](#7-questions--answers) 37 8. [Full Flag Reference](#8-full-flag-reference) 38 39 --- 40 41 ## 1. Quick Start 42 43 <figure class="flow plate corners"> 44 <figcaption class="flow__cap"><span class="flow__kind">Collect to ingest pipeline</span><span class="flow__dir">LR</span></figcaption> 45 <div class="flow__body"> 46 <div class="flow__diagram" data-dir="lr"> 47 <div class="flow-rank"><div class="flow-node is-entry">Creds or ticket</div></div> 48 <div class="flow-edge"></div> 49 <div class="flow-rank"><div class="flow-node">bloodhound-ce-python<span class="sub">-c All --zip</span></div></div> 50 <div class="flow-edge"></div> 51 <div class="flow-rank"><div class="flow-node">*.zip output</div></div> 52 <div class="flow-edge"></div> 53 <div class="flow-rank"><div class="flow-node">Upload in BHCE UI<span class="sub">Administration -> File Ingest</span></div></div> 54 <div class="flow-edge"></div> 55 <div class="flow-rank"><div class="flow-node is-goal">Run Cypher / paths</div></div> 56 </div> 57 </div> 58 </figure> 59 60 ```bash 61 # Password auth, collect everything, zip the result 62 bloodhound-ce-python -d corp.local -u user -p 'Passw0rd!' \ 63 -dc dc01.corp.local -ns 10.10.10.5 -c All --zip 64 ``` 65 66 --- 67 68 ## 2. Authentication 69 70 ```bash 71 # Plaintext password 72 bloodhound-ce-python -d corp.local -u user -p 'Passw0rd!' -ns 10.10.10.5 -c All --zip 73 74 # NTLM hash (pass-the-hash) — LM:NT or just NT 75 bloodhound-ce-python -d corp.local -u user --hashes :NTHASH -ns 10.10.10.5 -c All --zip 76 77 # Kerberos ticket from ccache 78 export KRB5CCNAME=user.ccache 79 bloodhound-ce-python -d corp.local -u user -k -no-pass -dc dc01.corp.local -ns 10.10.10.5 -c All --zip 80 81 # AES key 82 bloodhound-ce-python -d corp.local -u user -aesKey <hex> -k -ns 10.10.10.5 -c All --zip 83 84 # Prompt for password interactively (keep it off your shell history) 85 bloodhound-ce-python -d corp.local -u user -ns 10.10.10.5 -c All --zip # will prompt 86 ``` 87 88 | Flag | Meaning | 89 | :-- | :-- | 90 | `-u` / `--username` | Username (no domain) | 91 | `-p` / `--password` | Password (omit to be prompted) | 92 | `--hashes LM:NT` | Pass-the-hash (use `:NT` for NT-only) | 93 | `-k` / `--kerberos` | Use Kerberos auth (reads `KRB5CCNAME`) | 94 | `-no-pass` | No password (ticket-based) | 95 | `-aesKey` | Kerberos AES128/256 key | 96 | `-d` / `--domain` | Target domain FQDN | 97 98 --- 99 100 ## 3. Collection Methods (`-c`) 101 102 ```bash 103 -c Default # Group, LocalAdmin, Session, Trusts, ACL, ObjectProps, Container 104 -c All # everything except LoggedOn 105 -c DCOnly # LDAP-only, no host connections — quietest, no SMB touch 106 -c Session,LoggedOn # comma-separate multiple methods 107 ``` 108 109 | Method | Collects | Noise | 110 | :-- | :-- | :-- | 111 | `Group` | Group memberships | low (LDAP) | 112 | `LocalAdmin` | Local admin rights (SAMR/host) | med | 113 | `RDP` / `DCOM` / `PSRemote` | Remote-access rights | med | 114 | `Session` | Active user sessions | med (touches hosts) | 115 | `LoggedOn` | Logged-on users (needs admin) | high | 116 | `Trusts` | Domain trusts | low | 117 | `ACL` | Object ACLs / DACLs | low | 118 | `ObjectProps` | Attributes (descriptions, pwd age…) | low | 119 | `Container` | OU/GPO container structure | low | 120 | `DCOnly` | Everything obtainable via LDAP only | **lowest** | 121 | `Default` | Sensible bundle (see above) | med | 122 | `All` | All except LoggedOn | high | 123 124 > [!tip] Start quiet, then go loud 125 > On a stealth engagement run `-c DCOnly` first (pure LDAP, no SMB/host connections). Only escalate to `Session`/`All` once you accept the extra host traffic. 126 127 --- 128 129 ## 4. DNS & Nameserver 130 131 BloodHound resolves computer names over DNS — point it at the DC or it will fail to resolve internal hosts. 132 133 ```bash 134 -ns 10.10.10.5 # use the DC as nameserver (most common) 135 --dns-tcp # force DNS over TCP (some AD DNS blocks UDP) 136 -d corp.local # domain must be the FQDN, not NetBIOS 137 --dns-timeout 5 # bump if resolution is slow 138 139 # If /etc/resolv.conf already points at the DC you can omit -ns, but explicit is safer. 140 ``` 141 142 > [!warning] "Could not resolve" errors 143 > Almost always a DNS problem, not auth. Set `-ns <DC-IP>`, add `--dns-tcp`, and make sure `-d` is the full domain FQDN. 144 145 --- 146 147 ## 5. Kerberos & Clock Skew 148 149 When authenticating with `-k`, Kerberos is time-sensitive. If `nmap` showed clock skew, wrap the collector with `faketime` (full guide: faketime-cheatsheet). 150 151 ```bash 152 # DC is 7h30m ahead -> +7h30m ; use -f so child processes inherit the fake clock 153 export KRB5CCNAME=user.ccache 154 faketime -f '+7h30m' bloodhound-ce-python -d corp.local -u user -k -no-pass \ 155 -dc dc01.corp.local -ns 10.10.10.5 -c All --zip 156 157 # Get a TGT first (impacket), then collect under faketime: 158 faketime -f '+7h30m' impacket-getTGT corp.local/user:'Passw0rd!' -dc-ip 10.10.10.5 159 export KRB5CCNAME=user.ccache 160 faketime -f '+7h30m' bloodhound-ce-python -d corp.local -u user -k -no-pass \ 161 -dc dc01.corp.local -ns 10.10.10.5 -c DCOnly --zip 162 ``` 163 164 > [!note] `-dc` should be the FQDN 165 > For Kerberos, pass the DC's hostname (`-dc dc01.corp.local`), not just its IP — the SPN and realm need to match. Keep `-ns <IP>` for name resolution. 166 167 --- 168 169 ## 6. Ingesting into BHCE 170 171 ```bash 172 # Collector writes a zip of JSON files: 173 ls -1 *.zip # e.g. 20260719_bloodhound.zip 174 ``` 175 176 Then in the BloodHound CE web UI: **Administration → File Ingest → Upload Files**, drop the zip, wait for processing, then run Cypher / pathfinding. 177 178 ```bash 179 # CLI alternative: bhcli / API upload (if you script ingestion) 180 # The web UI drag-and-drop is the supported path for one-off engagements. 181 ``` 182 183 > [!tip] Timestamped output 184 > Rename per host/user so multiple collections don't clobber each other: 185 > ```bash 186 > bloodhound-ce-python ... --zip -op "$(date +%Y%m%d)_corp_user" 187 > ``` 188 189 --- 190 191 ## 7. Questions & Answers 192 193 ### Q: What's the quietest collection for a stealth run? 194 ```bash 195 bloodhound-ce-python -d corp.local -u user -p 'Passw0rd!' -ns 10.10.10.5 -c DCOnly --zip 196 ``` 197 **Answer:** `-c DCOnly` — pure LDAP, no SMB/host connections. 198 199 ### Q: I have a Kerberos ticket and the DC clock is skewed. Full command? 200 ```bash 201 export KRB5CCNAME=user.ccache 202 faketime -f '+7h30m' bloodhound-ce-python -d corp.local -u user -k -no-pass \ 203 -dc dc01.corp.local -ns 10.10.10.5 -c All --zip 204 ``` 205 **Answer:** wrap with `faketime -f` and add `-k -no-pass`. 206 207 ### Q: Collection works but hosts won't resolve. Fix? 208 **Answer:** DNS. Add `-ns <DC-IP>`, try `--dns-tcp`, ensure `-d` is the FQDN. 209 210 ### Q: Can I pass-the-hash? 211 ```bash 212 bloodhound-ce-python -d corp.local -u user --hashes :NTHASH -ns 10.10.10.5 -c All --zip 213 ``` 214 **Answer:** Yes — `--hashes :NT` (leave LM blank). 215 216 --- 217 218 ## 8. Full Flag Reference 219 220 | Flag | Purpose | 221 | :-- | :-- | 222 | `-d`, `--domain` | Domain FQDN | 223 | `-u`, `--username` | Username | 224 | `-p`, `--password` | Password (prompts if omitted) | 225 | `--hashes LM:NT` | Pass-the-hash | 226 | `-k`, `--kerberos` | Kerberos auth (uses `KRB5CCNAME`) | 227 | `-no-pass` | No password (ticket) | 228 | `-aesKey` | Kerberos AES key | 229 | `-c`, `--collectionmethod` | What to collect (see §3) | 230 | `-dc` | Domain controller hostname (FQDN) | 231 | `-gc` | Global catalog server | 232 | `-ns`, `--nameserver` | DNS server for resolution | 233 | `--dns-tcp` | DNS over TCP | 234 | `--dns-timeout` | DNS timeout (s) | 235 | `--zip` | Zip the JSON output | 236 | `-op`, `--outputprefix` | Prefix output filenames | 237 | `--computerfile` | Restrict to hosts in a file | 238 | `--exclude-dcs` | Skip DCs during host enumeration | 239 | `-w`, `--workers` | Parallel enumeration threads | 240 | `-v` | Verbose | 241 242 --- 243 244 ## See Also 245 246 - faketime-cheatsheet — beating Kerberos clock skew when using `-k` 247 - BloodHound-Python_Cheatsheet — legacy (non-CE) collector 248 - Kerberos — tickets, TGT/TGS, PKINIT