daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

bloodhound-ce-python.md (9185B)


      1 ---
      2 title: "bloodhound-ce-python"
      3 description: "pipx install bloodhound-ce # provides bloodhound-ce-python"
      4 category: active-directory
      5 subcategory: "Tooling & Recon"
      6 tags: ["active-directory", "kerberos"]
      7 tools: ["Nmap", "Impacket", "BloodHound", "faketime"]
      8 difficulty: intermediate
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/bloodhound-ce-python-cheatsheet.md"
     11 ---
     12 # BloodHound CE Python Cheat Sheet
     13 
     14 > [!info] What this is
     15 > `bloodhound-ce-python` is the Python (impacket-based) ingestor for **BloodHound Community Edition**. It runs remotely from Linux — no domain-joined Windows host needed — and outputs JSON/zip for upload into the BHCE web UI. Based on dirkjanm's `BloodHound.py` (the `bloodhound-ce` branch).
     16 
     17 > [!warning] CE vs legacy output are NOT interchangeable
     18 > BloodHound **CE** uses a different JSON schema from legacy BloodHound. Use `bloodhound-ce-python` for CE and the older `bloodhound-python` for legacy. Uploading the wrong format silently fails or mis-parses. See BloodHound-Python_Cheatsheet for the legacy tool.
     19 
     20 ```bash
     21 pipx install bloodhound-ce      # provides bloodhound-ce-python
     22 # or on Kali:
     23 sudo apt install bloodhound-ce-python
     24 ```
     25 
     26 ---
     27 
     28 ## Table of Contents
     29 
     30 1. [Quick Start](#1-quick-start)
     31 2. [Authentication](#2-authentication)
     32 3. [Collection Methods (`-c`)](#3-collection-methods--c)
     33 4. [DNS & Nameserver](#4-dns--nameserver)
     34 5. [Kerberos & Clock Skew](#5-kerberos--clock-skew)
     35 6. [Ingesting into BHCE](#6-ingesting-into-bhce)
     36 7. [Questions & Answers](#7-questions--answers)
     37 8. [Full Flag Reference](#8-full-flag-reference)
     38 
     39 ---
     40 
     41 ## 1. Quick Start
     42 
     43 <figure class="flow plate corners">
     44   <figcaption class="flow__cap"><span class="flow__kind">Collect to ingest pipeline</span><span class="flow__dir">LR</span></figcaption>
     45   <div class="flow__body">
     46     <div class="flow__diagram" data-dir="lr">
     47       <div class="flow-rank"><div class="flow-node is-entry">Creds or ticket</div></div>
     48       <div class="flow-edge"></div>
     49       <div class="flow-rank"><div class="flow-node">bloodhound-ce-python<span class="sub">-c All --zip</span></div></div>
     50       <div class="flow-edge"></div>
     51       <div class="flow-rank"><div class="flow-node">*.zip output</div></div>
     52       <div class="flow-edge"></div>
     53       <div class="flow-rank"><div class="flow-node">Upload in BHCE UI<span class="sub">Administration -&gt; File Ingest</span></div></div>
     54       <div class="flow-edge"></div>
     55       <div class="flow-rank"><div class="flow-node is-goal">Run Cypher / paths</div></div>
     56     </div>
     57   </div>
     58 </figure>
     59 
     60 ```bash
     61 # Password auth, collect everything, zip the result
     62 bloodhound-ce-python -d corp.local -u user -p 'Passw0rd!' \
     63   -dc dc01.corp.local -ns 10.10.10.5 -c All --zip
     64 ```
     65 
     66 ---
     67 
     68 ## 2. Authentication
     69 
     70 ```bash
     71 # Plaintext password
     72 bloodhound-ce-python -d corp.local -u user -p 'Passw0rd!' -ns 10.10.10.5 -c All --zip
     73 
     74 # NTLM hash (pass-the-hash) — LM:NT or just NT
     75 bloodhound-ce-python -d corp.local -u user --hashes :NTHASH -ns 10.10.10.5 -c All --zip
     76 
     77 # Kerberos ticket from ccache
     78 export KRB5CCNAME=user.ccache
     79 bloodhound-ce-python -d corp.local -u user -k -no-pass -dc dc01.corp.local -ns 10.10.10.5 -c All --zip
     80 
     81 # AES key
     82 bloodhound-ce-python -d corp.local -u user -aesKey <hex> -k -ns 10.10.10.5 -c All --zip
     83 
     84 # Prompt for password interactively (keep it off your shell history)
     85 bloodhound-ce-python -d corp.local -u user -ns 10.10.10.5 -c All --zip     # will prompt
     86 ```
     87 
     88 | Flag | Meaning |
     89 | :-- | :-- |
     90 | `-u` / `--username` | Username (no domain) |
     91 | `-p` / `--password` | Password (omit to be prompted) |
     92 | `--hashes LM:NT` | Pass-the-hash (use `:NT` for NT-only) |
     93 | `-k` / `--kerberos` | Use Kerberos auth (reads `KRB5CCNAME`) |
     94 | `-no-pass` | No password (ticket-based) |
     95 | `-aesKey` | Kerberos AES128/256 key |
     96 | `-d` / `--domain` | Target domain FQDN |
     97 
     98 ---
     99 
    100 ## 3. Collection Methods (`-c`)
    101 
    102 ```bash
    103 -c Default        # Group, LocalAdmin, Session, Trusts, ACL, ObjectProps, Container
    104 -c All            # everything except LoggedOn
    105 -c DCOnly         # LDAP-only, no host connections — quietest, no SMB touch
    106 -c Session,LoggedOn   # comma-separate multiple methods
    107 ```
    108 
    109 | Method | Collects | Noise |
    110 | :-- | :-- | :-- |
    111 | `Group` | Group memberships | low (LDAP) |
    112 | `LocalAdmin` | Local admin rights (SAMR/host) | med |
    113 | `RDP` / `DCOM` / `PSRemote` | Remote-access rights | med |
    114 | `Session` | Active user sessions | med (touches hosts) |
    115 | `LoggedOn` | Logged-on users (needs admin) | high |
    116 | `Trusts` | Domain trusts | low |
    117 | `ACL` | Object ACLs / DACLs | low |
    118 | `ObjectProps` | Attributes (descriptions, pwd age…) | low |
    119 | `Container` | OU/GPO container structure | low |
    120 | `DCOnly` | Everything obtainable via LDAP only | **lowest** |
    121 | `Default` | Sensible bundle (see above) | med |
    122 | `All` | All except LoggedOn | high |
    123 
    124 > [!tip] Start quiet, then go loud
    125 > On a stealth engagement run `-c DCOnly` first (pure LDAP, no SMB/host connections). Only escalate to `Session`/`All` once you accept the extra host traffic.
    126 
    127 ---
    128 
    129 ## 4. DNS & Nameserver
    130 
    131 BloodHound resolves computer names over DNS — point it at the DC or it will fail to resolve internal hosts.
    132 
    133 ```bash
    134 -ns 10.10.10.5                 # use the DC as nameserver (most common)
    135 --dns-tcp                      # force DNS over TCP (some AD DNS blocks UDP)
    136 -d corp.local                  # domain must be the FQDN, not NetBIOS
    137 --dns-timeout 5                # bump if resolution is slow
    138 
    139 # If /etc/resolv.conf already points at the DC you can omit -ns, but explicit is safer.
    140 ```
    141 
    142 > [!warning] "Could not resolve" errors
    143 > Almost always a DNS problem, not auth. Set `-ns <DC-IP>`, add `--dns-tcp`, and make sure `-d` is the full domain FQDN.
    144 
    145 ---
    146 
    147 ## 5. Kerberos & Clock Skew
    148 
    149 When authenticating with `-k`, Kerberos is time-sensitive. If `nmap` showed clock skew, wrap the collector with `faketime` (full guide: faketime-cheatsheet).
    150 
    151 ```bash
    152 # DC is 7h30m ahead -> +7h30m ; use -f so child processes inherit the fake clock
    153 export KRB5CCNAME=user.ccache
    154 faketime -f '+7h30m' bloodhound-ce-python -d corp.local -u user -k -no-pass \
    155   -dc dc01.corp.local -ns 10.10.10.5 -c All --zip
    156 
    157 # Get a TGT first (impacket), then collect under faketime:
    158 faketime -f '+7h30m' impacket-getTGT corp.local/user:'Passw0rd!' -dc-ip 10.10.10.5
    159 export KRB5CCNAME=user.ccache
    160 faketime -f '+7h30m' bloodhound-ce-python -d corp.local -u user -k -no-pass \
    161   -dc dc01.corp.local -ns 10.10.10.5 -c DCOnly --zip
    162 ```
    163 
    164 > [!note] `-dc` should be the FQDN
    165 > For Kerberos, pass the DC's hostname (`-dc dc01.corp.local`), not just its IP — the SPN and realm need to match. Keep `-ns <IP>` for name resolution.
    166 
    167 ---
    168 
    169 ## 6. Ingesting into BHCE
    170 
    171 ```bash
    172 # Collector writes a zip of JSON files:
    173 ls -1 *.zip     # e.g. 20260719_bloodhound.zip
    174 ```
    175 
    176 Then in the BloodHound CE web UI: **Administration → File Ingest → Upload Files**, drop the zip, wait for processing, then run Cypher / pathfinding.
    177 
    178 ```bash
    179 # CLI alternative: bhcli / API upload (if you script ingestion)
    180 # The web UI drag-and-drop is the supported path for one-off engagements.
    181 ```
    182 
    183 > [!tip] Timestamped output
    184 > Rename per host/user so multiple collections don't clobber each other:
    185 > ```bash
    186 > bloodhound-ce-python ... --zip -op "$(date +%Y%m%d)_corp_user"
    187 > ```
    188 
    189 ---
    190 
    191 ## 7. Questions & Answers
    192 
    193 ### Q: What's the quietest collection for a stealth run?
    194 ```bash
    195 bloodhound-ce-python -d corp.local -u user -p 'Passw0rd!' -ns 10.10.10.5 -c DCOnly --zip
    196 ```
    197 **Answer:** `-c DCOnly` — pure LDAP, no SMB/host connections.
    198 
    199 ### Q: I have a Kerberos ticket and the DC clock is skewed. Full command?
    200 ```bash
    201 export KRB5CCNAME=user.ccache
    202 faketime -f '+7h30m' bloodhound-ce-python -d corp.local -u user -k -no-pass \
    203   -dc dc01.corp.local -ns 10.10.10.5 -c All --zip
    204 ```
    205 **Answer:** wrap with `faketime -f` and add `-k -no-pass`.
    206 
    207 ### Q: Collection works but hosts won't resolve. Fix?
    208 **Answer:** DNS. Add `-ns <DC-IP>`, try `--dns-tcp`, ensure `-d` is the FQDN.
    209 
    210 ### Q: Can I pass-the-hash?
    211 ```bash
    212 bloodhound-ce-python -d corp.local -u user --hashes :NTHASH -ns 10.10.10.5 -c All --zip
    213 ```
    214 **Answer:** Yes — `--hashes :NT` (leave LM blank).
    215 
    216 ---
    217 
    218 ## 8. Full Flag Reference
    219 
    220 | Flag | Purpose |
    221 | :-- | :-- |
    222 | `-d`, `--domain` | Domain FQDN |
    223 | `-u`, `--username` | Username |
    224 | `-p`, `--password` | Password (prompts if omitted) |
    225 | `--hashes LM:NT` | Pass-the-hash |
    226 | `-k`, `--kerberos` | Kerberos auth (uses `KRB5CCNAME`) |
    227 | `-no-pass` | No password (ticket) |
    228 | `-aesKey` | Kerberos AES key |
    229 | `-c`, `--collectionmethod` | What to collect (see §3) |
    230 | `-dc` | Domain controller hostname (FQDN) |
    231 | `-gc` | Global catalog server |
    232 | `-ns`, `--nameserver` | DNS server for resolution |
    233 | `--dns-tcp` | DNS over TCP |
    234 | `--dns-timeout` | DNS timeout (s) |
    235 | `--zip` | Zip the JSON output |
    236 | `-op`, `--outputprefix` | Prefix output filenames |
    237 | `--computerfile` | Restrict to hosts in a file |
    238 | `--exclude-dcs` | Skip DCs during host enumeration |
    239 | `-w`, `--workers` | Parallel enumeration threads |
    240 | `-v` | Verbose |
    241 
    242 ---
    243 
    244 ## See Also
    245 
    246 - faketime-cheatsheet — beating Kerberos clock skew when using `-k`
    247 - BloodHound-Python_Cheatsheet — legacy (non-CE) collector
    248 - Kerberos — tickets, TGT/TGS, PKINIT