daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

bloodhound-python.md (22962B)


      1 ---
      2 title: "BloodHound-Python_"
      3 description: "bloodhound-python --help"
      4 category: active-directory
      5 subcategory: "Tooling & Recon"
      6 tags: ["active-directory", "kerberos"]
      7 tools: ["Nmap", "NetExec", "Impacket", "BloodHound", "SharpHound"]
      8 difficulty: intermediate
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/BloodHound-Python_Cheatsheet.md"
     11 ---
     12 # ๐Ÿ BloodHound-Python Cheatsheet
     13 
     14 > **Complete guide to using bloodhound-python for remote Active Directory enumeration**
     15 
     16 ---
     17 
     18 ## ๐Ÿ“‹ Table of Contents
     19 
     20 - [Overview](#-overview)
     21 - [Installation](#-installation)
     22 - [Basic Usage](#-basic-usage)
     23 - [Authentication Methods](#-authentication-methods)
     24 - [Collection Methods](#-collection-methods)
     25 - [Advanced Options](#-advanced-options)
     26 - [Output Options](#-output-options)
     27 - [Common Usage Scenarios](#-common-usage-scenarios)
     28 - [SharpHound Comparison](#-sharphound-comparison)
     29 - [Troubleshooting](#-troubleshooting)
     30 - [Post-Collection](#-post-collection)
     31 
     32 ---
     33 
     34 ## ๐ŸŽฏ Overview
     35 
     36 **bloodhound-python** (also known as **BloodHound.py**) is a Python-based ingestor for BloodHound that allows remote data collection from Active Directory environments without needing to execute code on Windows systems.
     37 
     38 ### Key Features
     39 - โœ… Remote enumeration from Linux
     40 - โœ… No code execution on target required
     41 - โœ… LDAP-based collection
     42 - โœ… Multiple authentication methods
     43 - โœ… Kerberos support
     44 - โœ… Outputs JSON files for BloodHound
     45 
     46 ### When to Use bloodhound-python vs SharpHound
     47 
     48 | Scenario | Tool |
     49 |----------|------|
     50 | Have valid AD credentials, attacking from Linux | **bloodhound-python** |
     51 | Have shell access on Windows machine | **SharpHound** |
     52 | Need session enumeration | **SharpHound** |
     53 | Remote enumeration only | **bloodhound-python** |
     54 | Need local admin rights detection | **SharpHound** |
     55 | Stealth is priority (no Windows execution) | **bloodhound-python** |
     56 
     57 ---
     58 
     59 ## ๐Ÿ“ฆ Installation
     60 
     61 ### Kali Linux (Pre-installed)
     62 
     63 ```bash
     64 # Usually pre-installed on Kali
     65 bloodhound-python --help
     66 
     67 # If not installed
     68 sudo apt update
     69 sudo apt install bloodhound.py
     70 ```
     71 
     72 ### Manual Installation (pip)
     73 
     74 ```bash
     75 # Install via pip
     76 pip3 install bloodhound
     77 
     78 # Or install from GitHub (latest version)
     79 git clone https://github.com/fox-it/BloodHound.py.git
     80 cd BloodHound.py
     81 pip3 install .
     82 
     83 # Verify installation
     84 bloodhound-python --version
     85 ```
     86 
     87 ### Dependencies
     88 
     89 ```bash
     90 # Required dependencies
     91 pip3 install dnspython ldap3 impacket
     92 
     93 # For Kerberos support
     94 sudo apt install krb5-user
     95 pip3 install pyasn1 pyasn1-modules
     96 ```
     97 
     98 ---
     99 
    100 ## ๐Ÿš€ Basic Usage
    101 
    102 ### Standard Execution
    103 
    104 ```bash
    105 # Basic enumeration with all collection methods
    106 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41
    107 
    108 # With automatic ZIP creation
    109 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip
    110 
    111 # Specify output directory
    112 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 -o /tmp/bloodhound
    113 
    114 # Custom collection name
    115 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --collectionmethod all
    116 ```
    117 
    118 ### Essential Parameters
    119 
    120 | Parameter | Description | Example |
    121 |-----------|-------------|---------|
    122 | `-c, --collectionmethod` | Collection method(s) | `-c all` |
    123 | `-u, --username` | Username | `-u judith.mader` |
    124 | `-p, --password` | Password | `-p judith09` |
    125 | `-d, --domain` | Domain name | `-d certified.htb` |
    126 | `-ns, --nameserver` | Domain Controller IP | `-ns 10.10.11.41` |
    127 | `-dc, --domain-controller` | DC hostname | `-dc DC01.certified.htb` |
    128 
    129 ---
    130 
    131 ## ๐Ÿ” Authentication Methods
    132 
    133 ### Method 1: Username & Password
    134 
    135 ```bash
    136 # Basic password authentication
    137 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41
    138 
    139 # With domain prefix
    140 bloodhound-python -c all -u certified.htb/judith.mader -p judith09 -ns 10.10.11.41
    141 
    142 # Using domain\username format
    143 bloodhound-python -c all -u 'certified.htb\judith.mader' -p judith09 -ns 10.10.11.41
    144 ```
    145 
    146 ### Method 2: NTLM Hash (Pass-the-Hash)
    147 
    148 ```bash
    149 # Using NTLM hash
    150 bloodhound-python -c all -u judith.mader --hashes :8846f7eaee8fb117ad06bdd830b7586c -d certified.htb -ns 10.10.11.41
    151 
    152 # With LM hash (usually empty)
    153 bloodhound-python -c all -u judith.mader --hashes aad3b435b51404eeaad3b435b51404ee:8846f7eaee8fb117ad06bdd830b7586c -d certified.htb -ns 10.10.11.41
    154 
    155 # From secretsdump output
    156 bloodhound-python -c all -u administrator --hashes aad3b435b51404eeaad3b435b51404ee:32693b11e6aa90eb43d32c72a07ceea6 -d certified.htb -ns 10.10.11.41
    157 ```
    158 
    159 ### Method 3: Kerberos Authentication
    160 
    161 ```bash
    162 # Using Kerberos ticket
    163 bloodhound-python -c all -u judith.mader -d certified.htb -ns 10.10.11.41 -k
    164 
    165 # With ticket cache
    166 export KRB5CCNAME=/tmp/judith.ccache
    167 bloodhound-python -c all -u judith.mader -d certified.htb -ns 10.10.11.41 -k --kerberos
    168 
    169 # Using AES key
    170 bloodhound-python -c all -u judith.mader -d certified.htb -ns 10.10.11.41 --aesKey <aes_key>
    171 ```
    172 
    173 ### Method 4: No Password (with .ccache file)
    174 
    175 ```bash
    176 # Set Kerberos ticket cache
    177 export KRB5CCNAME=/tmp/krb5cc_judith.mader
    178 
    179 # Run without password
    180 bloodhound-python -c all -u judith.mader -d certified.htb -ns 10.10.11.41 -k --no-pass
    181 ```
    182 
    183 ### Method 5: Interactive Password Prompt
    184 
    185 ```bash
    186 # Prompt for password (more secure, no password in bash history)
    187 bloodhound-python -c all -u judith.mader -d certified.htb -ns 10.10.11.41
    188 # Will prompt: Password:
    189 ```
    190 
    191 ---
    192 
    193 ## ๐ŸŽฏ Collection Methods
    194 
    195 ### Available Collection Methods
    196 
    197 | Method | Description | What It Collects |
    198 |--------|-------------|------------------|
    199 | **all** | All collection methods | Everything below |
    200 | **group** | Group memberships | Groups and members |
    201 | **localadmin** | Local admin rights | Local admin relationships |
    202 | **session** | User sessions | Logged on users |
    203 | **trusts** | Domain trusts | Trust relationships |
    204 | **default** | Default safe methods | Group, LocalAdmin, Session, Trusts |
    205 | **container** | Container info | OUs and Containers |
    206 | **psremote** | PSRemote rights | PowerShell remoting access |
    207 | **dcom** | DCOM rights | DCOM execution rights |
    208 | **rdp** | RDP rights | Remote Desktop access |
    209 | **objectprops** | Object properties | Additional AD object properties |
    210 | **acl** | ACL enumeration | Access Control Lists |
    211 | **loggedon** | Logged on users | Currently logged on users |
    212 
    213 ### Collection Method Usage
    214 
    215 ```bash
    216 # All methods (most comprehensive)
    217 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41
    218 
    219 # Default methods only
    220 bloodhound-python -c default -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41
    221 
    222 # Specific single method
    223 bloodhound-python -c group -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41
    224 
    225 # Multiple specific methods
    226 bloodhound-python -c group,acl,trusts -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41
    227 
    228 # All except sessions (less noisy)
    229 bloodhound-python -c group,localadmin,trusts,acl,container,objectprops -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41
    230 ```
    231 
    232 ### Method Comparison
    233 
    234 ```bash
    235 # Quick enumeration (fastest)
    236 bloodhound-python -c group,trusts -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41
    237 
    238 # Comprehensive enumeration (slower but complete)
    239 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41
    240 
    241 # Stealth enumeration (LDAP only, no SMB)
    242 bloodhound-python -c group,acl,objectprops,container,trusts -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41
    243 ```
    244 
    245 ---
    246 
    247 ## โš™๏ธ Advanced Options
    248 
    249 ### Domain Controller Specification
    250 
    251 ```bash
    252 # Using IP address (nameserver)
    253 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41
    254 
    255 # Using hostname (domain controller)
    256 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -dc dc01.certified.htb
    257 
    258 # Using FQDN
    259 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -dc dc01.certified.htb -ns 10.10.11.41
    260 
    261 # Multiple DCs (will try in order)
    262 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41,10.10.11.42
    263 ```
    264 
    265 ### LDAP Configuration
    266 
    267 ```bash
    268 # Specify LDAP port (default: 389)
    269 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --ldapport 389
    270 
    271 # Use LDAPS (secure LDAP, port 636)
    272 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --ldapport 636
    273 
    274 # Use Global Catalog port
    275 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --ldapport 3268
    276 
    277 # Use GC-SSL
    278 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --ldapport 3269
    279 
    280 # Disable certificate verification (LDAPS)
    281 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --ldapport 636 --disable-signing
    282 ```
    283 
    284 ### DNS Configuration
    285 
    286 ```bash
    287 # Use custom DNS server
    288 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --dns-tcp
    289 
    290 # Force TCP for DNS queries
    291 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --dns-tcp
    292 
    293 # Specify DNS timeout
    294 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --dns-timeout 5
    295 ```
    296 
    297 ### Global Catalog Options
    298 
    299 ```bash
    300 # Use Global Catalog for queries
    301 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --global-catalog
    302 
    303 # Specify GC hostname
    304 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --gc dc01.certified.htb
    305 ```
    306 
    307 ### Computer/Host Enumeration
    308 
    309 ```bash
    310 # Exclude domain controllers from enumeration
    311 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --exclude-dcs
    312 
    313 # Custom computer filter (LDAP filter)
    314 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --computerfilter "(operatingSystem=*Server*)"
    315 
    316 # Disable computer enumeration (LDAP only)
    317 bloodhound-python -c group,acl -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41
    318 ```
    319 
    320 ---
    321 
    322 ## ๐Ÿ“ Output Options
    323 
    324 ### Output Directory & Files
    325 
    326 ```bash
    327 # Default output (current directory)
    328 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41
    329 
    330 # Custom output directory
    331 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 -o /tmp/bloodhound_data
    332 
    333 # Specific output directory with ZIP
    334 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 -o /tmp/bh --zip
    335 ```
    336 
    337 ### ZIP File Creation
    338 
    339 ```bash
    340 # Automatically create ZIP file
    341 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip
    342 
    343 # ZIP file will be named: YYYYMMDDHHMMSS_bloodhound.zip
    344 ```
    345 
    346 ### Output Files Generated
    347 
    348 Without `--zip`:
    349 ```
    350 20241127163045_computers.json
    351 20241127163045_users.json
    352 20241127163045_groups.json
    353 20241127163045_domains.json
    354 20241127163045_gpos.json
    355 20241127163045_ous.json
    356 20241127163045_containers.json
    357 ```
    358 
    359 With `--zip`:
    360 ```
    361 20241127163045_bloodhound.zip (contains all JSON files)
    362 ```
    363 
    364 ---
    365 
    366 ## ๐Ÿ”ฅ Common Usage Scenarios
    367 
    368 ### Scenario 1: Initial Domain Enumeration
    369 
    370 ```bash
    371 # Quick initial recon
    372 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip
    373 
    374 # Save to specific location
    375 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 -o ~/htb/certified/bloodhound --zip
    376 ```
    377 
    378 ### Scenario 2: Stealth Enumeration (LDAP Only)
    379 
    380 ```bash
    381 # No SMB connections, LDAP queries only
    382 bloodhound-python -c group,acl,objectprops,trusts -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip
    383 
    384 # Minimize queries
    385 bloodhound-python -c group,trusts -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip
    386 ```
    387 
    388 ### Scenario 3: After Obtaining Hash
    389 
    390 ```bash
    391 # Pass-the-hash attack
    392 bloodhound-python -c all -u administrator --hashes :32693b11e6aa90eb43d32c72a07ceea6 -d certified.htb -ns 10.10.11.41 --zip
    393 
    394 # After secretsdump
    395 impacket-secretsdump certified.htb/judith.mader:judith09@10.10.11.41
    396 # Use extracted hash
    397 bloodhound-python -c all -u administrator --hashes :32693b11e6aa90eb43d32c72a07ceea6 -d certified.htb -ns 10.10.11.41 --zip
    398 ```
    399 
    400 ### Scenario 4: Multi-Domain Environment
    401 
    402 ```bash
    403 # Enumerate parent domain
    404 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip
    405 
    406 # Enumerate child domain
    407 bloodhound-python -c all -u judith.mader -p judith09 -d child.certified.htb -ns 10.10.11.42 --zip
    408 
    409 # Enumerate trusted domain (if creds work)
    410 bloodhound-python -c all -u judith.mader -p judith09 -d external.local -ns 10.10.11.50 --zip
    411 ```
    412 
    413 ### Scenario 5: Kerberos Authentication
    414 
    415 ```bash
    416 # Get TGT first
    417 impacket-getTGT certified.htb/judith.mader:judith09
    418 
    419 # Set ticket cache
    420 export KRB5CCNAME=/tmp/judith.mader.ccache
    421 
    422 # Run bloodhound with Kerberos
    423 bloodhound-python -c all -u judith.mader -d certified.htb -ns 10.10.11.41 -k --no-pass --zip
    424 ```
    425 
    426 ### Scenario 6: Through SOCKS Proxy
    427 
    428 ```bash
    429 # Set up proxy (e.g., with chisel)
    430 export HTTP_PROXY=socks5://127.0.0.1:1080
    431 export HTTPS_PROXY=socks5://127.0.0.1:1080
    432 
    433 # Or use proxychains
    434 proxychains bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip
    435 ```
    436 
    437 ### Scenario 7: Limited User Permissions
    438 
    439 ```bash
    440 # Low-privilege user - collect what you can
    441 bloodhound-python -c group,trusts -u lowpriv -p password123 -d certified.htb -ns 10.10.11.41 --zip
    442 
    443 # Check for interesting group memberships and trusts
    444 ```
    445 
    446 ---
    447 
    448 ## ๐Ÿ†š SharpHound Comparison
    449 
    450 ### Feature Comparison
    451 
    452 | Feature | bloodhound-python | SharpHound |
    453 |---------|------------------|------------|
    454 | **Platform** | Linux/Remote | Windows/Local |
    455 | **Execution** | No code on target | Runs on target |
    456 | **Sessions** | โŒ Limited | โœ… Full |
    457 | **Local Admin** | โš ๏ธ Via LDAP | โœ… Direct query |
    458 | **LDAP Data** | โœ… Full | โœ… Full |
    459 | **Groups** | โœ… Full | โœ… Full |
    460 | **ACLs** | โœ… Full | โœ… Full |
    461 | **GPOs** | โœ… Full | โœ… Full |
    462 | **Stealth** | โœ… Better | โš ๏ธ More noisy |
    463 | **Speed** | โš ๏ธ Slower | โœ… Faster |
    464 
    465 ### Command Comparison
    466 
    467 **bloodhound-python:**
    468 ```bash
    469 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip
    470 ```
    471 
    472 **SharpHound equivalent (on Windows as judith.mader):**
    473 ```powershell
    474 .\SharpHound.exe -c All -d certified.htb --domaincontroller 10.10.11.41
    475 ```
    476 
    477 ### When to Use Each
    478 
    479 **Use bloodhound-python when:**
    480 - โœ… You have valid credentials but no Windows access
    481 - โœ… You want to enumerate remotely from Linux
    482 - โœ… You need stealth (no code execution on target)
    483 - โœ… You're doing initial reconnaissance
    484 
    485 **Use SharpHound when:**
    486 - โœ… You have shell access on Windows
    487 - โœ… You need session enumeration
    488 - โœ… You need local admin detection
    489 - โœ… You want faster/more complete enumeration
    490 
    491 ---
    492 
    493 ## ๐Ÿ› Troubleshooting
    494 
    495 ### Common Errors & Solutions
    496 
    497 #### Error: "Could not resolve domain"
    498 
    499 ```bash
    500 # Solution 1: Add to /etc/hosts
    501 echo "10.10.11.41 certified.htb dc01.certified.htb" | sudo tee -a /etc/hosts
    502 
    503 # Solution 2: Use IP instead of hostname
    504 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41
    505 
    506 # Solution 3: Use DC hostname
    507 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -dc dc01.certified.htb -ns 10.10.11.41
    508 ```
    509 
    510 #### Error: "Authentication failed"
    511 
    512 ```bash
    513 # Check credentials
    514 crackmapexec smb 10.10.11.41 -u judith.mader -p judith09 -d certified.htb
    515 
    516 # Try different username formats
    517 bloodhound-python -c all -u 'certified.htb\judith.mader' -p judith09 -ns 10.10.11.41
    518 bloodhound-python -c all -u judith.mader@certified.htb -p judith09 -ns 10.10.11.41
    519 bloodhound-python -c all -u certified.htb/judith.mader -p judith09 -ns 10.10.11.41
    520 
    521 # Check for account lockout
    522 crackmapexec ldap 10.10.11.41 -u judith.mader -p judith09 -d certified.htb
    523 ```
    524 
    525 #### Error: "LDAP connection failed"
    526 
    527 ```bash
    528 # Try different LDAP port
    529 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --ldapport 389
    530 
    531 # Try LDAPS
    532 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --ldapport 636
    533 
    534 # Disable signing
    535 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --disable-signing
    536 
    537 # Check connectivity
    538 nmap -p 389,636,3268,3269 10.10.11.41
    539 ```
    540 
    541 #### Error: "DNS resolution failed"
    542 
    543 ```bash
    544 # Add DNS server to /etc/resolv.conf
    545 echo "nameserver 10.10.11.41" | sudo tee /etc/resolv.conf
    546 
    547 # Use --dns-tcp
    548 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --dns-tcp
    549 
    550 # Add domain to /etc/hosts
    551 echo "10.10.11.41 certified.htb" | sudo tee -a /etc/hosts
    552 ```
    553 
    554 #### Error: "No output generated"
    555 
    556 ```bash
    557 # Check permissions
    558 ls -la /tmp
    559 
    560 # Specify output directory
    561 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 -o /tmp/bh
    562 
    563 # Check for errors in output
    564 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 -v
    565 ```
    566 
    567 #### Error: "Kerberos authentication failed"
    568 
    569 ```bash
    570 # Check KRB5CCNAME
    571 echo $KRB5CCNAME
    572 
    573 # Verify ticket
    574 klist
    575 
    576 # Get fresh ticket
    577 impacket-getTGT certified.htb/judith.mader:judith09 -dc-ip 10.10.11.41
    578 
    579 # Set correct ticket path
    580 export KRB5CCNAME=/tmp/judith.mader.ccache
    581 
    582 # Configure /etc/krb5.conf
    583 sudo nano /etc/krb5.conf
    584 ```
    585 
    586 #### Error: "Module not found"
    587 
    588 ```bash
    589 # Install dependencies
    590 pip3 install bloodhound dnspython ldap3 impacket
    591 
    592 # Or reinstall
    593 pip3 install --upgrade bloodhound
    594 
    595 # Check Python path
    596 which python3
    597 python3 -m site
    598 ```
    599 
    600 ---
    601 
    602 ## ๐Ÿ“Š Post-Collection
    603 
    604 ### Verify Output Files
    605 
    606 ```bash
    607 # Check generated files
    608 ls -lh *bloodhound* *_*.json
    609 
    610 # Verify JSON files
    611 for file in *.json; do 
    612     echo "Checking $file"
    613     jq empty "$file" && echo "โœ“ Valid JSON" || echo "โœ— Invalid JSON"
    614 done
    615 
    616 # Count objects in files
    617 echo "Users: $(jq '.users | length' *_users.json)"
    618 echo "Groups: $(jq '.groups | length' *_groups.json)"
    619 echo "Computers: $(jq '.computers | length' *_computers.json)"
    620 ```
    621 
    622 ### Import to BloodHound
    623 
    624 ```bash
    625 # Start Neo4j
    626 sudo neo4j start
    627 
    628 # Start BloodHound GUI
    629 bloodhound
    630 
    631 # Or use bloodhound-import (if available)
    632 bloodhound-import -f 20241127163045_bloodhound.zip
    633 ```
    634 
    635 ### Manual ZIP Creation (if needed)
    636 
    637 ```bash
    638 # Create ZIP manually
    639 zip bloodhound_certified.zip *_computers.json *_users.json *_groups.json *_domains.json *_gpos.json *_ous.json *_containers.json
    640 
    641 # Or use tar
    642 tar -czf bloodhound_certified.tar.gz *_*.json
    643 ```
    644 
    645 ### Clean Up
    646 
    647 ```bash
    648 # Remove individual JSON files (keep ZIP)
    649 rm *_computers.json *_users.json *_groups.json *_domains.json *_gpos.json *_ous.json *_containers.json
    650 
    651 # Remove all BloodHound files
    652 rm -f *bloodhound* *_*.json
    653 ```
    654 
    655 ---
    656 
    657 ## ๐ŸŽ“ Advanced Techniques
    658 
    659 ### Combining with Other Tools
    660 
    661 ```bash
    662 # 1. Enumerate domain users first
    663 crackmapexec ldap 10.10.11.41 -u judith.mader -p judith09 -d certified.htb --users
    664 
    665 # 2. Run BloodHound
    666 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip
    667 
    668 # 3. Enumerate shares
    669 crackmapexec smb 10.10.11.41 -u judith.mader -p judith09 -d certified.htb --shares
    670 
    671 # 4. Check for AS-REP roasting
    672 impacket-GetNPUsers certified.htb/judith.mader:judith09 -dc-ip 10.10.11.41 -request
    673 
    674 # 5. Kerberoasting
    675 impacket-GetUserSPNs certified.htb/judith.mader:judith09 -dc-ip 10.10.11.41 -request
    676 ```
    677 
    678 ### Automation Script
    679 
    680 ```bash
    681 #!/bin/bash
    682 # bloodhound_auto.sh
    683 
    684 DOMAIN="certified.htb"
    685 DC_IP="10.10.11.41"
    686 USERNAME="judith.mader"
    687 PASSWORD="judith09"
    688 OUTPUT_DIR="/tmp/bloodhound_$(date +%Y%m%d_%H%M%S)"
    689 
    690 echo "[+] Creating output directory: $OUTPUT_DIR"
    691 mkdir -p "$OUTPUT_DIR"
    692 
    693 echo "[+] Running BloodHound collection..."
    694 bloodhound-python -c all \
    695     -u "$USERNAME" \
    696     -p "$PASSWORD" \
    697     -d "$DOMAIN" \
    698     -ns "$DC_IP" \
    699     -o "$OUTPUT_DIR" \
    700     --zip
    701 
    702 echo "[+] Collection complete!"
    703 echo "[+] Output saved to: $OUTPUT_DIR"
    704 ls -lh "$OUTPUT_DIR"
    705 ```
    706 
    707 ### Using with Responder/LLMNR Poisoning
    708 
    709 ```bash
    710 # 1. Capture credentials with Responder
    711 sudo responder -I tun0 -wv
    712 
    713 # 2. Wait for credentials...
    714 # [+] Captured NTLMv2 hash: user::domain:hash...
    715 
    716 # 3. Crack the hash
    717 hashcat -m 5600 captured.hash /usr/share/wordlists/rockyou.txt
    718 
    719 # 4. Use credentials with BloodHound
    720 bloodhound-python -c all -u captured_user -p cracked_pass -d certified.htb -ns 10.10.11.41 --zip
    721 ```
    722 
    723 ---
    724 
    725 ## ๐Ÿ’ก Pro Tips
    726 
    727 1. **Always use --zip** - Makes import to BloodHound cleaner
    728 2. **Start with 'all' collection** - Get complete picture first
    729 3. **Save output to organized directories** - Use timestamps and target names
    730 4. **Add domains to /etc/hosts** - Prevents DNS issues
    731 5. **Use pass-the-hash when possible** - Don't crack if you don't need to
    732 6. **Combine with other tools** - CME, Impacket suite for comprehensive recon
    733 7. **Run multiple times** - User sessions change, run during business hours
    734 8. **Document your findings** - Keep track of credentials and paths found
    735 9. **Use --exclude-dcs for stealth** - Reduces queries to domain controllers
    736 10. **Verify JSON validity** - Check files before importing to BloodHound
    737 
    738 ---
    739 
    740 ## โš ๏ธ Operational Security
    741 
    742 ### Stealth Considerations
    743 
    744 ```bash
    745 # Minimal queries (stealthy)
    746 bloodhound-python -c group,trusts -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip
    747 
    748 # Avoid computer enumeration (no SMB connections)
    749 bloodhound-python -c group,acl,trusts -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip
    750 
    751 # Use LDAPS for encryption
    752 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --ldapport 636 --zip
    753 ```
    754 
    755 ### Detection Considerations
    756 
    757 **What defenders might see:**
    758 - LDAP queries from unusual source
    759 - Multiple LDAP binds in short time
    760 - Queries for sensitive attributes (adminCount, etc.)
    761 - SMB connections for session enumeration
    762 
    763 **Mitigation:**
    764 - Use compromised internal system as jump box
    765 - Spread out collection over time
    766 - Use legitimate admin account if possible
    767 - Consider using SharpHound on compromised Windows box instead
    768 
    769 ---
    770 
    771 ## ๐Ÿ”— Useful Resources
    772 
    773 - **BloodHound.py GitHub**: https://github.com/fox-it/BloodHound.py
    774 - **BloodHound Documentation**: https://bloodhound.readthedocs.io/
    775 - **BloodHound GUI**: https://github.com/BloodHoundAD/BloodHound
    776 - **BloodHound Cypher Queries**: https://github.com/hausec/Bloodhound-Custom-Queries
    777 
    778 ---
    779 
    780 ## ๐Ÿ“ Quick Reference Card
    781 
    782 ```bash
    783 # Standard enumeration
    784 bloodhound-python -c all -u USER -p PASS -d DOMAIN -ns DC_IP --zip
    785 
    786 # With hash
    787 bloodhound-python -c all -u USER --hashes :NTHASH -d DOMAIN -ns DC_IP --zip
    788 
    789 # With Kerberos
    790 export KRB5CCNAME=/tmp/ticket.ccache
    791 bloodhound-python -c all -u USER -d DOMAIN -ns DC_IP -k --no-pass --zip
    792 
    793 # Stealth mode
    794 bloodhound-python -c group,acl,trusts -u USER -p PASS -d DOMAIN -ns DC_IP --zip
    795 
    796 # Custom output
    797 bloodhound-python -c all -u USER -p PASS -d DOMAIN -ns DC_IP -o /tmp/bh --zip
    798 
    799 # Through proxy
    800 proxychains bloodhound-python -c all -u USER -p PASS -d DOMAIN -ns DC_IP --zip
    801 ```
    802 
    803 ---
    804 
    805 **Created by NetRunner | For Ethical Hacking & Penetration Testing** ๐ŸŽ“๐Ÿ”