← All cheat sheets

BLOODHOUND

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

BloodHound uses graph theory to reveal hidden relationships
in Active Directory environments for attack path discovery.

COMPONENTS#

- BloodHound GUI: Visualization and querying
- SharpHound: C# data collector
- BloodHound.py: Python data collector
- Neo4j: Graph database backend

INSTALLATION#

# Neo4j Database
sudo apt install neo4j
sudo neo4j console
# Access: http://localhost:7474 (default: neo4j/neo4j)

# BloodHound GUI
# Download from: https://github.com/BloodHoundAD/BloodHound/releases
./BloodHound --no-sandbox

# BloodHound.py
pip install bloodhound

# SharpHound
# Download from: https://github.com/BloodHoundAD/SharpHound

DATA COLLECTION - SHARPHOUND#


    

BASIC COLLECTION#

# All collection methods
SharpHound.exe -c All

# Specific collection methods
SharpHound.exe -c DCOnly           # DC info only
SharpHound.exe -c Session          # Session info
SharpHound.exe -c LoggedOn         # Logged on users
SharpHound.exe -c Trusts           # Domain trusts
SharpHound.exe -c ACL              # ACL info
SharpHound.exe -c Container        # Container info
SharpHound.exe -c RDP              # RDP rights
SharpHound.exe -c DCOM             # DCOM rights
SharpHound.exe -c PSRemote         # PS remoting rights
SharpHound.exe -c LocalAdmin       # Local admin rights
SharpHound.exe -c LocalGroup       # Local groups
SharpHound.exe -c Group            # Group memberships
SharpHound.exe -c ObjectProps      # Object properties
SharpHound.exe -c SPNTargets       # SPN targets

# Multiple collection methods
SharpHound.exe -c Session,LoggedOn,ACL

COMMON COLLECTION OPTIONS#

# Standard collection
SharpHound.exe -c All -d domain.local

# With domain controller
SharpHound.exe -c All --DomainController DC01.domain.local

# Stealth mode
SharpHound.exe -c DCOnly --Stealth

# Specify output directory
SharpHound.exe -c All --OutputDirectory C:\Temp

# Specify output prefix
SharpHound.exe -c All --OutputPrefix BloodHound

# Loop collection (continuous)
SharpHound.exe -c Session --Loop --LoopDuration 02:00:00

# With credentials
SharpHound.exe -c All -d domain.local --LdapUsername user --LdapPassword pass

# Exclude DCs
SharpHound.exe -c All --ExcludeDomainControllers

# Specific OU
SharpHound.exe -c All --OU "OU=Workstations,DC=domain,DC=local"

POWERSHELL VARIANT#

# Import module
Import-Module .\SharpHound.ps1

# Collect all
Invoke-BloodHound -CollectionMethod All

# With options
Invoke-BloodHound -CollectionMethod All -Domain domain.local -OutputDirectory C:\Temp

# Stealth
Invoke-BloodHound -CollectionMethod DCOnly -Stealth

DATA COLLECTION - BLOODHOUND.PY#


    

BASIC USAGE#

# With password
bloodhound-python -u user -p password -d domain.local -dc DC01.domain.local -c All

# With NTLM hash
bloodhound-python -u user --hashes :NTHASH -d domain.local -dc DC01.domain.local -c All

# With Kerberos
bloodhound-python -u user -p password -d domain.local -dc DC01.domain.local -c All -k

# DNS resolution
bloodhound-python -u user -p password -d domain.local -ns 192.168.1.1 -c All

COLLECTION METHODS#

bloodhound-python -c Group            # Group memberships
bloodhound-python -c LocalAdmin       # Local admin rights
bloodhound-python -c Session          # Sessions
bloodhound-python -c Trusts           # Domain trusts
bloodhound-python -c Default          # Default collection
bloodhound-python -c All              # Everything
bloodhound-python -c DCOnly           # DC only (stealthy)
bloodhound-python -c Container        # Container/OU info
bloodhound-python -c ACL              # ACLs
bloodhound-python -c ObjectProps      # Object properties

OUTPUT OPTIONS#

# Specify output directory
bloodhound-python -c All -d domain.local -dc DC01 -u user -p pass --outputdir /path/

# ZIP output
bloodhound-python -c All --zip

BLOODHOUND GUI#


    

DATABASE OPERATIONS#

# Clear database
MATCH (n) DETACH DELETE n

# Upload data
# Drag and drop ZIP/JSON files into GUI

PRE-BUILT QUERIES#

# Analysis tab includes:
- Find all Domain Admins
- Find Shortest Paths to Domain Admins
- Find Principals with DCSync Rights
- Users with Foreign Domain Group Membership
- Groups with Foreign Domain Group Membership
- Map Domain Trusts
- Shortest Paths to Unconstrained Delegation Systems
- Shortest Paths from Kerberoastable Users
- Shortest Paths to Domain Admins from Kerberoastable Users
- Shortest Path from Owned Principals
- Shortest Paths to High Value Targets

MARKING NODES#

# Right-click node:
- Mark as Owned
- Mark as High Value
- Mark as Starting Point

CUSTOM CYPHER QUERIES#


    

USERS#

# All users
MATCH (u:User) RETURN u

# Users with SPN (Kerberoastable)
MATCH (u:User) WHERE u.hasspn=true RETURN u

# Users with no Kerberos preauth (AS-REP roastable)
MATCH (u:User) WHERE u.dontreqpreauth=true RETURN u

# Users with password not required
MATCH (u:User) WHERE u.passwordnotreqd=true RETURN u

# Disabled users
MATCH (u:User) WHERE u.enabled=false RETURN u

# Users with admin count
MATCH (u:User) WHERE u.admincount=true RETURN u

GROUPS#

# All groups
MATCH (g:Group) RETURN g

# Domain Admins members
MATCH (u:User)-[:MemberOf*1..]->(g:Group) WHERE g.name CONTAINS 'DOMAIN ADMINS' RETURN u

# Find nested group membership
MATCH (u:User)-[:MemberOf*1..5]->(g:Group) WHERE g.name CONTAINS 'ADMIN' RETURN u, g

COMPUTERS#

# All computers
MATCH (c:Computer) RETURN c

# Unconstrained delegation computers
MATCH (c:Computer) WHERE c.unconstraineddelegation=true RETURN c

# Computers where Domain Users can RDP
MATCH (g:Group)-[:CanRDP]->(c:Computer) WHERE g.name CONTAINS 'DOMAIN USERS' RETURN c

# Find computers with LAPS
MATCH (c:Computer) WHERE c.haslaps=true RETURN c

SESSIONS#

# All sessions
MATCH (u:User)-[:HasSession]->(c:Computer) RETURN u, c

# Where Domain Admins have sessions
MATCH (u:User)-[:MemberOf*1..]->(g:Group)-[:HasSession]->(c:Computer) WHERE g.name CONTAINS 'DOMAIN ADMINS' RETURN u, c

PATHS#

# Shortest path to Domain Admins
MATCH p=shortestPath((u:User)-[*1..]->(g:Group)) WHERE g.name CONTAINS 'DOMAIN ADMINS' RETURN p

# Shortest path from owned user
MATCH p=shortestPath((u:User {owned:true})-[*1..]->(g:Group)) WHERE g.name CONTAINS 'DOMAIN ADMINS' RETURN p

# All paths to DA (limited)
MATCH p=(u:User)-[*1..5]->(g:Group) WHERE g.name CONTAINS 'DOMAIN ADMINS' RETURN p LIMIT 100

ACL QUERIES#

# Users with DCSync rights
MATCH (u:User)-[:GetChanges|GetChangesAll*1..]->(d:Domain) RETURN u

# GenericAll rights
MATCH (u:User)-[:GenericAll]->(target) RETURN u, target

# WriteDACL rights
MATCH (u:User)-[:WriteDacl]->(target) RETURN u, target

# WriteOwner rights
MATCH (u:User)-[:WriteOwner]->(target) RETURN u, target

# AddMember rights to groups
MATCH (u:User)-[:AddMember]->(g:Group) RETURN u, g

ATTACK PATHS#

# Kerberoastable to DA
MATCH p=shortestPath((u:User {hasspn:true})-[*1..]->(g:Group)) WHERE g.name CONTAINS 'DOMAIN ADMINS' RETURN p

# AS-REP roastable to DA
MATCH p=shortestPath((u:User {dontreqpreauth:true})-[*1..]->(g:Group)) WHERE g.name CONTAINS 'DOMAIN ADMINS' RETURN p

# Owned to DA
MATCH p=shortestPath((u {owned:true})-[*1..]->(g:Group)) WHERE g.name CONTAINS 'DOMAIN ADMINS' RETURN p

STATISTICS#

# Count users
MATCH (u:User) RETURN COUNT(u)

# Count computers
MATCH (c:Computer) RETURN COUNT(c)

# Users per domain
MATCH (u:User) RETURN u.domain, COUNT(u)

COMMON ATTACK PATHS#

1. Kerberoasting
   - Find users with SPNs
   - Check paths to high value targets

2. AS-REP Roasting
   - Find users without preauth
   - Check paths from those users

3. Delegation Abuse
   - Unconstrained delegation hosts
   - Constrained delegation users/computers
   - Resource-based constrained delegation

4. ACL Abuse
   - GenericAll/GenericWrite on users/groups
   - WriteDACL on objects
   - WriteOwner permissions
   - AddMember to privileged groups

5. Session Hijacking
   - Find where privileged users are logged in
   - Path from owned machine to those sessions

INTEGRATION WITH OTHER TOOLS#

# Collect with CrackMapExec/NetExec
nxc ldap DC -u user -p pass --bloodhound -c All

# Collect with ADRecon
.\ADRecon.ps1 -Collect All

QUICK REFERENCE#

SharpHound.exe -c All                 # Collect all
bloodhound-python -c All -u user -p pass -d domain.local
# Upload ZIP to BloodHound GUI
# Use pre-built queries or custom Cypher
# Mark owned nodes
# Find shortest paths to targets