BLOODHOUND
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
BloodHound uses graph theory to reveal hidden relationships in Active Directory environments for attack path discovery.
COMPONENTS#
- BloodHound GUI: Visualization and querying - SharpHound: C# data collector - BloodHound.py: Python data collector - Neo4j: Graph database backend
INSTALLATION#
# Neo4j Database sudo apt install neo4j sudo neo4j console # Access: http://localhost:7474 (default: neo4j/neo4j) # BloodHound GUI # Download from: https://github.com/BloodHoundAD/BloodHound/releases ./BloodHound --no-sandbox # BloodHound.py pip install bloodhound # SharpHound # Download from: https://github.com/BloodHoundAD/SharpHound
DATA COLLECTION - SHARPHOUND#
BASIC COLLECTION#
# All collection methods SharpHound.exe -c All # Specific collection methods SharpHound.exe -c DCOnly # DC info only SharpHound.exe -c Session # Session info SharpHound.exe -c LoggedOn # Logged on users SharpHound.exe -c Trusts # Domain trusts SharpHound.exe -c ACL # ACL info SharpHound.exe -c Container # Container info SharpHound.exe -c RDP # RDP rights SharpHound.exe -c DCOM # DCOM rights SharpHound.exe -c PSRemote # PS remoting rights SharpHound.exe -c LocalAdmin # Local admin rights SharpHound.exe -c LocalGroup # Local groups SharpHound.exe -c Group # Group memberships SharpHound.exe -c ObjectProps # Object properties SharpHound.exe -c SPNTargets # SPN targets # Multiple collection methods SharpHound.exe -c Session,LoggedOn,ACL
COMMON COLLECTION OPTIONS#
# Standard collection SharpHound.exe -c All -d domain.local # With domain controller SharpHound.exe -c All --DomainController DC01.domain.local # Stealth mode SharpHound.exe -c DCOnly --Stealth # Specify output directory SharpHound.exe -c All --OutputDirectory C:\Temp # Specify output prefix SharpHound.exe -c All --OutputPrefix BloodHound # Loop collection (continuous) SharpHound.exe -c Session --Loop --LoopDuration 02:00:00 # With credentials SharpHound.exe -c All -d domain.local --LdapUsername user --LdapPassword pass # Exclude DCs SharpHound.exe -c All --ExcludeDomainControllers # Specific OU SharpHound.exe -c All --OU "OU=Workstations,DC=domain,DC=local"
POWERSHELL VARIANT#
# Import module Import-Module .\SharpHound.ps1 # Collect all Invoke-BloodHound -CollectionMethod All # With options Invoke-BloodHound -CollectionMethod All -Domain domain.local -OutputDirectory C:\Temp # Stealth Invoke-BloodHound -CollectionMethod DCOnly -Stealth
DATA COLLECTION - BLOODHOUND.PY#
BASIC USAGE#
# With password bloodhound-python -u user -p password -d domain.local -dc DC01.domain.local -c All # With NTLM hash bloodhound-python -u user --hashes :NTHASH -d domain.local -dc DC01.domain.local -c All # With Kerberos bloodhound-python -u user -p password -d domain.local -dc DC01.domain.local -c All -k # DNS resolution bloodhound-python -u user -p password -d domain.local -ns 192.168.1.1 -c All
COLLECTION METHODS#
bloodhound-python -c Group # Group memberships bloodhound-python -c LocalAdmin # Local admin rights bloodhound-python -c Session # Sessions bloodhound-python -c Trusts # Domain trusts bloodhound-python -c Default # Default collection bloodhound-python -c All # Everything bloodhound-python -c DCOnly # DC only (stealthy) bloodhound-python -c Container # Container/OU info bloodhound-python -c ACL # ACLs bloodhound-python -c ObjectProps # Object properties
OUTPUT OPTIONS#
# Specify output directory bloodhound-python -c All -d domain.local -dc DC01 -u user -p pass --outputdir /path/ # ZIP output bloodhound-python -c All --zip
BLOODHOUND GUI#
DATABASE OPERATIONS#
# Clear database MATCH (n) DETACH DELETE n # Upload data # Drag and drop ZIP/JSON files into GUI
PRE-BUILT QUERIES#
# Analysis tab includes: - Find all Domain Admins - Find Shortest Paths to Domain Admins - Find Principals with DCSync Rights - Users with Foreign Domain Group Membership - Groups with Foreign Domain Group Membership - Map Domain Trusts - Shortest Paths to Unconstrained Delegation Systems - Shortest Paths from Kerberoastable Users - Shortest Paths to Domain Admins from Kerberoastable Users - Shortest Path from Owned Principals - Shortest Paths to High Value Targets
MARKING NODES#
# Right-click node: - Mark as Owned - Mark as High Value - Mark as Starting Point
CUSTOM CYPHER QUERIES#
USERS#
# All users MATCH (u:User) RETURN u # Users with SPN (Kerberoastable) MATCH (u:User) WHERE u.hasspn=true RETURN u # Users with no Kerberos preauth (AS-REP roastable) MATCH (u:User) WHERE u.dontreqpreauth=true RETURN u # Users with password not required MATCH (u:User) WHERE u.passwordnotreqd=true RETURN u # Disabled users MATCH (u:User) WHERE u.enabled=false RETURN u # Users with admin count MATCH (u:User) WHERE u.admincount=true RETURN u
GROUPS#
# All groups MATCH (g:Group) RETURN g # Domain Admins members MATCH (u:User)-[:MemberOf*1..]->(g:Group) WHERE g.name CONTAINS 'DOMAIN ADMINS' RETURN u # Find nested group membership MATCH (u:User)-[:MemberOf*1..5]->(g:Group) WHERE g.name CONTAINS 'ADMIN' RETURN u, g
COMPUTERS#
# All computers MATCH (c:Computer) RETURN c # Unconstrained delegation computers MATCH (c:Computer) WHERE c.unconstraineddelegation=true RETURN c # Computers where Domain Users can RDP MATCH (g:Group)-[:CanRDP]->(c:Computer) WHERE g.name CONTAINS 'DOMAIN USERS' RETURN c # Find computers with LAPS MATCH (c:Computer) WHERE c.haslaps=true RETURN c
SESSIONS#
# All sessions MATCH (u:User)-[:HasSession]->(c:Computer) RETURN u, c # Where Domain Admins have sessions MATCH (u:User)-[:MemberOf*1..]->(g:Group)-[:HasSession]->(c:Computer) WHERE g.name CONTAINS 'DOMAIN ADMINS' RETURN u, c
PATHS#
# Shortest path to Domain Admins
MATCH p=shortestPath((u:User)-[*1..]->(g:Group)) WHERE g.name CONTAINS 'DOMAIN ADMINS' RETURN p
# Shortest path from owned user
MATCH p=shortestPath((u:User {owned:true})-[*1..]->(g:Group)) WHERE g.name CONTAINS 'DOMAIN ADMINS' RETURN p
# All paths to DA (limited)
MATCH p=(u:User)-[*1..5]->(g:Group) WHERE g.name CONTAINS 'DOMAIN ADMINS' RETURN p LIMIT 100
ACL QUERIES#
# Users with DCSync rights MATCH (u:User)-[:GetChanges|GetChangesAll*1..]->(d:Domain) RETURN u # GenericAll rights MATCH (u:User)-[:GenericAll]->(target) RETURN u, target # WriteDACL rights MATCH (u:User)-[:WriteDacl]->(target) RETURN u, target # WriteOwner rights MATCH (u:User)-[:WriteOwner]->(target) RETURN u, target # AddMember rights to groups MATCH (u:User)-[:AddMember]->(g:Group) RETURN u, g
ATTACK PATHS#
# Kerberoastable to DA
MATCH p=shortestPath((u:User {hasspn:true})-[*1..]->(g:Group)) WHERE g.name CONTAINS 'DOMAIN ADMINS' RETURN p
# AS-REP roastable to DA
MATCH p=shortestPath((u:User {dontreqpreauth:true})-[*1..]->(g:Group)) WHERE g.name CONTAINS 'DOMAIN ADMINS' RETURN p
# Owned to DA
MATCH p=shortestPath((u {owned:true})-[*1..]->(g:Group)) WHERE g.name CONTAINS 'DOMAIN ADMINS' RETURN p
STATISTICS#
# Count users MATCH (u:User) RETURN COUNT(u) # Count computers MATCH (c:Computer) RETURN COUNT(c) # Users per domain MATCH (u:User) RETURN u.domain, COUNT(u)
COMMON ATTACK PATHS#
1. Kerberoasting - Find users with SPNs - Check paths to high value targets 2. AS-REP Roasting - Find users without preauth - Check paths from those users 3. Delegation Abuse - Unconstrained delegation hosts - Constrained delegation users/computers - Resource-based constrained delegation 4. ACL Abuse - GenericAll/GenericWrite on users/groups - WriteDACL on objects - WriteOwner permissions - AddMember to privileged groups 5. Session Hijacking - Find where privileged users are logged in - Path from owned machine to those sessions
INTEGRATION WITH OTHER TOOLS#
# Collect with CrackMapExec/NetExec nxc ldap DC -u user -p pass --bloodhound -c All # Collect with ADRecon .\ADRecon.ps1 -Collect All
QUICK REFERENCE#
SharpHound.exe -c All # Collect all bloodhound-python -c All -u user -p pass -d domain.local # Upload ZIP to BloodHound GUI # Use pre-built queries or custom Cypher # Mark owned nodes # Find shortest paths to targets