VulnScanners Logo

Active Directory

SharpHound

BloodHound data collector for AD attack paths.

adbloodhound
sharphound — terminal
$ SharpHound.exe -c All

What it does

SharpHound gathers Active Directory relationships — sessions, ACLs, and group membership — for analysis in BloodHound to reveal attack paths to Domain Admin. It's the collection half of BloodHound.

Common use cases

  • Collect Active Directory session, ACL, and group data for BloodHound attack-path analysis.
  • Map privilege escalation routes from a compromised workstation to Domain Admin.
  • Regularly export AD relationship snapshots to track changes in domain attack surface.

Key features

  • Collects sessions, ACLs, group membership, trusts, and GPO relationships from AD.
  • Runs collection methods — Default, All, DCOnly, RDP — depending on access and context.
  • Outputs ZIP files ready for direct import into BloodHound's graph database.
  • Supports LDAP, SMB, and WinRM collection channels with parent-child detection.

Source

https://github.com/BloodHoundAD/SharpHound

More Active Directory tools

Need hosted scanning instead of local tooling?

Run a scan in the browser →