Active Directory
SharpHound
BloodHound data collector for AD attack paths.
adbloodhound
sharphound — terminal
$ SharpHound.exe -c AllWhat it does
SharpHound gathers Active Directory relationships — sessions, ACLs, and group membership — for analysis in BloodHound to reveal attack paths to Domain Admin. It's the collection half of BloodHound.
Common use cases
- •Collect Active Directory session, ACL, and group data for BloodHound attack-path analysis.
- •Map privilege escalation routes from a compromised workstation to Domain Admin.
- •Regularly export AD relationship snapshots to track changes in domain attack surface.
Key features
- •Collects sessions, ACLs, group membership, trusts, and GPO relationships from AD.
- •Runs collection methods — Default, All, DCOnly, RDP — depending on access and context.
- •Outputs ZIP files ready for direct import into BloodHound's graph database.
- •Supports LDAP, SMB, and WinRM collection channels with parent-child detection.
Source
https://github.com/BloodHoundAD/SharpHound ↗More Active Directory tools
Need hosted scanning instead of local tooling?
Run a scan in the browser →