BloodHound
BloodHound turns flat AD enumeration into a relationship graph: nodes (users, groups, computers, OUs, GPOs, domains) joined by edges representing permissions and relationships (MemberOf, AdminTo, HasSession, GenericAll, CanRDP, Owns…). Over that graph, one query answers the question that’s nearly impossible by hand: “what’s the shortest path from the account I control to Domain Admin?”. It converts thousands of scattered ACLs into a concrete attack path.
Threat model
Section titled “Threat model”What BloodHound exploits isn’t a bug: it’s accumulated complexity. A real AD holds tens of thousands of delegated permissions, nested groups, and active sessions nobody audits together. Individually harmless relationships, chained, form a route to DA the defense team never sees because they never look at it as a graph. The attacker does.
Architecture
Section titled “Architecture”- Collectors (SharpHound): traverse the domain via LDAP, SMB, and sessions, producing JSON.
- Interface (BloodHound): loads the JSON into a Neo4j database and lets you query/visualize paths.
- Two flavors: BloodHound Community Edition (new, web,
bloodhound.py/SharpHound collector) and legacy (Electron). Edges and logic are equivalent.
Red Team
Section titled “Red Team”Collection
Section titled “Collection”# from Windows (executable or in-memory DLL)SharpHound.exe -c All --zipfilename out# from Linux with credentials (without touching a Windows host)bloodhound-python -u user -p pass -d domain.local -ns <DC_IP> -c All# collection methods: Session, LoggedOn, ACL, Trusts, Group, LocalAdmin...-c All collects ACLs, sessions, local admins, trusts, and GPOs. For stealth, --stealth or selective methods (fewer queries, less noise).
Analysis: the queries that matter
Section titled “Analysis: the queries that matter”Load the ZIP and mark your starting node as Owned. Key queries:
- “Shortest Path to Domain Admins” from your owned user/host → the direct route.
- Kerberoastable / ASREProastable users → roasting targets (see Kerberos Attacks).
- Unconstrained/constrained delegation → see ad-delegation.
- Dangerous ACLs:
GenericAll,WriteDacl,WriteOwner,ForceChangePassword,AddMemberover privileged objects. - Sessions of privileged users on hosts you already control (
HasSession) → credential theft there. - Where can my owned principals RDP / PSRemote; Computers where Domain Users are local admin.
Interpreting edges (what each enables)
Section titled “Interpreting edges (what each enables)”MemberOf -> you inherit the group's permissionsAdminTo -> local admin on that computer (execution, dump)HasSession -> that user's credentials are on that hostGenericAll -> full control of the object (reset pass, add member, RBCD)WriteDacl -> grant yourself permissions over the objectForceChangePassword -> change the user's password without the old oneOwns / WriteOwner -> become owner and rewrite the DACLAllowedToDelegate -> exploitable constrained delegationTools and extensions
Section titled “Tools and extensions”- SharpHound / bloodhound.py — collectors (Windows / Linux).
- BloodHound CE / AzureHound (for Entra ID / Azure AD).
- Cypher (Neo4j language) for custom queries over the graph.
- PlumHound, GoodHound — prioritized reporting over BloodHound data.
Impact
Section titled “Impact”From “I have some account” to “I know exactly which 3 steps lead me to Domain Admin.” BloodHound doesn’t exploit by itself, but it plans the whole attack and reveals routes no human would find by hand.
Blue Team
Section titled “Blue Team”Detection
Section titled “Detection”- SharpHound generates mass LDAP queries and SMB connections in a short time from a workstation → detectable pattern (event 4662, LDAP spikes,
\\host\IPC$to many computers for sessions). - Session enumeration (
NetSessionEnum/NetWkstaUserEnum) against many hosts. - Execution of the SharpHound binary/DLL (signatures, Sysmon image load).
Telemetry
Section titled “Telemetry”- Fine LDAP auditing (4662) and network-logon auditing; alert on query volume per account.
- Restrict anonymous/user
NetSessionEnum(key: denies SharpHound theHasSessionedge). - Honeytokens: “juicy” accounts that, appearing in a path and being touched, raise alerts.
Hardening (shrink the graph)
Section titled “Hardening (shrink the graph)”- The best control is deleting edges: audit and remove dangerous ACLs, flatten nested groups, strip local admin from domain users.
- Implement tiering / PAW (Tier 0 admins never log on to workstations) → cuts
HasSessionroutes. - Run BloodHound yourself periodically as a defensive tool: measure and reduce the paths to DA.
- LAPS, gMSA, Protected Users, and cleanup of privileged memberships.
Response
Section titled “Response”If you detect collection, assume the attacker already has the map: prioritize closing the short routes to DA (reset accounts in the path, remove the abusable ACLs) over chasing only the source host.
CVEs and real-world cases
Section titled “CVEs and real-world cases”- BloodHound isn’t a CVE: it’s methodology. It appears in ransomware reports (leaked Conti playbook, LockBit, BlackCat) as the standard pre-DA mapping tool.
- MITRE ATT&CK: T1087 (account discovery), T1069 (groups), T1482 (trusts), T1018 (remote systems).
- The BloodHound team (SpecterOps) documents real paths and their mitigation; the basis of the “Attack Path Management” discipline.
Testing checklist
Section titled “Testing checklist”- Collect with
-c All(SharpHound or bloodhound.py) without errors - Mark owned nodes and import the ZIP
- “Shortest Path to Domain Admins” from your principal
- Kerberoastable / ASREProastable users
- Dangerous ACLs (GenericAll/WriteDacl/ForceChangePassword) to privileged objects
- Delegations (unconstrained/constrained/RBCD)
- Privileged users’ sessions on controllable hosts
- Custom Cypher queries for non-obvious paths