Sinisterly
BloodHound, Graphs, and PowerSploit - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Hacking (https://sinister.li/Forum-Hacking)
+--- Forum: Hacking Tools (https://sinister.li/Forum-Hacking-Tools)
+--- Thread: BloodHound, Graphs, and PowerSploit (/Thread-BloodHound-Graphs-and-PowerSploit)



BloodHound, Graphs, and PowerSploit - numer_05 - 07-08-2019

I was poking around online to see what I can find on making life easier for me after initial foothold is established. Essentially in an engagement one would want to stay in a network for as long as possible and the goal is _forever_. This easier said then done. There are such things as PowerSploit which need to be obfuscated because Microsoft has caught on and Defender blocks it as is (Defender is signature based btw), but to get a layout of the network a nice tool called BloodHound exists. As far as I can tell, SharpHound uses the Domain Controller and possibly LDAP (?) to map out the network via Active Directory and give details such as when admin last logged in and where. The most useful feature of this is that the csv files can be imported into neo4j via BloodHound interface in a graph format. Installation instructions are here:

https://github.com/BloodHoundAD/BloodHound/wiki/Getting-started