Red Team Labs. (2018, April 24). Hidden Administrative Accounts: BloodHound to the Rescue. Retrieved October 28, 2020.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1018 Remote System Discovery |
ToolBloodHound | BloodHound can enumerate and collect the properties of domain computers, including domain controllers. |
| T1033 System Owner/User Discovery |
ToolBloodHound | BloodHound can collect information on user sessions. |
| T1059.001 PowerShell |
ToolBloodHound | BloodHound can use PowerShell to pull Active Directory information from the target environment. |
| T1069.001 Local Groups |
ToolBloodHound | BloodHound can collect information about local groups and members. |
| T1069.002 Domain Groups |
ToolBloodHound | BloodHound can collect information about domain groups and members. |
| T1087.001 Local Account |
ToolBloodHound | BloodHound can identify users with local administrator rights. |
| T1087.002 Domain Account |
ToolBloodHound | BloodHound can collect information about domain users, including identification of domain admin accounts. |
| T1482 Domain Trust Discovery |
ToolBloodHound | BloodHound has the ability to map domain trusts and identify misconfigurations for potential abuse. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.