ATT&CKSoftwareBloodHound

BloodHound

S0521

Tool.View on attack.mitre.org

About this tool

BloodHound is an Active Directory (AD) reconnaissance tool that can reveal hidden relationships and identify attack paths within an AD environment.

Techniques used11

Procedure examples11

TechniqueProcedure example
T1018
Remote System Discovery

BloodHound can enumerate and collect the properties of domain computers, including domain controllers.

T1033
System Owner/User Discovery

BloodHound can collect information on user sessions.

T1059.001
PowerShell

BloodHound can use PowerShell to pull Active Directory information from the target environment.

T1069.001
Local Groups

BloodHound can collect information about local groups and members.

T1069.002
Domain Groups

BloodHound can collect information about domain groups and members.

T1087.001
Local Account

BloodHound can identify users with local administrator rights.

T1087.002
Domain Account

BloodHound can collect information about domain users, including identification of domain admin accounts.

T1106
Native API

BloodHound can use .NET API calls in the SharpHound ingestor component to pull Active Directory data.

T1482
Domain Trust Discovery

BloodHound has the ability to map domain trusts and identify misconfigurations for potential abuse.

T1560
Archive Collected Data

BloodHound can compress data collected by its SharpHound ingestor into a ZIP file to be written to disk.

T1615
Group Policy Discovery

BloodHound has the ability to collect local admin information via GPO.

Groups that use it6

Campaigns1

References3

  1. CrowdStrike BloodHound April 2018 Open source
    Red Team Labs. (2018, April 24). Hidden Administrative Accounts: BloodHound to the Rescue. Retrieved October 28, 2020.
  2. FoxIT Wocao December 2019 Open source
    Dantzig, M. v., Schamper, E. (2019, December 19). Operation Wocao: Shining a light on one of China’s hidden hacking groups. Retrieved October 8, 2020.
  3. GitHub Bloodhound Open source
    Robbins, A., Vazarkar, R., and Schroeder, W. (2016, April 17). Bloodhound: Six Degrees of Domain Admin. Retrieved March 5, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.