ATT&CKReferencesCrowdStrike BloodHound April 2018

CrowdStrike BloodHound April 2018

Red Team Labs. (2018, April 24). Hidden Administrative Accounts: BloodHound to the Rescue. Retrieved October 28, 2020.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1018
Remote System Discovery
ToolBloodHound

BloodHound can enumerate and collect the properties of domain computers, including domain controllers.

T1033
System Owner/User Discovery
ToolBloodHound

BloodHound can collect information on user sessions.

T1059.001
PowerShell
ToolBloodHound

BloodHound can use PowerShell to pull Active Directory information from the target environment.

T1069.001
Local Groups
ToolBloodHound

BloodHound can collect information about local groups and members.

T1069.002
Domain Groups
ToolBloodHound

BloodHound can collect information about domain groups and members.

T1087.001
Local Account
ToolBloodHound

BloodHound can identify users with local administrator rights.

T1087.002
Domain Account
ToolBloodHound

BloodHound can collect information about domain users, including identification of domain admin accounts.

T1482
Domain Trust Discovery
ToolBloodHound

BloodHound has the ability to map domain trusts and identify misconfigurations for potential abuse.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.