BloodHound is an Active Directory (AD) reconnaissance tool that can reveal hidden relationships and identify attack paths within an AD environment.
| Technique | Procedure example |
|---|---|
| T1018 Remote System Discovery |
BloodHound can enumerate and collect the properties of domain computers, including domain controllers. |
| T1033 System Owner/User Discovery |
BloodHound can collect information on user sessions. |
| T1059.001 PowerShell |
BloodHound can use PowerShell to pull Active Directory information from the target environment. |
| T1069.001 Local Groups |
BloodHound can collect information about local groups and members. |
| T1069.002 Domain Groups |
BloodHound can collect information about domain groups and members. |
| T1087.001 Local Account |
BloodHound can identify users with local administrator rights. |
| T1087.002 Domain Account |
BloodHound can collect information about domain users, including identification of domain admin accounts. |
| T1106 Native API |
BloodHound can use .NET API calls in the SharpHound ingestor component to pull Active Directory data. |
| T1482 Domain Trust Discovery |
BloodHound has the ability to map domain trusts and identify misconfigurations for potential abuse. |
| T1560 Archive Collected Data |
BloodHound can compress data collected by its SharpHound ingestor into a ZIP file to be written to disk. |
| T1615 Group Policy Discovery |
BloodHound has the ability to collect local admin information via GPO. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.