BloodHound Collection Files

 Original Source: [Sigma source]
Title: BloodHound Collection Files
Status: test
Description:Detects default file names outputted by the BloodHound collection tool SharpHound
References:
  -https://academy.hackthebox.com/course/preview/active-directory-bloodhound/bloodhound--data-collection
Author: C.J. May
Date: 2022-08-09
modified:2026-02-19
Tags:
  • -'attack.discovery'
  • -'attack.t1087.001'
  • -'attack.t1087.002'
  • -'attack.t1482'
  • -'attack.t1069.001'
  • -'attack.t1069.002'
  • -'attack.execution'
  • -'attack.t1059.001'
Logsource:
  • product: windows
  • category: file_event
Detection:
  selection:
    TargetFilename|endswith:
      -'BloodHound.zip'
      -'_computers.json'
      -'_containers.json'
      -'_gpos.json'
      -'_groups.json'
      -'_ous.json'
      -'_users.json'

  filter_optional_ms_winapps:
    Image|endswith: '\svchost.exe'
    TargetFilename|startswith: 'C:\Program Files\WindowsApps\Microsoft.'
    TargetFilename|endswith: '\pocket_containers.json'
  condition:selection and not 1 of filter_optional_*
Falsepositives:
  -Some false positives may arise in some environment and this may require some tuning. Add additional filters or reduce level depending on the level of noise
Level: high