Title:
BloodHound Collection Files
Status:
test
Description:Detects default file names outputted by the BloodHound collection tool SharpHound
References:
-https://academy.hackthebox.com/course/preview/active-directory-bloodhound/bloodhound--data-collection
Author: C.J. May
Date: 2022-08-09
modified:2026-02-19
Tags:
- -'attack.discovery'
- -'attack.t1087.001'
- -'attack.t1087.002'
- -'attack.t1482'
- -'attack.t1069.001'
- -'attack.t1069.002'
- -'attack.execution'
- -'attack.t1059.001'
Logsource:
- product: windows
- category: file_event
Detection:
selection:
TargetFilename|endswith:
-'BloodHound.zip'
-'_computers.json'
-'_containers.json'
-'_gpos.json'
-'_groups.json'
-'_ous.json'
-'_users.json'
filter_optional_ms_winapps:
Image|endswith:
'\svchost.exe'
TargetFilename|startswith:
'C:\Program Files\WindowsApps\Microsoft.'
TargetFilename|endswith:
'\pocket_containers.json'
condition:
selection and not 1 of filter_optional_*
Falsepositives:
-Some false positives may arise in some environment and this may require some tuning. Add additional filters or reduce level depending on the level of noise
Level:
high