HackTool - Bloodhound/Sharphound Execution

 Original Source: [Sigma source]
Title: HackTool - Bloodhound/Sharphound Execution
Status: test
Description:Detects command line parameters used by Bloodhound and Sharphound hack tools
References:
  -https://github.com/BloodHoundAD/BloodHound
  -https://github.com/BloodHoundAD/SharpHound
Author: Florian Roth (Nextron Systems)
Date: 2019-12-20
modified:2023-02-04
Tags:
  • -'attack.discovery'
  • -'attack.t1087.001'
  • -'attack.t1087.002'
  • -'attack.t1482'
  • -'attack.t1069.001'
  • -'attack.t1069.002'
  • -'attack.execution'
  • -'attack.t1059.001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Product|contains:'SharpHound' Description|contains:'SharpHound'     - Company|contains:
      - 'SpecterOps'
      - 'evil corp'
    - Image|contains:
      - '\Bloodhound.exe'
      - '\SharpHound.exe'
  selection_cli_1:
    CommandLine|contains:
      -' -CollectionMethod All '
      -' --CollectionMethods Session '
      -' --Loop --Loopduration '
      -' --PortScanTimeout '
      -'.exe -c All -d '
      -'Invoke-Bloodhound'
      -'Get-BloodHoundData'

  selection_cli_2:
    CommandLine|contains|all:
      -' -JsonFolder '
      -' -ZipFileName '

  selection_cli_3:
    CommandLine|contains|all:
      -' DCOnly '
      -' --NoSaveCache '

  condition:1 of selection_*
Falsepositives:
  -Other programs that use these command line option and accepts an 'All' parameter
Level: high