BloodHound & Active Directory Enumeration
This skill helps you enumerate and visualize Active Directory relationships to identify privilege escalation paths, lateral movement opportunities, and security misconfigurations.
When to Use This Skill
Use this skill when you need to:
- Map Active Directory relationships and trust structures
- Find privilege escalation paths in a Windows domain
- Enumerate Group Policy Objects (GPOs) and their configurations
- Identify Kerberoastable service accounts
- Visualize attack paths through AD
- Perform AD health checks and risk assessments
- Collect AD data for offline analysis
Tool Selection Guide
| Tool | Best For | Noise Level | Privileges Required |
|---|---|---|---|
| BloodHound + SharpHound | Graph visualization, path finding | Medium-High | Domain user (elevated for full data) |
| ADRecon | Comprehensive Excel report | Medium | Domain user |
| AD Explorer | GUI browsing, snapshot comparison | Low | Domain user |
| Group3r | GPO misconfiguration detection | Low | Domain user |
| PingCastle | AD health check, risk scoring | Low | Domain user |
| RustHound-CE | Stealthy ADWS collection | Low | Domain user |
BloodHound Deployment
Quick Start (Docker)
# Deploy BloodHound CE
curl -L https://ghst.ly/getbhce | docker compose -f - up
# Access Web UI at http://localhost:8080
# Default credentials: admin / (check logs for password)
Collector Selection
Choose the right collector based on your access level and stealth requirements:
SharpHound (Full Collection)
# Full sweep - most comprehensive but noisy
SharpHound.exe --CollectionMethods All
# Targeted collection - balance of data and stealth
SharpHound.exe --CollectionMethods Group,LocalAdmin,Session,Trusts,ACL
# Stealth mode - LDAP only, minimal noise
SharpHound.exe --Stealth --LDAP
RustHound-CE (Stealthy ADWS)
# Low-noise collection via ADWS
rusthound-ce -d corp.local -u svc.collector -p 'Passw0rd!' -c All -z
AzureHound (Azure AD)
# Azure AD enumeration
Invoke-AzureHound -TenantId <tenant-id> -ClientSecret <secret>
Critical: Running Collectors Elevated
Why elevation matters:
- UAC creates filtered tokens for interactive admins, stripping sensitive privileges
- Non-elevated shells miss high-value privileges like
SeBackupPrivilege,SeDebugPrivilege - BloodHound won't ingest privilege edges from filtered tokens
- Local LPE edges are invisible without elevated collection
Always run collectors elevated when possible to capture:
- Token privileges (
SeBackupPrivilege,SeDebugPrivilege,SeImpersonatePrivilege,SeAssignPrimaryTokenPrivilege) - Logon rights (
SeInteractiveLogonRight,SeRemoteInteractiveLogonRight,SeNetworkLogonRight,SeServiceLogonRight,SeBatchLogonRight) - Deny entries that gate lateral movement
Collection Strategies
Strategy 1: GPO/SYSVOL Parsing (Stealthy, Low-Privilege)
Use when: You have normal user access and need to stay quiet
Process:
- Enumerate GPOs over LDAP:
(objectCategory=groupPolicyContainer) - Read each
gPCFileSysPathto locate GPO files - Fetch
MACHINE\Microsoft\Windows NT\SecEdit\GptTmpl.inffrom SYSVOL - Parse
[Privilege Rights]section mapping privilege names to SIDs - Resolve GPO links via
gPLinkon OUs/sites/domains - Attribute rights to computers in linked containers
Pros: Works with normal user, quiet operation Cons: Only sees GPO-pushed rights, misses local tweaks
Strategy 2: LSA RPC Enumeration (Noisy, Accurate)
Use when: You have local admin on targets and need complete data
Process:
- From elevated context on target, open Local Security Policy
- Call
LsaEnumerateAccountsWithUserRightfor each privilege/logon right - Enumerate assigned principals over RPC
Pros: Captures all rights including local modifications Cons: Noisy network traffic, requires admin on every host
Kerberoasting Workflow
Use graph context to keep roasting targeted and efficient:
Step 1: Collect Once, Work Offline
rusthound-ce -d corp.local -u svc.collector -p 'Passw0rd!' -c All -z
Step 2: Import and Query
- Import the ZIP into BloodHound GUI
- Mark compromised principal as "owned"
- Run built-in queries:
- Kerberoastable Users - Find SPN accounts
- Shortest Paths to Domain Admins - Prioritize by blast radius
Step 3: Prioritize Targets
Review before cracking:
pwdLastSet- How old is the password?lastLogon- Is the account active?- Allowed encryption types - What can you crack?
Step 4: Request and Crack
# Request tickets for prioritized SPNs
netexec ldap dc01.corp.local -u svc.collector -p 'Passw0rd!' \
--kerberoasting kerberoast.txt --spn svc-sql
# Crack offline with hashcat or john
Step 5: Re-query with New Access
After cracking, re-import into BloodHound with new credentials to discover additional paths.
Common Attack Paths
Privilege Escalation via Backup Privilege
CanRDP → Host with SeBackupPrivilege → Elevated shell →
Read SAM/SYSTEM hives → secretsdump.py → Local Admin hash → Lateral movement
GPO-Based Escalation
GPO with dangerous permissions → Modify GPO →
Push malicious policy → Domain-wide impact
Trust Abuse
Cross-domain trust → Trust admin rights →
Domain compromise → Forest-wide access
Other Enumeration Tools
ADRecon (Comprehensive Report)
# Run from Windows host in domain
PS C:\> .\ADRecon.ps1 -OutputDir C:\Temp\ADRecon
Output: Excel report with ACLs, GPOs, trusts, CA templates
AD Explorer (GUI Analysis)
- Connect to domain controller with domain credentials
- Create offline snapshot:
File → Create Snapshot - Compare snapshots:
File → Compareto spot permission drifts
Group3r (GPO Analysis)
# Execute inside domain
Group3r.exe -f gpo.log # -s for stdout
Focus: GPO misconfigurations and dangerous permissions
PingCastle (Health Check)
PingCastle.exe --healthcheck --server corp.local \
--user bob --password "P@ssw0rd!"
Output: HTML report with risk scoring and remediation guidance
Best Practices
- Collect once, analyze offline - Minimize noise by doing one thorough collection
- Prioritize by blast radius - Focus on accounts with admin/infra rights
- Use stealth collectors first - Start with RustHound-CE or SharpHound --Stealth
- Mark owned nodes - In BloodHound, mark compromised principals to find paths
- Combine tools - Use multiple tools to cross-validate findings
- Document findings - Save snapshots and reports for later analysis
Troubleshooting
BloodHound not showing privilege edges
- Ensure collector ran elevated
- Check if
SeBackupPrivilegeand similar are in collection - Try LSA RPC enumeration instead of GPO parsing
SharpHound fails to connect
- Verify domain connectivity
- Check firewall rules for LDAP (389) and RPC (135)
- Ensure account has read permissions on domain objects
No paths found in BloodHound
- Verify data was imported correctly
- Check collection methods - try
Allinstead of targeted - Ensure you marked owned nodes correctly