Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Bloodhound 2.0

Bloodhound 2.0

Presented at null Dubai Meet 31 August 2018 Monthly Meet

Pralhad Chaskar

August 31, 2018
Tweet

More Decks by Pralhad Chaskar

Other Decks in Technology

Transcript

  1. What is Bloodhound • Active Directory privileges, rights and trust

    relationships mapping tool • Makes finding attack paths super easy • Uses a Neo4j Graph Database • Data collection using C# binary called SharpHound • Bloodhound UI is built with Linkurious, compiled into an Electron app • Free and open source software
  2. New feature in 2.0 • CanRDP, ExecuteDCOM, ReadLAPSPassword, AllowedToDelegate •

    JSON Output (instead of CSV) • Edge Filtering • Graph Editing from the UI • Owned Value Properties • High Value Properties • Edge Abuse Help • Dark Mode
  3. Detecting Bloodhound/ Hardening Infra • Net Cease - Hardening Net

    Session Enumeration • SAMRi10 - Hardening SAM Remote Access in Windows 10/Server 2016 • Using Netflow or other tools • Using DejaVU • ………or detect the system which makes tons of LDAP queries to DC
  4. References • https://blog.cptjesus.com/posts/bloodhound20 • Bloodhound: He Attac, but he also

    Protec (https://www.youtube.com/watch?v=hHfxZug1HHo) • https://github.com/BloodHoundAD/BloodHound • https://github.com/SadProcessor/Cheats/blob/master/DogWhisperer V2.md • https://github.com/PowerShellMafia/PowerSploit/tree/master/Recon