BloodHound AD Collection

Collect Active Directory data for BloodHound analysis

Tool
bloodhound-python
Category
Enumeration / LDAP
Platform
linux
Requires
password
Protocols
LDAP

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

bloodhound-python -d '<domain>' -u '<user>' -p '<password>' -gc '<domain>' -c all -ns '<ip>' --zip --dns-tcp

Credential variants

The same attack using a different authentication material.

NTLM Hash requires NTLM hash

bloodhound-python -d '<domain>' -u '<user>' --hashes ':<hash>' -gc '<domain>' -c all -ns '<ip>' --zip --dns-tcp

Kerberos Ticket requires Kerberos ticket

bloodhound-python -d '<domain>' -u '<user>' -k --auth-method kerberos -gc '<domain>' -c all -ns '<ip>' --zip --dns-tcp

Examples

bloodhound-python -d 'CORP.LOCAL' -u 'user' -p 'password' -gc 'CORP.LOCAL' -c all -ns '192.168.1.100' --zip --dns-tcp

Tags

bloodhound ad enumeration collection graph