RustHound BloodHound Collection

Collect Active Directory data for BloodHound using RustHound (Kerberos-aware)

Tool
rusthound
Category
Enumeration / LDAP
Platform
linux
Requires
password
Protocols
LDAP, KERBEROS

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

rusthound -d '<domain>' -i <ip> -u '<user>@<domain>' -f '<dc_fqdn>' -z --fqdn-resolver

Credential variants

The same attack using a different authentication material.

Kerberos Ticket requires Kerberos ticket

rusthound -d '<domain>' -i <ip> -u '<user>@<domain>' -f '<dc_fqdn>' -k -z --fqdn-resolver

Examples

rusthound -d 'corp.local' -i 192.168.1.100 -u 'user@corp.local' -f 'dc01.corp.local' -z --fqdn-resolver
rusthound -d 'euvendor.local' -i 192.168.12.212 -u 'administrator@eu.local' -f 'euvendor-dc.euvendor.local' -k -z --fqdn-resolver

Tags

rusthound bloodhound enumeration collection ad