SharpHound

BloodHound data collector for AD.

Windowsmedium

pkg: (collector)

SharpHound gathers Active Directory objects and relationships to feed BloodHound attack-path analysis.

Syntax

SharpHound.exe -c {CollectionMethod}

Example

SharpHound.exe -c All

Collects all AD data into a zip for BloodHound import.

Advantages
  • Feeds BloodHound graphs
  • Flexible collection methods
Disadvantages
  • Can be noisy/detected
  • Windows collector
Tags
#ad#bloodhound

Official docs: SharpHound

Related commands

Frequently asked questions

What is SharpHound used for?
SharpHound gathers Active Directory objects and relationships to feed BloodHound attack-path analysis.
What is an example SharpHound command?
A common example is: SharpHound.exe -c All — Collects all AD data into a zip for BloodHound import.
Is SharpHound part of a standard install?
SharpHound runs on Windows. Install the (collector) package.
What category of security tool is SharpHound?
SharpHound is a Post-Exploitation tool with a medium-risk profile when run against a live target.

Try recon tools live

Run real scans against a domain you control, stage by stage.

Open the lab →