Перейти к содержимому

Domain Enum. via BloodHound | Collectors, Pathways, Cypher Queries & More

HackerForce

0:00 / 0:00

Domain Enum. via BloodHound | Collectors, Pathways, Cypher Queries & More

318 просмотров · 2 недели назад
HackerForce
1,12 тыс. подписчиков
318 просмотров · 2 недели назад
💬 Join the Community   / discord   💥 Red Cell Operator I https://hackerforce.io/courses/red-ce... 🖥️ Presentation https://tinyurl.com/domain-enum-via-b... 📌 About 'Defenders think in lists. Attackers think in graphs. As long as this is true, attackers win.'—John Lambert, 2014. A quote that aged like fine wine, and gave birth to BloodHound. In HackerForce's latest video, sunflower breaks down: Graph theory, nodes and edges, for visualising object relationships BloodHound requirements, permissions, and collectors Objects, relationships, and the attributes that tie a directory together Pathfinding and Cypher queries for hunting down privilege escalation pathways Doesn't matter which side of the fence you're on, red or blue, BloodHound belongs in your toolkit, and this video covers pretty much all of it. 📚 Resources BloodHound documentation: https://bloodhound.specterops.io/get-... BloodHound CLI: https://github.com/SpecterOps/bloodho... BloodHound query library: https://queries.specterops.io/ Docker documentation: https://docs.docker.com/manuals/ 🔔 Stay Connected X/Twitter: https://x.com/hackerforcex ⏱️ Timestamps 00:00 Introduction 02:07 Graph theory 03:49 Nodes and edges 05:03 Adjacency 06:43 About BloodHound (e.g. editions, features, etc.) 08:04 Requirements 09:44 Data collectors 10:35 Permissions 11:14 SAMRPC permission requirements example 12:42 Other collector permission requirements 13:03 Installing Docker 15:03 Installing BloodHound 17:04 BloodHound's configuration files 17:33 Downloading a collector (i.e. SharpHound) 18:28 SharpHound versions (i.e. .exe and .ps1) 19:03 SharpHound's options 19:18 Standard (default) data collection 20:17 Collection methods 22:11 Cache file leftover artefact 23:44 Other SharpHound switches 24:40 Ingesting data 25:06 Searching data by node names 26:08 Searching data using prefixes (e.g. user:, computer:, etc.) 26:44 Node properties 27:40 Established sessions (and collector looping) 29:09 Understanding edge relationships 30:57 Group membership 31:44 Local administrator rights 32:20 Execution privileges 32:59 Outbound object control access rights 33:36 Inbound object control access rights 34:31 Node operations (marking as owned and Tier Zero) 35:56 Pathfinding 37:02 Cypher queries 39:27 Extended query database 40:26 Cleaning up and purging data 41:12 Stopping (and starting) BloodHound 41:30 Upcoming 🔗 Tags #sliver #c2 #redteam #blueteam #hacker #hack #penetrationtesters #pentesting #mimikatz #metasploit #bloodhound #sharphound #kerberos #activedirectory