Domain Enum. via BloodHound | Collectors, Pathways, Cypher Queries & More
HackerForce
0:00 / 0:00
Domain Enum. via BloodHound | Collectors, Pathways, Cypher Queries & More
318 просмотров · 2 недели назад
HackerForce
1,12 тыс. подписчиков
318 просмотров · 2 недели назад
💬 Join the Community
/ discord
💥 Red Cell Operator I
https://hackerforce.io/courses/red-ce...
🖥️ Presentation
https://tinyurl.com/domain-enum-via-b...
📌 About
'Defenders think in lists. Attackers think in graphs. As long as this is true, attackers win.'—John Lambert, 2014. A quote that aged like fine wine, and gave birth to BloodHound.
In HackerForce's latest video, sunflower breaks down:
Graph theory, nodes and edges, for visualising object relationships
BloodHound requirements, permissions, and collectors
Objects, relationships, and the attributes that tie a directory together
Pathfinding and Cypher queries for hunting down privilege escalation pathways
Doesn't matter which side of the fence you're on, red or blue, BloodHound belongs in your toolkit, and this video covers pretty much all of it.
📚 Resources
BloodHound documentation: https://bloodhound.specterops.io/get-...
BloodHound CLI: https://github.com/SpecterOps/bloodho...
BloodHound query library: https://queries.specterops.io/
Docker documentation: https://docs.docker.com/manuals/
🔔 Stay Connected
X/Twitter: https://x.com/hackerforcex
⏱️ Timestamps
00:00 Introduction
02:07 Graph theory
03:49 Nodes and edges
05:03 Adjacency
06:43 About BloodHound (e.g. editions, features, etc.)
08:04 Requirements
09:44 Data collectors
10:35 Permissions
11:14 SAMRPC permission requirements example
12:42 Other collector permission requirements
13:03 Installing Docker
15:03 Installing BloodHound
17:04 BloodHound's configuration files
17:33 Downloading a collector (i.e. SharpHound)
18:28 SharpHound versions (i.e. .exe and .ps1)
19:03 SharpHound's options
19:18 Standard (default) data collection
20:17 Collection methods
22:11 Cache file leftover artefact
23:44 Other SharpHound switches
24:40 Ingesting data
25:06 Searching data by node names
26:08 Searching data using prefixes (e.g. user:, computer:, etc.)
26:44 Node properties
27:40 Established sessions (and collector looping)
29:09 Understanding edge relationships
30:57 Group membership
31:44 Local administrator rights
32:20 Execution privileges
32:59 Outbound object control access rights
33:36 Inbound object control access rights
34:31 Node operations (marking as owned and Tier Zero)
35:56 Pathfinding
37:02 Cypher queries
39:27 Extended query database
40:26 Cleaning up and purging data
41:12 Stopping (and starting) BloodHound
41:30 Upcoming
🔗 Tags
#sliver #c2 #redteam #blueteam #hacker #hack #penetrationtesters #pentesting #mimikatz #metasploit #bloodhound #sharphound #kerberos #activedirectory