BloodHound data collection, aka Sharphound, is quite a complex beast.
When giving BloodHound workshops, the part where I get the most questions is
always data collection.
How is the BloodHound data collected? What methods do what? Who am I talking
to? How do I fly under the radar?
These are all very relevant questions when you think about it.
After all, the rest is just a gorgeous UI sitting on top of a cool data model,
but the only bit of BloodHound code that ever touches the targeted network is
SharpHound. And so questions about it should be mandatory.
Now even thought I’ve been working with BloodHound for quite a while, there is
always this moment where I have to check before answering… (I feel the older I
get, the quicker I understand, but the less I remember… but that’s another story
I guess…)
Arrroooo… Bloodhound Crew!! Heard the news? CypherDog 4.0 is out and
it’s full of new features…
Now a couple of you might be thinking “Hey there, wait a minute… didn’t
CypherDog 3.0 come out not that long ago..??”, and I am happy to see some of you
are paying attention…
Indeed, when Bloodhound 3 came out, I quickly updated CypherDog 2 to CypherDog 3
to be compatible with it.
But Bloodhound 3 is compatible with neo4j 3 and 4, however the neo4j REST API
has been deprecated in neo4j 4 and CypherDog 3 relied on it.
Long story short, CypherDog 4.0 is a full rewrite compatible with the new
neo4j 4 HTTP API, and since I was refactoring the whole thing, I added some
cool new features to the tool.
The idea was to be able to do more with less keystrokes, and to do it
server-side…
And so I made a meme.
So there was a pandemic, the whole world was under lockdown, and I got a bit
depressed.
I needed something new in my life, so I decided to take my favorite dog out for
a walk in the ATT&CK jungle to check out the newly added sub-techniques…
If you’re not familiar with ATT&CK and are wondering what this is all about, no
worries…
ATT&CK stands for Adversarial Tactics, Techniques & Common Knowledge.
It’s a treasure trove of information about real-life offensive tradecraft.
I like to see it as an open-source encyclopedia of corporate
post-exploitation.
There is a growing community around the project and more info keeps being added
to it.
[Check out
this post
by @LikeTheCoins if you want to know more]
With the current situation, it’s not easy to find the right angle to start this
blog post, so I won’t even try… but with Troopers cancelled, my Bloodhound
workshop went down the drain, and I didn’t get a chance to meet or catch up with
all of you and share my latest BloodHound adventures. So I decided to write a
quick post to share all this…
As you might have heard, BloodHound 3 was released last month, so I thought it
was time to update the Dog Whisperers Handbook.
It’s basically a quick intro to BloodHound and Cypher, with a lot of links to
resources for further learning.
You can download the latest version
here. Hope you enjoy it.
SadProcessor here, happy to be back on the Insinuator to share with you some of
my latest BloodHound adventures and experiments…
TL;DR Well too bad for you…
Before diving into a bit of code and some BloodHound data manipulation,
I would like to thank the BruCon Crew for having me over last week for
BruCON0x0B.
I had the pleasure of delivering a 4h BloodHound & Cypher workshop in the
lovely city of Gent [in a fantastic training room], and I am pleased with the
interaction & feedback I had with the attendees.
I was also very happy to see almost as many Blues as Reds in the room [as well
as regular security folks!!], all together having a play with BloodHound &
Cypher.
The PowerShell Conference Europe 2019 took place last
week in Hannover, and I had the pleasure to attend and speak for the second year
in a row. I want to thank @TobiasPSP@Alexandair@sqldbawithbeard and the
@PSConfEU crew for putting up this
#PowerShell feast. From a RaspberryPi
to the Clouds, from PowerShell internals to a dancing Lego robot, if you have
anything to do with windows, PowerShell, or a computer, there was some content
made for you…[I will update this post with links as soon as the videos are
published. Make sure to check it out.]
As promised in my
previous post, I am back
for an overview of the Troopers19 – Active Directory related talks… Videos
have been published and it’s popcorn time… So if you are into stories about
Kingdoms and Crown Jewels, grab your loved one [or a drink…] and turn the
lights down low, ’cause tonight it’s “Troopers & Chill…”
Warning: Don’t watch it all in one go… or you will start to feel some anxiety
and pain…
and then the Flying Dutchman will move to the cloud… And at that point we are
not insured anymore.
When I got home last weekend after an awesome week at
WEareTROOPERS, my 5yr old asked me what
actually happened in Heidelberg…
I told him we were meeting with some people from all over the world to talk
about computer security, and he asked me if it was “to stop the bad guys, like
super-heroes?”. So I told him “yes, kind of…”, and he decided he would take his
new Troopers T-Shirt to school on Monday to show his classmates. Kids are truly
amazing… [<3 <3 <3]
Back from Holidays, you started the year well motivated to make the world a
safer place.
However, sitting at your desk today you realize nothing really changed since
last year, and you are surfing the web, feeling a bit blue, trying to avoid that
pile of emails waiting for you and wondering how you could gain some
visibility on your domain in order to better defend it.
No worries, emails can wait a bit longer. All you need is some fresh air and
something cool to keep your defensive mind motivated for the year, and I might
have just what you need; so put on your shoes and let me take you on a 15 minute
Cypher walk with a cool blue dog…
Generally speaking, I’m more of a Cat type of guy, but I have to say I really
love BloodHound. And if you do too, you are in for a treat…
Last week, the ERNW InsightActive
Directory Security Summit took place in Heidelberg.
(More Info)
For
this occasion, @Enno_Insinuator asked me
if I would like to deliver a BloodHound Workshop, and of course I accepted
the challenge…
We had a full class, I had a blast training it, and I hope the trainees enjoyed
it as much as I did.
But that’s not all…
Another part of the deal was that I had to write a Training Guide that we
would then share with the Community (aka you).
So here it is, fresh from the Heidelberg press and available for download: