Attack Flow
Low-priv creds obtained → ldapdomaindump (readable AD snapshot)
+ bloodhound-python (graph data) → import to BloodHound → identify path to DATool 1 - Ldapdomaindump
Output Files
| File | Contents |
|---|---|
domain_users.html | All domain users, group memberships |
domain_groups.html | All groups and members |
domain_computers.html | All computers, OS, last logon |
domain_policy.html | Password policy, lockout threshold |
domain_trusts.html | Domain trusts |
domain_users_by_group.html | Users organised by group |
Execution
mkdir <domain-name>
cd <domain-name>
sudo ldapdomaindump ldap://<dc-ip> -u '<DOMAIN>\<username>' -p '<password>'
sudo ldapdomaindump ldaps://<dc-ip> -u '<DOMAIN>\<username>' -p '<password>'
firefox domain_users.html
firefox domain_groups.html
firefox domain_computers.htmlGrep Output for Quick Wins
grep -i "Domain Admins" domain_groups.grep
grep -i "Never" domain_users.grep
grep -i "DONT_EXPIRE_PASSWORD" domain_users.grep
grep -i "disabled" domain_users.grepTool 2 - BloodHound
Installation
sudo apt update && sudo apt install -y bloodhound
sudo bloodhound-setupStarting BloodHound
# Terminal 1 — start neo4j (use the password set during bloodhound-setup)
sudo neo4j console
# Terminal 2 — launch BloodHound
sudo bloodhound-startReset admin password if needed:
sudo env bhe_recreate_default_admin=true bloodhoundCollecting AD Data (Ingestor)
sudo bloodhound-python -d '<domain.local>' -u '<username>' -p '<password>' -ns <dc-ip> -c all
# Output: computers.json, users.json, groups.json, domains.json, gpos.jsonImporting Data
BloodHound UI → Upload Data → select JSON files / zip → wait for importKey Queries
Shortest path:
Find Shortest Paths to Domain Admins
Find Shortest Path from Owned Principals
Find Principals with DCSync Rights
Find Computers where Domain Users are Local AdminHigh value targets:
Find All Domain Admins
Find Kerberoastable Users with DA Privileges
Find AS-REP Roastable Users
Find Computers with Unconstrained Delegation
Find Computers with Constrained DelegationACL abuse:
Find Shortest Paths to Domain Admins via ACL Abuse
Principals with WriteDACL on Domain
Principals with GenericAll on DomainMark owned:
Right click node → Mark as Owned
Then run: Find Shortest Path from Owned PrincipalsRecommended Order
# Terminal 1 — dump AD to readable files
mkdir <domain-name> && cd <domain-name>
sudo ldapdomaindump ldaps://<dc-ip> -u '<DOMAIN>\<username>' -p '<password>'
# Terminal 2 — collect BloodHound data
sudo bloodhound-python -d '<domain.local>' -u '<username>' -p '<password>' -ns <dc-ip> -c all
# Start BloodHound
sudo neo4j console
sudo bloodhound
# Import JSON files, review HTML output alongside
firefox domain_users.html &
firefox domain_groups.html &What Each Finding Tells You
| Finding | Implication |
|---|---|
| Domain Admin members identified | Focus lateral movement here |
| Short path to DA via ACL | ACL abuse viable — follow BloodHound path |
| Kerberoastable DA account | Kerberoast immediately |
| Unconstrained delegation computer | High value relay/coercion target |
| Domain Users are local admin somewhere | Pass the hash target |
| Stale accounts in privileged groups | Spray candidate — less monitored |
| Low lockout threshold | Spray carefully — one attempt per window |
| Trust relationships present | Other domains reachable |