home/toolvault/priv-esc & post-exploitation/bloodhound

BloodHound //

Priv-Esc & Post-ExploitationAD mapping

BloodHound maps Active Directory attack paths as a graph โ€” 'Helpdesk โ†’ 3 hops โ†’ Domain Admin' becomes visible. Red teams plan with it; blue teams use it to cut those paths.

difficulty ยท advanced
60 min
time to first win
5
guided steps
0
students started here*

HOW TO USE BLOODHOUND

Follow the steps โ€” click any step card to replay the terminal demo from that point. Everything runs in a lab you control.

bloodhound โ€” guided lab session
static view
step 01

Collect from a lab domain

bloodhound-python -u labuser -p 'Pass123' -d lab.local -ns 10.0.2.10 -c All

SharpHound (C#) on Windows or bloodhound-python from Kali.

step 02

Feed the graph

import ZIP into BloodHound (neo4j)

Neo4j database + GUI = the map.

step 03

The famous query

Queries โ†’ Shortest Paths to Domain Admins

One click shows who can become god-mode and how.

step 04

Mark what's owned

right-click node โ†’ Mark as Owned

Simulate: 'if I phish THIS user, where do I end up?'

step 05

Defend with it

find 'weird' edges (GenericAll on admins)

Delete the accidental path = delete the attack. Purple-team gold.

THE WORKFLOW AT A GLANCE

๐Ÿ“ฅ
Collect
SharpHound
๐Ÿ—„๏ธ
Import
neo4j graph
๐Ÿ”
Query
paths to DA
๐Ÿ‘‘
Own
mark & pivot
โœ‚๏ธ
Remediate
cut edges
LEARNING CURVE
advanced โ€” 60 min to first win

FLAGS & SUPER-MOVES

SharpHound.ps1/.exeWindows collector
bloodhound-pythonKali collector
-c Allcollect everything
owned nodesmark compromised
custom cypherexpert queries

PRO TIPS

01

TryHackMe's 'Attacktive Directory' & 'Post-Exploitation Basics' rooms set this up gently.

TryHackMe's 'Attacktive Directory' & 'Post-Exploitation Basics' rooms set this up gently.

02

In real AD labs (GOAD), your first action after creds

In real AD labs (GOAD), your first action after creds: collect + map.

03

Defenders

Defenders: audit for paths INTO Tier-0 (DA/Enterprise Admins) regularly.

04

Impacket + BloodHound + NetExec is the holy AD attack trinity.

Impacket + BloodHound + NetExec is the holy AD attack trinity.

โš–๏ธ

Golden rule

Use BloodHound only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox โ€” plenty of legal targets, zero risk.

KEEP DIGGING

CYBER//ZERO ToolVault
Animated deep-dives on every tool in the guide.
โœ๏ธ Author LDM ยท ldmhub4u@gmail.com
full guide v1 ยท v2 immersive ยท latest news
Made for learners, everywhere ยท 2026
*plausibly. verify commands with official docs.