ThaiCERT    ETDA    MDES
Report
Search
Home > List all groups > List all tools > List all groups using tool BloodHound

Threat Group Cards: A Threat Actor Encyclopedia

Permanent link Tool: BloodHound

NamesBloodHound
CategoryTools
TypeReconnaissance
Description(PenTestPartners) BloodHound is an application used to visualize active directory environments. The front-end is built on electron and the back-end is a Neo4j database, the data leveraged is pulled from a series of data collectors also referred to as ingestors which come in PowerShell and C# flavours.

It can be used on engagements to identify different attack paths in Active Directory (AD), this encompasses access control lists (ACLs), users, groups, trust relationships and unique AD objects. The tool can be leveraged by both blue and red teams to find different paths to targets. The subsections below explain the different and how to properly utilize the different ingestors.
Information<https://www.pentestpartners.com/security-blog/bloodhound-walkthrough-a-tool-for-many-tradecrafts/>
<https://github.com/BloodHoundAD/BloodHound>

Last change to this tool card: 20 April 2020

Download this tool card in JSON format

All groups using tool BloodHound

ChangedNameCountryObserved

APT groups

 APT 20, Violin PandaChina2014-2017 
XStone Panda, APT 10, menuPassChina2006-Feb 2021 HOTX
XTA2101, Maze Team[Unknown]2019-Mar 2021 HOTX
XTraveling Spider[Unknown]2019-Mar 2021 HOT 
XWizard Spider, Gold BlackburnRussia2014-Apr 2021 HOTX

5 groups listed (5 APT, 0 other, 0 unknown)

Thailand Computer Emergency Response Team (ThaiCERT)
Electronic Transactions Development Agency

Follow us on

Facebook Twitter

Report incidents

Telephone +66 (0)2-123-1234
E-mail report@thaicert.or.th
PGP Download PGP key