Skip to main content
Mallory
MalwareRansomwareUsed by 5 actors

BloodHound

BloodHound is an Active Directory reconnaissance and relationship-mapping tool, with SharpHound serving as its data collection ingestor. It is used to enumerate and collect information about domain users, domain administrator accounts, local and domain groups, user sessions, domain computers including domain controllers, domain trusts, and Group Policy-derived local administrator relationships. The tool can gather Active Directory data through PowerShell and .NET API calls, and SharpHound can compress collected data into a ZIP archive written to disk. The content also notes BloodHound can reveal replication-related privileges in Active Directory.

BloodHound is widely used in penetration testing and by internal security teams, but the content also documents repeated use by threat actors during real intrusions for network reconnaissance, Active Directory mapping, and identifying privilege-escalation and lateral-movement paths. Reported examples include Russian state-sponsored actors targeting U.S. cleared defense contractors, attackers in the Capita 2023 intrusion, UNC2447 activity, Play, and other intrusion sets using BloodHound alongside tools such as Cobalt Strike, Mimikatz, PsExec, AdFind, and PowerView. In several cited cases, BloodHound use occurred prior to ransomware deployment or during broader post-compromise discovery.

Observed execution patterns in the content include PowerShell-based invocation of SharpHound, including download cradles that retrieve SharpHound.ps1 from public repositories and execute Invoke-BloodHound from memory or local disk. The content highlights detection opportunities around SharpHound/BloodHound LDAP query patterns, anomalous SPN requests associated with Kerberoasting indicators, and large-scale Active Directory enumeration. High-confidence behavioral indicators mentioned include PowerShell commands downloading SharpHound.ps1, Invoke-BloodHound execution, LDAP-based Active Directory collection, and SharpHound-produced ZIP archives containing collected directory data.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
BlackBasta

"Additional Resources ... Bloodhound"

via bushidotoken blogblog.bushidotoken.net
Twelve

Prominent among the other tools used by Twelve are Cobalt Strike, Mimikatz, Chisel, BloodHound, PowerView, adPEAS, CrackMapExec, Advanced IP Scanner, and PsExec for credential theft, discovery, network mapping, and privilege escalation.

via the hacker newsthehackernews.com
WIZARD SPIDER

During an intrusion, tools such as Cobalt Strike, PowerShell Empire, Bloodhound, PSExec... are used for network discovery and traversal, privilege escalation, staging, and ransomware deployment.

via secureworks threat profilessecureworks.com
Ryuk actors

"SharpHound... for BloodHound (an open-source Active Directory analysis tool used to identify attack paths in AD environments)."

via sophos threat researchnews.sophos.com
UNC2447

...UNC2447 has been observed using the following tools: ADFIND, BLOODHOUND...

via mandiant threat intelligencecloud.google.com
MITRE ATT&CK

Techniques & procedures

19 distinct techniques documented for this family, organized by ATT&CK tactic.

T1588.002ToolEvidence1

The content repeatedly states that threat actors 'obtained,' 'acquired,' or 'used' publicly available, open-source, legitimate, or modified tools such as Mimikatz, Cobalt Strike, PsExec, Empire, Impacket, and many others.

Execution

1 technique
T1059.001PowerShellEvidence1
TacticExecution

The content repeatedly describes threat actors and malware using PowerShell scripts/commands for execution, download, staging, reconnaissance, persistence, credential access, lateral movement, and defense evasion; e.g., "Sandworm Team used PowerShell scripts to run a credential harvesting tool in memory to evade defenses."

T1068Exploitation for Privilege EscalationEvidence1

There are also built-in escalation path queries, such as built-in queries for Active Directory Certificate Services (ADCS) privilege escalation techniques.

T1484.002Trust ModificationEvidence1

Access Control Lists (ACL) misconfiguration is one of the most common issues Microsoft Incident Response finds in Active Directory environments... These attack paths create an escalation path from a low privileged user to total domain control.

T1548Abuse Elevation Control MechanismEvidence1

Some of the typically misused rights include: ForceChangePassword ... GenericAll ... GenericWrite ... WriteOwner ... WriteDacl ... Self ... These things can have critical impact and often times lead to Domain Admin privileges.

Stealth

2 techniques
T1036MasqueradingEvidence1
TacticStealth

"You could detect it with traffic to 9389 (ADWS) but there's an even bigger problem there, all of RSAT uses ADWS. So sysadmins doing normal operations would trigger false positives."

T1036.002Right-to-Left OverrideEvidence1
TacticStealth

Another deception example is the use of the infamous Right-To-Left Override (RLO) character... Invoking a PowerShell command that downloads and executes BloodHound, with argv[0] containing the RLO character \u202E, makes it much harder to understand what is going on when looking at the reported command line.

T1484.002Trust ModificationEvidence1

Access Control Lists (ACL) misconfiguration is one of the most common issues Microsoft Incident Response finds in Active Directory environments... These attack paths create an escalation path from a low privileged user to total domain control.

Discovery

12 techniques
T1016System Network Configuration DiscoveryEvidence1
TacticDiscovery

In BOFHound output mode, all attributes for every object are parsed and outputted to BOFHound format... Computers collection

T1018Remote System DiscoveryEvidence13
TacticDiscovery

Further investigation revealed a Git repository that contains a framework of tools and scripts that align with two components: an automated Active Directory (AD) discovery panel

T1033System Owner/User DiscoveryEvidence2
TacticDiscovery

The content repeatedly describes malware and threat actors collecting usernames, identifying logged-in users, running whoami/query user/quser, checking admin status, and enumerating user sessions.

T1046Network Service DiscoveryEvidence2
TacticDiscovery

For four days – March 24-28 – they conducted network reconnaissance using Cobalt Strike and Bloodhound before Capita detected three compromised staff devices and contained them.

T1049System Network Connections DiscoveryEvidence1
TacticDiscovery

System Networks Connections Discovery [T1049]: A common tool used for this network enumeration tactic is Bloodhound.

T1069Permission Groups DiscoveryEvidence4
TacticDiscovery

Users collection Groups collection Computers collection Trusts collection OU collection GPO collection Certificate template collection

T1069.002Domain GroupsEvidence4
TacticDiscovery

adfind.exe -f "(objectcategory=group)" > ad_group.txt

T1082System Information DiscoveryEvidence1
TacticDiscovery

GeminiDuke focuses primarily on gathering details about the victim’s computer’s configuration.

T1083File and Directory DiscoveryEvidence1
TacticDiscovery

After gaining access to networks, the threat actors used BloodHound to map the Active Directory.

T1087Account DiscoveryEvidence3
TacticDiscovery

Frequently attackers query for the currently running security tools, privileged users, and security settings such as those defined in Group Policy before continuing their attack.

T1087.002Domain AccountEvidence3
TacticDiscovery

For example, you can filter for “enabled” accounts.

T1482Domain Trust DiscoveryEvidence8
TacticDiscovery

The threat actor executed Bloodhound to map out the AD environment

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution5

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping19

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.