Skip to main content

Parse output from common sources and transform it into BloodHound-ingestible data

Project description

              _____________________________ __    __    ______    __    __   __   __   _______
             |   _   /  /  __   / |   ____/|  |  |  |  /  __  \  |  |  |  | |  \ |  | |       \
             |  |_)  | |  |  |  | |  |__   |  |__|  | |  |  |  | |  |  |  | |   \|  | |  .--.  |
             |   _  <  |  |  |  | |   __|  |   __   | |  |  |  | |  |  |  | |  . `  | |  |  |  |
             |  |_)  | |  `--'  | |  |     |  |  |  | |  `--'  | |  `--'  | |  |\   | |  '--'  |
             |______/   \______/  |__|     |__|  |___\_\________\_\________\|__| \___\|_________\
           
                                         << @coffeegist | @Tw1sm >>

Python PyPi

BOFHound is an offline BloodHound ingestor and LDAP result parser compatible with TrustedSec's ldapsearch BOF, the Python adaptation, pyldapsearch and Brute Ratel's LDAP Sentinel. ldapsearch BOF output can also be parsed from Havoc logs, OutflankC2 logs, and Mythic callbacks.

By parsing log files generated by the aforementioned tools, BOFHound allows operators to utilize BloodHound's beloved interface while maintaining full control over the LDAP queries being run and the spped at which they are executed. This leaves room for operator discretion to account for potential honeypot accounts, expensive LDAP query thresholds and other detection mechanisms designed with the traditional, automated BloodHound collectors in mind.

Check this PR to the SA BOF repo for BOFs that collect session and local group membership data and can be parsed by BOFHound.

References

Blog Posts:

Title Date
BOFHound: AD CS Integration Oct 30, 2024
BOFHound: Session Integration Jan 30, 2024
Granularize Your AD Recon Game Part 2 Jun 15, 2022
Granularize Your AD Recon Game May 10, 2022

Presentations:

Conference Materials Date
SO-CON 2024 Slides & Recording Mar 11, 2024

Installation

BOFHound can be installed with pip3 install bofhound or by cloning this repository and running pip3 install .

Usage

 Usage: bofhound [OPTIONS]

 Generate BloodHound compatible JSON from logs written by the ldapsearch BOF, pyldapsearch and
 specific C2 frameworks

╭─ Options ─────────────────────────────────────────────────────────────────────────────────────╮
│ --input             -i      TEXT                             Directory or file containing     │
│                                                              logs of ldapsearch results       │
│                                                              [default:                        │
│                                                              /opt/cobaltstrike/logs]          │
│ --output            -o      TEXT                             Location to export bloodhound    │
│                                                              files                            │
│                                                              [default: .]                     │
│ --properties-level  -p      [Standard|Member|All]            Change the verbosity of          │
│                                                              properties exported to JSON:     │
│                                                              Standard - Common BH properties  │
│                                                              | Member - Includes MemberOf and │
│                                                              Member | All - Includes all      │
│                                                              properties                       │
│                                                              [default: Member]                │
│ --parser                    [ldapsearch|BRC4|Havoc|Outflank  Parser to use for log files.     │
│                             C2|Mythic]                       ldapsearch parser (default)      │
│                                                              supports ldapsearch BOF logs     │
│                                                              from Cobalt Strike and           │
│                                                              pyldapsearch logs                │
│                                                              [default: ldapsearch]            │
│ --debug                                                      Enable debug output              │
│ --zip               -z                                       Compress the JSON output files   │
│                                                              into a zip archive               │
│ --quiet             -q                                       Suppress banner                  │
│ --help              -h                                       Show this message and exit.      │
╰───────────────────────────────────────────────────────────────────────────────────────────────╯
╭─ Mythic Options ──────────────────────────────────────────────────────────────────────────────╮
│ --mythic-server        TEXT  IP or hostname of Mythic server to connect to                    │
│                              [default: 127.0.0.1]                                             │
│  --mythic-token         TEXT  Mythic API token [default: None]                                │
╰───────────────────────────────────────────────────────────────────────────────────────────────╯
╭─ BloodHound CE Options ───────────────────────────────────────────────────────────────────────╮
│ --bh-token-id         TEXT  BloodHound API token ID [default: None]                           │
│ --bh-token-key        TEXT  BloodHound API token key [default: None]                          │
│ --bh-server           TEXT  BloodHound CE URL [default: http://127.0.0.1:8080]                │
╰───────────────────────────────────────────────────────────────────────────────────────────────╯

Example Usage

Parse ldapseach BOF results from Cobalt Strike logs (/opt/cobaltstrike/logs by default) to /data/

bofhound -o /data/

Parse pyldapsearch logs and only include all properties (vs other property levels)

bofhound -i ~/.pyldapsearch/logs/ --properties-level all

Parse LDAP Sentinel data from BRc4 logs (will change default input path to /opt/bruteratel/logs)

bofhound --parser brc4

Parse Havoc loot logs (will change default input path to /opt/havoc/data/loot) and zip the resulting JSON files

bofhound --parser havoc --zip

ldapsearch

Specify *,ntsecuritydescriptor as the attributes to return to be able to parse ACL edges. You are missing a ton of data if you don't include this in your ldapsearch queries!

Required Data

The following attributes are required for proper functionality:

samaccounttype
distinguishedname
objectsid

Some object classes rely on domain objects being populated within BOFHound. Domains can be queried with either of the following commands

ldapsearch (objectclass=domain) --attributes *,ntsecuritydescriptor
ldapsearch (distinguishedname=DC=windomain,DC=local) --attributes *,ntsecuritydescriptor

Example ldapsearch Queries

# Get All the Data (Maybe Run BloodHound Instead?)
ldapsearch (objectclass=*) --attributes *,ntsecuritydescriptor

# Retrieve All Schema Info
ldapsearch (schemaIDGUID=*) --attributes name,schemaidguid --dn CN=Schema,CN=Configuration,DC=windomain,DC=local

# Retrieve Only the ms-Mcs-AdmPwd schemaIDGUID
ldapsearch (name=ms-mcs-admpwd) --attributes name,schemaidguid --count 1 --dn CN=Schema,CN=Configuration,DC=windomain,DC=local

# Retrieve Domain NetBIOS Names (useful if collecting data via `netsession2/netloggedon2` BOFs)
ldapsearch (netbiosname=*) --dn "CN=Partitions,CN=Configuration,DC=windomain,DC=local"

# Unroll a group's nested members
ldapsearch (memberOf:1.2.840.113556.1.4.1941:=CN=TargetGroup,CN=Users,DC=windomain,DC=local) --attributes *,ntsecuritydescriptor

# Query domain trusts
ldapsearch (objectclass=trusteddomain) --attributes *,ntsecuritydescriptor

# Query across a trust
ldapsearch (objectclass=domain) --attributes *,ntsecuritydescriptor --hostname dc1.trusted.windomain.local --dn "DC=TRUSTED,DC=WINDOMAIN,DC=LOCAL"

#####
# Queries below populate objects for AD CS parsing

# Query the domain object
ldapsearch (objectclass=domain) --attributes *,ntsecuritydescriptor

# Query Enterprise CAs
ldapsearch (objectclass=pKIEnrollmentService) --attributes *,ntsecuritydescriptor --dn "CN=Configuration,DC=domain,DC=local"

# Query AIACAs, Root CAs and NTAuth Stores
ldapsearch (objectclass=certificationAuthority) --attributes *,ntsecuritydescriptor --dn "CN=Configuration,DC=domain,DC=local"

# Query Certificate Templates
ldapsearch (objectclass=pKICertificateTemplate) --attributes *,ntsecuritydescriptor --dn "CN=Configuration,DC=domain,DC=local"

# Query Issuance Policies
ldapsearch (objectclass=msPKI-Enterprise-Oid) --attributes *,ntsecuritydescriptor --dn "CN=Configuration,DC=domain,DC=local"

Versions

Check the tagged releases to download a specific version

  • v0.4.0 and onward support parsing AD CS objects and edges
  • v0.3.0 and onward support session/local group data
  • v0.2.1 and onward are compatible with BloodHound CE
  • v0.2.0 is the last release supporting BloodHound Legacy

Development

bofhound uses Poetry to manage dependencies. Install from source and setup for development with:

git clone https://github.com/fortalice/bofhound
cd bofhound
poetry install
poetry run bofhound --help

References and Credits

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

bofhound-0.4.15.tar.gz (49.4 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

bofhound-0.4.15-py3-none-any.whl (68.7 kB view details)

Uploaded Python 3

File details

Details for the file bofhound-0.4.15.tar.gz.

File metadata

  • Download URL: bofhound-0.4.15.tar.gz
  • Upload date:
  • Size: 49.4 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: poetry/2.1.2 CPython/3.13.1 Darwin/24.6.0

File hashes

Hashes for bofhound-0.4.15.tar.gz
Algorithm Hash digest
SHA256 1f32b2c06938853244416d9009ee31b45e3d5c96b25b6c8dbf4038dd19926453
MD5 8cfb00518d26c132bdc5d6408f12569f
BLAKE2b-256 ff818f27cb7c08e58389d0abf4d7b112523b3e6d3a6c47c9a8ce722d9f9e45e2

See more details on using hashes here.

File details

Details for the file bofhound-0.4.15-py3-none-any.whl.

File metadata

  • Download URL: bofhound-0.4.15-py3-none-any.whl
  • Upload date:
  • Size: 68.7 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: poetry/2.1.2 CPython/3.13.1 Darwin/24.6.0

File hashes

Hashes for bofhound-0.4.15-py3-none-any.whl
Algorithm Hash digest
SHA256 9a0a662f7809c2c546f73709c2cc420767b7d81e15489c5ce62fdd39c8f0a96a
MD5 ca3e46c7003c0967403b2cc739daa8b4
BLAKE2b-256 29c8fde7ff6e2fe6ac1344557f283d7c2d3f2d99759b5036ee146da107b23dbb

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page