Skip to content
← LibraryTechnique entry
AD-BLOODHOUNDDiscovery

BloodHound / SharpHound Enumeration

Collect AD objects, sessions, and ACLs to discover attack paths to high-value targets.

§ Where this technique fits

AD-BLOODHOUND is catalogued under the Discovery tactic of the offensive-security kill-chain. It appears in 12 approved dossiers in the registry, typically at step 3.8 on average.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    Valid Accounts
    T1078 · Initial Access
    seen 2×
  2. 02
    WriteDACL
    AD-DACL-WRITEDACL · Privilege Escalation
    seen 2×
  3. 03
    AddMember (WriteProperty on member)
    AD-DACL-ADDMEMBER · Privilege Escalation
    seen 1×
  4. 04
    GPO Immediate Scheduled Task
    AD-GPO-IMMEDIATE · Privilege Escalation
    seen 1×
  5. 05
    Pass the Hash
    T1550.002 · Lateral Movement
    seen 1×