Active Directory
BloodHound / SharpHound / AzureHound
Maps Active Directory attack paths using graph theory.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
When
After domain foothold to find shortest path to Domain Admin.
How
Collect with SharpHound; import into BloodHound CE; query paths.
Why
Turns AD complexity into actionable privilege paths.
Commands & usage
SharpHound.exe -c All
bloodhound-python -u user -p pass -d domain.local -c All -ns 10.0.0.10
Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.
Comparisons
ATT&CK
Tags
Related in Active Directory
Impacket
Python collection for Windows network protocols (SMB, WMI, Kerberos, etc.).
CrackMapExec / NetExec
Swiss army knife for pentesting Windows/Active Directory networks (NetExec successor).
Rubeus
C# toolset for Kerberos abuse (AS-REP, kerberoast, tickets, etc.).
enum4linux-ng
SMB/Windows enumeration tool wrapping common Samba tools.
SMBMap
Enumerates Samba share drives across networks with permissions.
ldapsearch / windapsearch
Query LDAP/Active Directory directory data.