ShareHound: An OpenGraph Collector for Network Shares
ID: 5a71e958-ece9-559b-ac29-481f2e7d6688
STIX ID: report--5a71e958-ece9-559b-ac29-481f2e7d6688
Feed Name: SpecterOps Blog
This article presents ShareHound, a tool for BloodHound CE/Enterprise that efficiently maps SMB network shares, permissions, and file paths across domains using multithreading, per-host throttling, and a ShareQL filtering language to target crawling. It outlines practical Cypher queries to uncover principals with write or full-control access to shares and to find sensitive artifacts (e.g., VMDK files), shows example CLI usage, and recommends depth-limiting for time-sensitive assessments—supporting rapid identification of attack paths commonly leveraged in ransomware and lateral movement scenarios.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
