logo

Cato CTRL™ Threat Research: Overview of BloodHound and Associated Collectors Including ShadowHound, SharpHound, and SoapHound 

ID: 90cdba00-48df-5a9c-bc56-22022152aa6d

STIX ID: report--90cdba00-48df-5a9c-bc56-22022152aa6d

Feed Name: Cato Networks

Threat Score
65/100

Date Published: 2025-07-08

Date Updated: 2026-07-23

Author: Dolev Moshe Attiya

...
...

This report analyzes BloodHound and three associated collectors (SharpHound, SoapHound, ShadowHound), detailing how each gathers Active Directory data (LDAP, SMB/DCERPC, ADWS), their stealth and evasion capabilities, differences in deployment (binaries vs PowerShell), practical defensive and offensive uses, and detection strategies to identify large-scale AD enumeration that could lead to privilege escalation and lateral movement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.