Cato CTRL™ Threat Research: Overview of BloodHound and Associated Collectors Including ShadowHound, SharpHound, and SoapHound
ID: 90cdba00-48df-5a9c-bc56-22022152aa6d
STIX ID: report--90cdba00-48df-5a9c-bc56-22022152aa6d
Feed Name: Cato Networks
Threat Score
This report analyzes BloodHound and three associated collectors (SharpHound, SoapHound, ShadowHound), detailing how each gathers Active Directory data (LDAP, SMB/DCERPC, ADWS), their stealth and evasion capabilities, differences in deployment (binaries vs PowerShell), practical defensive and offensive uses, and detection strategies to identify large-scale AD enumeration that could lead to privilege escalation and lateral movement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
