Attack Tool(s): BloodHound, PlumHound, ADMiner, SCCMHunter
- BloodHound: https://github.com/BloodHoundAD/BloodHound
- PlumHound: https://github.com/PlumHound/PlumHound
- ADMiner: https://github.com/MAQsecure/ADMiner
- SCCMHunter: https://github.com/garrettfoster13/sccmhunter
Detection Link(s):
- Security Information and Event Management (SIEM) Log Analysis
- User and Entity Behavior Analytics (UEBA)
- Endpoint Security Protection Analysis
- Active Defense and Cyber Deception
Helpful Blogs (BHIS):
- “Webcast: Weaponizing Active Directory” – https://www.blackhillsinfosec.com/webcast-weaponizing-active-directory – BloodHound usage.
- “PlumHound Reporting Engine for BloodHoundAD” – https://www.blackhillsinfosec.com/plumhound-reporting-engine-for-bloodhoundad – PlumHound overview.
