Collection
Linux
Collect from your attack box using bloodhound-python or nxc: no need to touch the target host.Windows
Start BloodHound CE
Key Queries
Run these in order after importing data: they cover the most common privilege escalation paths.- Shortest Path to Domain Admin
- Shortest Path from Owned Principals
- Find Principals with DCSync Rights
- Find Kerberoastable Users
- Find AS-REP Roastable Users
- Computers Where Domain Users are Local Admin