SharpHound is an open-source C# data collection tool used to gather Active Directory and, in related variants such as AzureHound, Microsoft cloud identity information for analysis in BloodHound. It is widely used by red teams, penetration testers, and threat actors to map trust relationships, privileged paths, users, groups, sessions, service principal names, shares, and other directory metadata that support attack-path analysis and privilege escalation planning.
In intrusions, SharpHound is primarily used for reconnaissance and post-compromise discovery rather than as a standalone payload. Operators commonly execute it in memory through frameworks such as Cobalt Strike or Havoc, or deploy it after obtaining an initial foothold through compromised credentials, web-shell access, or exploitation of vulnerable servers. It has been observed in campaigns attributed to multiple threat actors, including UNC3944, China-linked UAT-8837, and clusters associated with Operation Crimson Palace, where it was used to map Active Directory infrastructure and support lateral movement and credential-focused operations.
SharpHound can enumerate users, groups, computers, sessions, domain trusts, service accounts, and shares using LDAP and RPC-based collection methods. The resulting graph data enables identification of administrative relationships, delegation paths, Kerberoasting opportunities, and other high-value attack paths inside Windows enterprise environments. Because it is a legitimate open-source security tool, its presence is not inherently malicious, but in unauthorized contexts it is a strong indicator of adversary reconnaissance against Active Directory.
Defenders frequently monitor for SharpHound command-line usage, in-memory execution, LDAP query patterns, and unusual RPC-based enumeration activity. Its operational role is best characterized as Active Directory reconnaissance tooling used during hands-on-keyboard post-exploitation in Windows domain environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2025-53690 is a ViewState deserialization vulnerability that affects any version of Sitecore Experience Manager (XM), Experience Platform (XP), Experience Commerce (XC), and Managed Cloud deployed in the manner above. Successful exploitation of the vulnerability might lead to remote code execution and non-authorised access to information. | SharpHound
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
UNC3944 will also use network reconnaissance tools like ADRecon, ADExplorer, and SharpHound.
"...most likely accomplished through the use of SharpHound, a Microsoft C#-based data 'injestor' tool for BloodHound..."
17 distinct techniques documented for this family, organized by ATT&CK tactic.
the attackers used a command shell session spawned from the malicious DLL to move laterally via WMIC, and to deploy the open-source SharpHound tool...
Run Sharphound and load the results into Bloodhound. This will give you a graph of what users have access to. It will also give you effective permissions.
LDAP-запросы дают полную карту: пользователи, группы, делегации, SPN, ACL-записи.
UNC3944 will also use network reconnaissance tools like ADRecon, ADExplorer, and SharpHound.
AD enumeration tools that can be used to find weaknesses in Active Directory were also seen in the form of Pingcastle and Sharphound
LDAP-запросы дают полную карту: пользователи, группы, делегации, SPN, ACL-записи.
[TA0007][T1087] AD account discovery Akira queries to obtain the maximum knowledge of the Active Directory and hence the infrastructure
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A reconnaissance tool used to enumerate users, sessions, and shares in Active Directory environments via RPC calls.
Active Directory reconnaissance collector used to enumerate directory relationships and privileges.
An Active Directory reconnaissance tool (commonly used with BloodHound) for enumerating users, groups, and domain relationships to map attack paths.
A tool used to collect Active Directory information for reconnaissance and privilege mapping.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.