
أداة إدخال بيانات Active Directory لـ BloodHound Legacy مكتوبة بلغة Rust. 🦀
هذا الإصدار متوافق فقط مع BloodHound Legacy 4.x
الإصدار المتوافق مع BloodHound Community Edition (CE) يمكن العثور عليه هنا RustHound-CE.
لم يتم تنفيذ جميع ميزات SharpHound. بعضها موجود في RustHound وليس في SharpHound أو BloodHound-Python. يرجى الرجوع إلى خارطة الطريق لمزيد من المعلومات.
RustHound هي أداة تجميع متعددة المنصات لـ BloodHound مكتوبة بلغة Rust، مما يجعلها متوافقة مع Linux وWindows وmacOS.
لا يوجد كشف من مضادات الفيروسات ومجمعة عبر المنصات.
تقوم RustHound بإنشاء ملفات JSON للمستخدمين والمجموعات وأجهزة الكمبيوتر وOUs وGPOs والحاويات والمجالات التي يمكن تحليلها باستخدام BloodHound.
💡 إذا كان بإمكانك استخدام SharpHound، فاستخدمه. استخدم RustHound كحل احتياطي إذا تم اكتشاف SharpHound بواسطة مضاد الفيروسات أو إذا لم يكن متوافقًا مع نظام التشغيل الخاص بك.
يمكنك استخدام الأمر make لتثبيت RustHound أو لتجميعه لنظامي Linux أو Windows.
make install
rusthound -h
المزيد من الأوامر في Makefile:
Default:
usage: make install
usage: make uninstall
usage: make debug
usage: make release
Static:
usage: make windows
usage: make windows_x64
usage: make windows_x86
usage: make linux_aarch64
usage: make linux_x86_64
usage: make linux_musl
usage: make macos
usage: make arm_musl
usage: make armv7
Without cli argument:
usage: make windows_noargs
Dependencies:
usage: make install_windows_deps
usage: make install_linux_musl_deps
usage: make install_macos_deps
استخدم RustHound مع Docker للتأكد من وجود جميع التبعيات.
docker build --rm -t rusthound .
# Then
docker run --rm -v ./:/usr/src/rusthound rusthound windows
docker run --rm -v ./:/usr/src/rusthound rusthound linux_musl
docker run --rm -v ./:/usr/src/rusthound rusthound macos
ستحتاج إلى تثبيت Rust على نظامك.
https://www.rust-lang.org/fr/tools/install
RustHound تدعم Kerberos وGSSAPI. لذلك، فهي تتطلب Clang ومكتبات التطوير الخاصة به، بالإضافة إلى مكتبات تطوير Kerberos. على Debian وUbuntu، هذا يعني clang-N وlibclang-N-dev وlibkrb5-dev.
على سبيل المثال:
# Debian/Ubuntu
sudo apt-get -y update && sudo apt-get -y install gcc clang libclang-dev libgssapi-krb5-2 libkrb5-dev libsasl2-modules-gssapi-mit musl-tools gcc-mingw-w64-x86-64
إليك كيفية تجميع الإصدارين "release" و"debug" باستخدام الأمر cargo.
git clone https://github.com/OPENCYBER-FR/RustHound
cd RustHound
cargo build --release
# or debug version
cargo b
يمكن العثور على النتيجة في المجلد target/release أو target/debug.
أدناه يمكنك العثور على منهجية التجميع لكل نظام تشغيل من Linux. إذا كنت بحاجة إلى نظام تجميع آخر، يرجى الرجوع إلى القائمة في هذا الرابط: https://doc.rust-lang.org/nightly/rustc/platform-support.html
# Install rustup and Cargo for Linux
curl https://sh.rustup.rs -sSf | sh
# Add Linux deps
rustup install stable-x86_64-unknown-linux-gnu
rustup target add x86_64-unknown-linux-gnu
# Static compilation for Linux
git clone https://github.com/OPENCYBER-FR/RustHound
cd RustHound
CFLAGS="-lrt";LDFLAGS="-lrt";RUSTFLAGS='-C target-feature=+crt-static';cargo build --release --target x86_64-unknown-linux-gnu
يمكن العثور على النتيجة في المجلد target/x86_64-unknown-linux-gnu/release.
# Install rustup and Cargo in Linux
curl https://sh.rustup.rs -sSf | sh
# Add Windows deps
rustup install stable-x86_64-pc-windows-gnu
rustup target add x86_64-pc-windows-gnu
# Static compilation for Windows
git clone https://github.com/OPENCYBER-FR/RustHound
cd RustHound
RUSTFLAGS="-C target-feature=+crt-static" cargo build --release --target x86_64-pc-windows-gnu
يمكن العثور على النتيجة في المجلد target/x86_64-pc-windows-gnu/release.
توثيق رائع: https://wapl.es/rust/2019/02/17/rust-cross-compile-linux-to-macos.html
# Install rustup and Cargo in Linux
curl https://sh.rustup.rs -sSf | sh
# Add macOS tool chain
sudo git clone https://github.com/tpoechtrager/osxcross /usr/local/bin/osxcross
sudo wget -P /usr/local/bin/osxcross/ -nc https://s3.dockerproject.org/darwin/v2/MacOSX10.10.sdk.tar.xz && sudo mv /usr/local/bin/osxcross/MacOSX10.10.sdk.tar.xz /usr/local/bin/osxcross/tarballs/
sudo UNATTENDED=yes OSX_VERSION_MIN=10.7 /usr/local/bin/osxcross/build.sh
sudo chmod 775 /usr/local/bin/osxcross/ -R
export PATH="/usr/local/bin/osxcross/target/bin:$PATH"
# Cargo needs to be told to use the correct linker for the x86_64-apple-darwin target, so add the following to your project’s .cargo/config file:
grep 'target.x86_64-apple-darwin' ~/.cargo/config || echo "[target.x86_64-apple-darwin]" >> ~/.cargo/config
grep 'linker = "x86_64-apple-darwin14-clang"' ~/.cargo/config || echo 'linker = "x86_64-apple-darwin14-clang"' >> ~/.cargo/config
grep 'ar = "x86_64-apple-darwin14-clang"' ~/.cargo/config || echo 'ar = "x86_64-apple-darwin14-clang"' >> ~/.cargo/config
# Static compilation for macOS
git clone https://github.com/OPENCYBER-FR/RustHound
cd RustHound
RUSTFLAGS="-C target-feature=+crt-static" cargo build --release --target x86_64-apple-darwin --features nogssapi
يمكن العثور على النتيجة في المجلد target/x86_64-apple-darwin/release.
💡 للحصول على تجميع محسّن لـ RustHound، أضف معلمات التجميع التالية في نهاية ملف
Cargo.toml.
[profile.release]
opt-level = "z"
lto = true
strip = true
codegen-units = 1
panic = "abort"
سيتم تقليل حجم الملف الثنائي بشكل كبير. يمكن استخدام أوامر تجميع cargo الأساسية.
make windows