Skip to content
KitploitKITPLOIT
ToolsBlog
Einreichen
ToolsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

··Feeds·Kontakt·Datenschutz·© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
RustHound — Active Directory Dateningestor für BloodHound Legacy, geschrieben in Rust. 🦀 | Kitploit
Tools/GitHubGitHub/nh-red-team/rusthound
AufklärungInformationsbeschaffungPenetrationstestsRed Teaming
GitHubnh-red-team/rusthound

RustHound

Active Directory Dateningestor für BloodHound Legacy, geschrieben in Rust. 🦀

Repository anzeigen
1.2k1072vor 1 JahrVon Kitploit geprüft

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Teilen

Diese Version ist nur mit BloodHound Legacy 4.x kompatibel

Die mit BloodHound Community Edition (CE) kompatible Version finden Sie hier RustHound-CE.


Crates.io GitHub Twitter Follow Twitter Follow
Linux supported Windows supported macOS supported

Zusammenfassung

  • Einschränkungen

  • Beschreibung

  • Wie kompilieren?

    • Mit Makefile
    • Mit Dockerfile
    • Mit Cargo
    • Linux x86_64 statische Version
    • Windows statische Version von Linux aus
    • macOS statische Version von Linux aus
    • Binärgröße optimieren
  • Wie die Dokumentation erstellen?

  • Verwendung

  • Demo

    • Einfache Verwendung
    • Modul FQDN-Auflöser
    • Modul ADCS-Collector
  • 🚀 Statistiken

  • 🚥 Fahrplan

  • 🔗 Links

Einschränkungen

Nicht alle SharpHound-Funktionen wurden implementiert. Einige existieren in RustHound und nicht in SharpHound oder BloodHound-Python. Bitte beachten Sie die Fahrplan für weitere Informationen.

Beschreibung

RustHound ist ein plattformübergreifendes BloodHound-Collector-Tool, geschrieben in Rust, das mit Linux, Windows und macOS kompatibel ist.

Keine AV-Erkennung und cross-kompiliert.

RustHound generiert JSON-Dateien für Benutzer, Gruppen, Computer, OUs, GPOs, Container und Domänen, die mit BloodHound analysiert werden können.

💡 Wenn Sie SharpHound verwenden können, tun Sie das. Verwenden Sie RustHound als Backup-Lösung, wenn SharpHound von der Antivirensoftware erkannt wird oder nicht mit Ihrem Betriebssystem kompatibel ist.

Wie kompilieren?

Mit Makefile

Sie können den make Befehl verwenden, um RustHound zu installieren oder für Linux oder Windows zu kompilieren.

root@kitploit:~
make install
rusthound -h

Weitere Befehle in der Makefile:

root@kitploit:~
Default:
usage: make install
usage: make uninstall
usage: make debug
usage: make release

Static:
usage: make windows
usage: make windows_x64
usage: make windows_x86
usage: make linux_aarch64
usage: make linux_x86_64
usage: make linux_musl
usage: make macos
usage: make arm_musl
usage: make armv7

Without cli argument:
usage: make windows_noargs

Dependencies:
usage: make install_windows_deps
usage: make install_linux_musl_deps
usage: make install_macos_deps

Mit Dockerfile

Verwenden Sie RustHound mit Docker, um sicherzustellen, dass alle Abhängigkeiten vorhanden sind.

root@kitploit:~
docker build --rm -t rusthound .

# Then
docker run --rm -v ./:/usr/src/rusthound rusthound windows
docker run --rm -v ./:/usr/src/rusthound rusthound linux_musl
docker run --rm -v ./:/usr/src/rusthound rusthound macos

Mit Cargo

Sie müssen Rust auf Ihrem System installieren.

https://www.rust-lang.org/fr/tools/install

RustHound unterstützt Kerberos und GSSAPI. Daher werden Clang und seine Entwicklungsbibliotheken sowie die Kerberos-Entwicklungsbibliotheken benötigt. Auf Debian und Ubuntu bedeutet dies clang-N, libclang-N-dev und libkrb5-dev.

Zum Beispiel:

root@kitploit:~
# Debian/Ubuntu
sudo apt-get -y update && sudo apt-get -y install gcc clang libclang-dev libgssapi-krb5-2 libkrb5-dev libsasl2-modules-gssapi-mit musl-tools gcc-mingw-w64-x86-64

So kompilieren Sie die "release" und "debug" Versionen mit dem cargo Befehl.

root@kitploit:~
git clone https://github.com/OPENCYBER-FR/RustHound
cd RustHound
cargo build --release
# or debug version
cargo b

Das Ergebnis finden Sie im Ordner target/release oder target/debug.

Nachfolgend finden Sie die Kompilierungsmethodik für jedes Betriebssystem von Linux aus. Falls Sie ein anderes Kompilierungssystem benötigen, konsultieren Sie bitte die Liste unter diesem Link: https://doc.rust-lang.org/nightly/rustc/platform-support.html

Manuell für Linux x86_64 statische Version

root@kitploit:~
# Install rustup and Cargo for Linux
curl https://sh.rustup.rs -sSf | sh

# Add Linux deps
rustup install stable-x86_64-unknown-linux-gnu
rustup target add x86_64-unknown-linux-gnu

# Static compilation for Linux
git clone https://github.com/OPENCYBER-FR/RustHound
cd RustHound
CFLAGS="-lrt";LDFLAGS="-lrt";RUSTFLAGS='-C target-feature=+crt-static';cargo build --release --target x86_64-unknown-linux-gnu

Das Ergebnis finden Sie im Ordner target/x86_64-unknown-linux-gnu/release.

Manuell für Windows statische Version von Linux aus

root@kitploit:~
# Install rustup and Cargo in Linux
curl https://sh.rustup.rs -sSf | sh

# Add Windows deps
rustup install stable-x86_64-pc-windows-gnu
rustup target add x86_64-pc-windows-gnu

# Static compilation for Windows
git clone https://github.com/OPENCYBER-FR/RustHound
cd RustHound
RUSTFLAGS="-C target-feature=+crt-static" cargo build --release --target x86_64-pc-windows-gnu

Das Ergebnis finden Sie im Ordner target/x86_64-pc-windows-gnu/release.

Manuell für macOS statische Version von Linux aus

Tolle Dokumentation: https://wapl.es/rust/2019/02/17/rust-cross-compile-linux-to-macos.html

root@kitploit:~
# Install rustup and Cargo in Linux
curl https://sh.rustup.rs -sSf | sh

# Add macOS tool chain
sudo git clone https://github.com/tpoechtrager/osxcross /usr/local/bin/osxcross
sudo wget -P /usr/local/bin/osxcross/ -nc https://s3.dockerproject.org/darwin/v2/MacOSX10.10.sdk.tar.xz && sudo mv /usr/local/bin/osxcross/MacOSX10.10.sdk.tar.xz /usr/local/bin/osxcross/tarballs/
sudo UNATTENDED=yes OSX_VERSION_MIN=10.7 /usr/local/bin/osxcross/build.sh
sudo chmod 775 /usr/local/bin/osxcross/ -R
export PATH="/usr/local/bin/osxcross/target/bin:$PATH"

# Cargo needs to be told to use the correct linker for the x86_64-apple-darwin target, so add the following to your project’s .cargo/config file:
grep 'target.x86_64-apple-darwin' ~/.cargo/config || echo "[target.x86_64-apple-darwin]" >> ~/.cargo/config
grep 'linker = "x86_64-apple-darwin14-clang"' ~/.cargo/config || echo 'linker = "x86_64-apple-darwin14-clang"' >> ~/.cargo/config
grep 'ar = "x86_64-apple-darwin14-clang"' ~/.cargo/config || echo 'ar = "x86_64-apple-darwin14-clang"' >> ~/.cargo/config

# Static compilation for macOS
git clone https://github.com/OPENCYBER-FR/RustHound
cd RustHound
RUSTFLAGS="-C target-feature=+crt-static" cargo build --release --target x86_64-apple-darwin --features nogssapi

Das Ergebnis finden Sie im Ordner target/x86_64-apple-darwin/release.

Binärgröße optimieren

💡 Um eine optimierte Kompilierung von RustHound zu erhalten, fügen Sie die folgenden Kompilierungsparameter am Ende der Cargo.toml Datei hinzu.

root@kitploit:~
[profile.release]
opt-level = "z"
lto = true
strip = true
codegen-units = 1
panic = "abort"

Die Größe der Binärdatei wird erheblich minimiert. Grundlegende Cargo-Compiler-Befehle können verwendet werden.

root@kitploit:~
make windows

Weitere Informationen hier

Wie die Dokumentation erstellen?

root@kitploit:~
git clone https://github.com/OPENCYBER-FR/RustHound
cd RustHound
cargo doc --open --no-deps

Verwendung

root@kitploit:~
Usage: rusthound [OPTIONS] --domain <domain>

Options:
  -v...          Set the level of verbosity
  -h, --help     Print help information
  -V, --version  Print version information

REQUIRED VALUES:
  -d, --domain <domain>  Domain name like: DOMAIN.LOCAL

OPTIONAL VALUES:
  -u, --ldapusername <ldapusername>  LDAP username, like: [email protected]
  -p, --ldappassword <ldappassword>  LDAP password
  -f, --ldapfqdn <ldapfqdn>          Domain Controler FQDN like: DC01.DOMAIN.LOCAL or just DC01
  -i, --ldapip <ldapip>              Domain Controller IP address like: 192.168.1.10
  -P, --ldapport <ldapport>          LDAP port [default: 389]
  -n, --name-server <name-server>    Alternative IP address name server to use for DNS queries
  -o, --output <output>              Output directory where you would like to save JSON files [default: ./]

OPTIONAL FLAGS:
      --ldaps           Force LDAPS using for request like: ldaps://DOMAIN.LOCAL/
      --dns-tcp         Use TCP instead of UDP for DNS queries
      --dc-only         Collects data only from the domain controller. Will not try to retrieve CA security/configuration or check for Web Enrollment
      --old-bloodhound  For ADCS only. Output result as BloodHound data for the original BloodHound version from @BloodHoundAD without PKI support
  -z, --zip             Compress the JSON files into a zip archive

OPTIONAL MODULES:
      --fqdn-resolver  Use fqdn-resolver module to get computers IP address
      --adcs           Use ADCS module to enumerate Certificate Templates, Certificate Authorities and other configurations.
                       (For the custom-built BloodHound version from @ly4k with PKI support)

Demo

Beispiele wurden mit GOADv2 durchgeführt, implementiert von mayfly:

Einfache Verwendung

root@kitploit:~
# Linux with username:password
rusthound -d north.sevenkingdoms.local -u '[email protected]' -p '_L0ngCl@w_' -o /tmp/demo -z

# Linux with username:password and ldapip
rusthound -d north.sevenkingdoms.local -i 192.168.56.11 -u '[email protected]' -p '_L0ngCl@w_' -o /tmp/demo -z

# Linux with username:password and ldaps
rusthound -d north.sevenkingdoms.local --ldaps -u '[email protected]' -p '_L0ngCl@w_' -o /tmp/demo -z 
# Linux with username:password and ldaps and custom port
rusthound -d north.sevenkingdoms.local --ldaps -P 3636 -u '[email protected]' -p '_L0ngCl@w_' -o /tmp/demo -z 

# Tips to redirect and append both standard output and standard error to a file > /tmp/rh_output 2>&1
rusthound -d north.sevenkingdoms.local --ldaps -u '[email protected]' -p '_L0ngCl@w_' -o /tmp/demo --fqdn-resolver > /tmp/rh_output 2>&1

# Windows with GSSAPI session
rusthound.exe -d sevenkingdoms.local --ldapfqdn kingslanding
# Windows simple bind connection username:password (do not use single or double quotes with cmd.exe)
rusthound.exe -d sevenkingdoms.local -u [email protected] -p _L0ngCl@w_ -o output -z

# Kerberos authentication (Linux)
export KRB5CCNAME="/tmp/jeor.mormont.ccache"
rusthound -d sevenkingdoms.local -f kingslanding -k -z
# Kerberos authentication (Windows)
rusthound.exe -d sevenkingdoms.local -f kingslanding -k -z

Modul FQDN-Auflöser

root@kitploit:~
# Linux with username:password and FQDN resolver module
rusthound -d essos.local -u '[email protected]' -p 'BurnThemAll!' -o /tmp/demo --fqdn-resolver -z
# Linux with username:password and ldaps and FQDN resolver module and TCP DNS request and custom name server
rusthound -d essos.local --ldaps -u '[email protected]' -p 'BurnThemAll!' -o /tmp/demo --fqdn-resolver --tcp-dns --name-server 192.168.56.12 -z

# Windows with GSSAPI session and FQDN resolver module
rusthound.exe -d essos.local -f meereen -o output --fqdn-resolver -z
# Windows simple bind connection username:password and FQDN resolver module and TCP DNS request and custom name server (do not use single or double quotes with cmd.exe)
rusthound.exe -d essos.local -u [email protected] -p BurnThemAll! -o output -z --fqdn-resolver --tcp-dns --name-server 192.168.56.12 

Modul ADCS-Collector

Beispiel mit @ly4k BloodHound version.

root@kitploit:~
# Linux with username:password and ADCS module for @ly4k BloodHound version
rusthound -d essos.local -u '[email protected]' -p 'BurnThemAll!' -o /tmp/adcs --adcs -z
# Linux with username:password and ADCS module and dconly flag (will don't check webenrollment)
rusthound -d essos.local -u '[email protected]' -p 'BurnThemAll!' -o /tmp/adcs --adcs --dc-only -z

# Linux with username:password and ADCS module using "--old-bloodhound" argument for official @BloodHoundAd version
rusthound -d essos.local -u '[email protected]' -p 'BurnThemAll!' -o /tmp/adcs --adcs --old-bloodhound -z

# Windows with GSSAPI session and ADCS module
rusthound.exe -d essos.local -f meereen -o output -z --adcs
# Windows with GSSAPI session and ADCS module and TCP DNS request and custom name server
rusthound.exe -d essos.local --ldapfqdn meereen -o output -z --adcs --tcp-dns --name-server 192.168.56.12
# Windows simple bind connection username:password (do not use single or double quotes with cmd.exe)
rusthound.exe -d essos.local -u [email protected] -p BurnThemAll! -o output -z --adcs --dc-only

Sie können die benutzerdefinierten Abfragen, die in der Demo verwendet werden, im Ressourcenordner finden.

Verwenden Sie den folgenden Befehl, um sie zu installieren:

root@kitploit:~
cp resources/customqueries.json ~/.config/bloodhound/customqueries.json

🚀 Statistiken

Um Statistiken auf einem DC mit mehr LDAP-Objekten zu erstellen, führen Sie BadBlood auf dem Domain-Controller ESSOS.local von GOAD aus. Der DC sollte nun etwa 3500 Objekte haben. Nachfolgend finden Sie die durchschnittliche Zeit, die die folgenden Tools benötigen:

🚥 Fahrplan

Authentifizierung

  • LDAP (389)
  • LDAPS (636)
  • BIND
  • NTLM
  • Kerberos
  • Passwort abfragen

Ausgaben

  • users.json
  • groups.json
  • computers.json
  • ous.json
  • gpos.json
  • containers.json
  • domains.json
  • cas.json
  • templates.json
  • args and function to zip JSON files --zip

Module

  • LAPS-Passwort abrufen, wenn Ihr Benutzer sie lesen kann automatisch
  • Gefundene FQDN-Computer in IP-Adressen auflösen --fqdn-resolver
  • Zertifikate für ESC-Ausnutzung mit Certipy abrufen --adcs
  • Kerberos-Angriffsmodul (ASREPROASTING und KERBEROASTING) --attack-kerberos
  • Daten aus vertrauenswürdigen Domänen abrufen --follow-trust (Derzeit in Arbeit, Beta-Version dieses Moduls vorhanden)

BloodHound v4.2

  • Parsing-Funktionen

    • Benutzer und Computer
      • HasSIDHistory
    • Benutzer
      • Properties : sfupassword
  • DCERPC (Abhängigkeiten)

    • Computer
      • Sessions (Sitzungen)
    • OUs und Domänen
      • LocalAdmins (Lokale Administratoren)
      • RemoteDesktopUsers (Remotedesktopbenutzer)
      • DcomUsers (DCOM-Benutzer)
      • (PS-Remote-Benutzer)

🔗 Links

  • Blogbeitrag: https://www.opencyber.com/rusthound-data-collector-for-bloodhound-written-in-rust/
  • BloodHound.py: https://github.com/fox-it/BloodHound.py
  • SharpHound: https://github.com/BloodHoundAD/SharpHound
  • BloodHound: https://github.com/BloodHoundAD/BloodHound
  • BloodHound docs: https://bloodhound.readthedocs.io/en/latest/index.html
  • GOAD: https://github.com/Orange-Cyberdefense/GOAD
  • ly4k BloodHound version: https://github.com/ly4k/BloodHound
  • Certipy: https://github.com/ly4k/Certipy
Tool herunterladen
ToolUmgebungObjekteZeitBefehl
SharpHound.exeWindows ~3500~51.605sMeasure-Command { sharphound.exe -d essos.local --ldapusername 'khal.drogo' --ldappassword 'horse' --domaincontroller '192.168.56.12' -c All }
BloodHound.pyLinux ~3500~9.657stime python3 bloodhound.py -u khal.drogo -p horse -d essos.local -ns 192.168.56.12 --zip -c all
RustHound.exeWindows ~3500~5.315sMeasure-Command { rusthound.exe -d essos.local -u [email protected] -p horse -z }
RustHoundLinux ~3500~3.166stime rusthound -d essos.local -u [email protected] -p horse -z
PSRemoteUsers
  • CAs
    • User Specified SAN (Benutzerdefiniertes SAN)
    • Request Disposition (Anforderungsdisposition)