Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
LogHound — Post-Exploitation EVTX Analyzer for BloodHound Mapping | Kitploit
Tools/GitHubGitHub/rnb-team/loghound
ReconnaissanceForensicsInformation GatheringPost-ExploitationDigital ForensicsPenetration TestingAuthenticationRed TeamingLog Analysis
GitHubrnb-team/loghound

LogHound

Post-Exploitation EVTX Analyzer for BloodHound Mapping

111174 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository

LogHound

587193175-819ba1ad-8551-4b58-bb54-56ce1f410187

Post-Exploitation EVTX Analyzer for BloodHound Mapping

LogHound collects and parses Windows Security Event Logs (.evtx) to extract authentication events, session data, and logon metadata for ingestion into BloodHound and for deeper adversarial telemetry.

Reasoning & Overview

LogHound was built to solve a specific problem for Red Teams and network penetration testers: how to efficiently track lateral movement targets, decipher active user sessions, and establish definitive machine ownership without burning operational security (OpSec).

Event log files (Security.evtx) on Active Directory Domain Controllers can be multi-gigabyte beasts. Traditional loading techniques often exhaust system memory or crash, leaving loud artifacts. LogHound addresses this by utilizing a chunk-based streaming paradigm on top of the robust Impacket framework.

It maps network structures, establishes who actually "owns" a machine based on login frequency, calculates precise working hours to identify off-hours (Night Owl) operations, and feeds this intelligence seamlessly into BloodHound CE (v5+).

Installation Steps

LogHound relies on Python 3 and Impacket. It is highly recommended to use a virtual environment.

# 1. Clone the repository
git clone https://github.com/LogHound/LogHound.git
cd LogHound

# 2. (Optional but Recommended) Create a Python virtual environment
python3 -m venv venv
source venv/bin/activate

# 3. Install the required dependencies
pip install -r requirements.txt

CLI Parameters Description

LogHound's CLI interacts identically to standard Impacket modules (like secretsdump.py), requiring you to specify an explicit operation mode (--local or --remote).

python loghound.py [[domain/]username[:password]@]<targetName or address> [options]

Operation Modes (Mandatory)

  • --local EVTX_FILE: Parse a .evtx file already residing on your local machine.
  • --remote: Pull Security.evtx down from the remote target system using the supplied credentials.

Authentication & Connections

  • -hashes LMHASH:NTHASH: Use NTLM hashes for Pass-The-Hash authentication.
  • -k: Use Kerberos authentication. Pulls credentials from a .ccache file specified by the KRB5CCNAME environment variable.
  • -aesKey hex_key: Use a specific AES key (128 or 256 bits) for Kerberos.
  • -no-pass: Do not prompt for a password interactively.
  • -keytab KEYTAB_FILE: Use a Kerberos keytab file for authentication.
  • -dc-ip IP: Explicit IP Address of the domain controller.
  • -target-ip IP: Explicit IP Address of the target machine (bypasses NetBIOS name resolution failures).

Output Formatting

  • -format {json,csv,md,all}: Dictates the text-based output format. Note: An interactive HTML report and the BloodHound JSON files are always generated. Default is json.
  • -outputfile BASENAME: Name prefix for the generated output reports in the subdirectories.

Performance

  • -threads N: Number of parser threads to run in parallel (Default: 4).
  • -chunk-size N: Number of log records per parsing chunk. Lower values reduce RAM overhead; higher values parse slightly faster (Default: 1000).

Examples

  • Bloodhound edges.
Screenshot 2026-04-08 195058
  • HTML Report.
Screenshot 2026-04-08 193914

Architecture and Dataflow

LogHound utilizes a highly decoupled, memory-efficient analytical pipeline:

  1. Collection (core/collector.py): Connects to the target via SMB, then executes wevtutil epl Security via WMI to export the Security event log to a temp file on the target. The exported file is then downloaded via SMB into loot/YYYY-MM-DD_<target>_Security.evtx to avoid overwrites.
  2. Parsing (core/parser.py): A threaded chunk parser streams over the raw .evtx binary and continuously emits parsed events into a temporary JSON Line buffer (jsonl/loghound_dump.jsonl). If interrupted, it can resume from precise checkpoints.
  3. Analysis (core/analyzer.py): Iterates line-by-line over the .jsonl stream to keep a low RAM footprint. It computes intermediate state dictionaries (session tracking, ownership scoring, logic tracking).
  4. Exporting (core/exporter.py & core/exporter_bloodhound.py): Flushes the analysis RAM-state into the final html/ and json/ export formats dynamically.

For deep architectural logic and previously addressed ingestion errors, please refer to the inner documentation at ARCHITECTURE.md.

Nodes, Attributes, and Metrics Description

LogHound filters natively for six explicit Windows Security Event IDs: 4624, 4634, 4648, 4768, 4769, 4776.

Using these events, LogHound augments BloodHound CE by tying the following custom attributes directly to generated User nodes via the Properties block:

BloodHound CE Merging Architecture

  • ObjectIdentifier SIDs: LogHound ensures ObjectIdentifier mappings align perfectly with existing SharpHound ingests. AD Domain Users receive their native Windows SID (S-1-5-21-...). To prevent BloodHound node tearing, Local Machine Accounts accurately maintain the fallback USER@HOSTNAME standard.
  • Computer Sessions: The generated computers.json utilizes the exact native SessionAPIResult data structure to draw real "HasSession" edges between machines and users.

Custom LogHound User Metrics

The analysis engine calculates working operational hours based on tracked logon/logoff events, omitting anomalies (like sessions spanning multiple days).

Property NameTypeMetric Description
loghound_avg_start_timeStringCalculates the average first logon (00:00 HH:MM) recorded across all observed valid days for the user.
loghound_avg_end_timeStringCalculates the average last activity (logoff or last touch) recorded per day.
loghound_active_daysIntegerTotal count of validated days (with at least one proper session) utilized to compute the average time arrays.
loghound_outside_hoursBooleanTrue/False. Specifically identifies a Night Owl. Evaluates as True if the user's computed active start-to-end window overlaps the overnight range of 22:00 to 06:00.
Avg Hours per DayFloatInternally calculated as the exact time difference between the user's average start time and average end time. (Displayed in text/HTML reports).

Machine Ownership Metrics

The analysis determines the explicit owner of any Workstation or IP Address by counting the most frequent interactive Logons. This binds a primary Owner to the origin node along with an array of secondary Other Users.

Disclaimer

This software is provided for educational, authorized penetration testing, and forensic investigation purposes only. Do not use this against networks for which you do not have explicit permission to operate within.

License

This project is licensed under the Apache License 2.0 - see LICENSE file.

Acknowledgements

  • Created by https://github.com/Nelkmen
  • Inspired by https://github.com/specterops/bloodhound, https://github.com/fortra/impacket
Download Tool