
Active Directory डेटा इन्जेस्टर BloodHound Legacy के लिए, Rust में लिखा गया। 🦀
यह संस्करण केवल BloodHound Legacy 4.x के साथ संगत है
BloodHound Community Edition (CE) के साथ संगत संस्करण यहाँ पाया जा सकता है: RustHound-CE।
सभी SharpHound सुविधाएँ लागू नहीं की गई हैं। कुछ RustHound में मौजूद हैं और SharpHound या BloodHound-Python में नहीं। अधिक जानकारी के लिए कृपया रोडमैप देखें।
RustHound एक क्रॉस-प्लेटफ़ॉर्म BloodHound कलेक्टर टूल है जो Rust में लिखा गया है, जो इसे Linux, Windows और macOS के साथ संगत बनाता है।
कोई AV डिटेक्शन नहीं और क्रॉस-कंपाइल किया गया।
RustHound उपयोगकर्ताओं, समूहों, कंप्यूटरों, OU, GPO, कंटेनरों और डोमेन JSON फ़ाइलें उत्पन्न करता है जिनका विश्लेषण BloodHound के साथ किया जा सकता है।
💡 यदि आप SharpHound का उपयोग कर सकते हैं, तो इसका उपयोग करें। RustHound का उपयोग बैकअप समाधान के रूप में करें यदि SharpHound का AV द्वारा पता लगाया जाता है या यह आपके OS के साथ संगत नहीं है।
RustHound को स्थापित करने या Linux या Windows के लिए इसे कंपाइल करने के लिए आप make कमांड का उपयोग कर सकते हैं।
make install
rusthound -h
More command in the Makefile:
Default:
usage: make install
usage: make uninstall
usage: make debug
usage: make release
Static:
usage: make windows
usage: make windows_x64
usage: make windows_x86
usage: make linux_aarch64
usage: make linux_x86_64
usage: make linux_musl
usage: make macos
usage: make arm_musl
usage: make armv7
Without cli argument:
usage: make windows_noargs
Dependencies:
usage: make install_windows_deps
usage: make install_linux_musl_deps
usage: make install_macos_deps
सभी निर्भरताओं को सुनिश्चित करने के लिए RustHound का Docker के साथ उपयोग करें।
docker build --rm -t rusthound .
# Then
docker run --rm -v ./:/usr/src/rusthound rusthound windows
docker run --rm -v ./:/usr/src/rusthound rusthound linux_musl
docker run --rm -v ./:/usr/src/rusthound rusthound macos
आपको अपने सिस्टम पर Rust स्थापित करने की आवश्यकता होगी।
https://www.rust-lang.org/fr/tools/install
RustHound Kerberos और GSSAPI का समर्थन करता है। इसलिए, इसे Clang और इसकी विकास लाइब्रेरी, साथ ही Kerberos विकास लाइब्रेरी की आवश्यकता है। Debian और Ubuntu पर, इसका अर्थ है clang-N, libclang-N-dev, और libkrb5-dev।
For example:
# Debian/Ubuntu
sudo apt-get -y update && sudo apt-get -y install gcc clang libclang-dev libgssapi-krb5-2 libkrb5-dev libsasl2-modules-gssapi-mit musl-tools gcc-mingw-w64-x86-64
यहां cargo कमांड का उपयोग करके "release" और "debug" संस्करणों को कंपाइल करने का तरीका दिया गया है।
git clone https://github.com/OPENCYBER-FR/RustHound
cd RustHound
cargo build --release
# or debug version
cargo b
परिणाम target/release या target/debug फ़ोल्डर में पाया जा सकता है।
नीचे आप Linux से प्रत्येक OS के लिए संकलन विधि पा सकते हैं। यदि आपको किसी अन्य संकलन प्रणाली की आवश्यकता है, तो कृपया इस लिंक पर सूची देखें: https://doc.rust-lang.org/nightly/rustc/platform-support.html
# Install rustup and Cargo for Linux
curl https://sh.rustup.rs -sSf | sh
# Add Linux deps
rustup install stable-x86_64-unknown-linux-gnu
rustup target add x86_64-unknown-linux-gnu
# Static compilation for Linux
git clone https://github.com/OPENCYBER-FR/RustHound
cd RustHound
CFLAGS="-lrt";LDFLAGS="-lrt";RUSTFLAGS='-C target-feature=+crt-static';cargo build --release --target x86_64-unknown-linux-gnu
परिणाम target/x86_64-unknown-linux-gnu/release फ़ोल्डर में पाया जा सकता है।
# Install rustup and Cargo in Linux
curl https://sh.rustup.rs -sSf | sh
# Add Windows deps
rustup install stable-x86_64-pc-windows-gnu
rustup target add x86_64-pc-windows-gnu
# Static compilation for Windows
git clone https://github.com/OPENCYBER-FR/RustHound
cd RustHound
RUSTFLAGS="-C target-feature=+crt-static" cargo build --release --target x86_64-pc-windows-gnu
परिणाम target/x86_64-pc-windows-gnu/release फ़ोल्डर में पाया जा सकता है।
अद्भुत दस्तावेज़: https://wapl.es/rust/2019/02/17/rust-cross-compile-linux-to-macos.html
# Install rustup and Cargo in Linux
curl https://sh.rustup.rs -sSf | sh
# Add macOS tool chain
sudo git clone https://github.com/tpoechtrager/osxcross /usr/local/bin/osxcross
sudo wget -P /usr/local/bin/osxcross/ -nc https://s3.dockerproject.org/darwin/v2/MacOSX10.10.sdk.tar.xz && sudo mv /usr/local/bin/osxcross/MacOSX10.10.sdk.tar.xz /usr/local/bin/osxcross/tarballs/
sudo UNATTENDED=yes OSX_VERSION_MIN=10.7 /usr/local/bin/osxcross/build.sh
sudo chmod 775 /usr/local/bin/osxcross/ -R
export PATH="/usr/local/bin/osxcross/target/bin:$PATH"
# Cargo needs to be told to use the correct linker for the x86_64-apple-darwin target, so add the following to your project’s .cargo/config file:
grep 'target.x86_64-apple-darwin' ~/.cargo/config || echo "[target.x86_64-apple-darwin]" >> ~/.cargo/config
grep 'linker = "x86_64-apple-darwin14-clang"' ~/.cargo/config || echo 'linker = "x86_64-apple-darwin14-clang"' >> ~/.cargo/config
grep 'ar = "x86_64-apple-darwin14-clang"' ~/.cargo/config || echo 'ar = "x86_64-apple-darwin14-clang"' >> ~/.cargo/config
# Static compilation for macOS
git clone https://github.com/OPENCYBER-FR/RustHound
cd RustHound
RUSTFLAGS="-C target-feature=+crt-static" cargo build --release --target x86_64-apple-darwin --features nogssapi
परिणाम target/x86_64-apple-darwin/release फ़ोल्डर में पाया जा सकता है।