
Ingestore di dati di Active Directory per BloodHound Legacy scritto in Rust. 🦀
Questa versione è compatibile solo con BloodHound Legacy 4.x
La versione compatibile con BloodHound Community Edition (CE) è disponibile qui RustHound-CE.
Non tutte le funzionalità di SharpHound sono state implementate. Alcune esistono in RustHound e non in SharpHound o BloodHound-Python. Fare riferimento alla roadmap per maggiori informazioni.
RustHound è uno strumento di raccolta BloodHound cross-platform scritto in Rust, che lo rende compatibile con Linux, Windows e macOS.
Nessuna rilevazione AV e cross-compilato.
RustHound genera file JSON di utenti, gruppi, computer, OU, GPO, contenitori e domini che possono essere analizzati con BloodHound.
💡 Se puoi usare SharpHound, usalo. Usa RustHound come soluzione di backup se SharpHound viene rilevato dall'AV o se non è compatibile con il tuo sistema operativo.
Puoi usare il comando make per installare RustHound o per compilarlo per Linux o Windows.
make install
rusthound -h
Ulteriori comandi nel Makefile:
Default:
usage: make install
usage: make uninstall
usage: make debug
usage: make release
Static:
usage: make windows
usage: make windows_x64
usage: make windows_x86
usage: make linux_aarch64
usage: make linux_x86_64
usage: make linux_musl
usage: make macos
usage: make arm_musl
usage: make armv7
Without cli argument:
usage: make windows_noargs
Dependencies:
usage: make install_windows_deps
usage: make install_linux_musl_deps
usage: make install_macos_deps
Usa RustHound con Docker per assicurarti di avere tutte le dipendenze.
docker build --rm -t rusthound .
# Then
docker run --rm -v ./:/usr/src/rusthound rusthound windows
docker run --rm -v ./:/usr/src/rusthound rusthound linux_musl
docker run --rm -v ./:/usr/src/rusthound rusthound macos
Dovrai installare Rust sul tuo sistema.
https://www.rust-lang.org/fr/tools/install
RustHound supporta Kerberos e GSSAPI. Pertanto, richiede Clang e le sue librerie di sviluppo, così come le librerie di sviluppo di Kerberos. Su Debian e Ubuntu, questo significa clang-N, libclang-N-dev e libkrb5-dev.
Ad esempio:
# Debian/Ubuntu
sudo apt-get -y update && sudo apt-get -y install gcc clang libclang-dev libgssapi-krb5-2 libkrb5-dev libsasl2-modules-gssapi-mit musl-tools gcc-mingw-w64-x86-64
Ecco come compilare le versioni "release" e "debug" usando il comando cargo.
git clone https://github.com/OPENCYBER-FR/RustHound
cd RustHound
cargo build --release
# or debug version
cargo b
Il risultato si trova nella cartella target/release o target/debug.
Di seguito puoi trovare la metodologia di compilazione per ciascun sistema operativo da Linux. Se hai bisogno di un altro sistema di compilazione, consulta l'elenco in questo link: https://doc.rust-lang.org/nightly/rustc/platform-support.html
# Install rustup and Cargo for Linux
curl https://sh.rustup.rs -sSf | sh
# Add Linux deps
rustup install stable-x86_64-unknown-linux-gnu
rustup target add x86_64-unknown-linux-gnu
# Static compilation for Linux
git clone https://github.com/OPENCYBER-FR/RustHound
cd RustHound
CFLAGS="-lrt";LDFLAGS="-lrt";RUSTFLAGS='-C target-feature=+crt-static';cargo build --release --target x86_64-unknown-linux-gnu
Il risultato si trova nella cartella target/x86_64-unknown-linux-gnu/release.
# Install rustup and Cargo in Linux
curl https://sh.rustup.rs -sSf | sh
# Add Windows deps
rustup install stable-x86_64-pc-windows-gnu
rustup target add x86_64-pc-windows-gnu
# Static compilation for Windows
git clone https://github.com/OPENCYBER-FR/RustHound
cd RustHound
RUSTFLAGS="-C target-feature=+crt-static" cargo build --release --target x86_64-pc-windows-gnu
Il risultato si trova nella cartella target/x86_64-pc-windows-gnu/release.
Documentazione fantastica: https://wapl.es/rust/2019/02/17/rust-cross-compile-linux-to-macos.html
# Install rustup and Cargo in Linux
curl https://sh.rustup.rs -sSf | sh
# Add macOS tool chain
sudo git clone https://github.com/tpoechtrager/osxcross /usr/local/bin/osxcross
sudo wget -P /usr/local/bin/osxcross/ -nc https://s3.dockerproject.org/darwin/v2/MacOSX10.10.sdk.tar.xz && sudo mv /usr/local/bin/osxcross/MacOSX10.10.sdk.tar.xz /usr/local/bin/osxcross/tarballs/
sudo UNATTENDED=yes OSX_VERSION_MIN=10.7 /usr/local/bin/osxcross/build.sh
sudo chmod 775 /usr/local/bin/osxcross/ -R
export PATH="/usr/local/bin/osxcross/target/bin:$PATH"
# Cargo needs to be told to use the correct linker for the x86_64-apple-darwin target, so add the following to your project’s .cargo/config file:
grep 'target.x86_64-apple-darwin' ~/.cargo/config || echo "[target.x86_64-apple-darwin]" >> ~/.cargo/config
grep 'linker = "x86_64-apple-darwin14-clang"' ~/.cargo/config || echo 'linker = "x86_64-apple-darwin14-clang"' >> ~/.cargo/config
grep 'ar = "x86_64-apple-darwin14-clang"' ~/.cargo/config || echo 'ar = "x86_64-apple-darwin14-clang"' >> ~/.cargo/config
# Static compilation for macOS
git clone https://github.com/OPENCYBER-FR/RustHound
cd RustHound
RUSTFLAGS="-C target-feature=+crt-static" cargo build --release --target x86_64-apple-darwin --features nogssapi
Il risultato si trova nella cartella target/x86_64-apple-darwin/release.