
Rustで書かれたBloodHound Legacy向けActive Directoryデータインジェスター。🦀
このバージョンは BloodHound Legacy 4.x とのみ互換性があります
BloodHound Community Edition (CE) に対応したバージョンは、こちら RustHound-CE にあります。
SharpHoundのすべての機能が実装されているわけではありません。RustHoundに存在する機能の中には、SharpHoundやBloodHound-Pythonにはないものもあります。詳細についてはロードマップを参照してください。
RustHoundはRustで書かれたクロスプラットフォームのBloodHoundコレクタツールで、Linux、Windows、macOSと互換性があります。
AV検出がなく、クロスコンパイル可能です。
RustHoundは、ユーザー、グループ、コンピュータ、OU、GPO、コンテナ、ドメインのJSONファイルを生成し、BloodHoundで分析できます。
💡 SharpHoundが使えるならそちらを使ってください。 SharpHoundがAVに検出されたり、OSと互換性がない場合のバックアップソリューションとしてRustHoundを使用してください。
makeコマンドを使用してRustHoundをインストールしたり、LinuxまたはWindows用にコンパイルできます。
make install
rusthound -h
Makefileのその他のコマンド:
デフォルト:
usage: make install
usage: make uninstall
usage: make debug
usage: make release
静的:
usage: make windows
usage: make windows_x64
usage: make windows_x86
usage: make linux_aarch64
usage: make linux_x86_64
usage: make linux_musl
usage: make macos
usage: make arm_musl
usage: make armv7
CLI引数なし:
usage: make windows_noargs
依存関係:
usage: make install_windows_deps
usage: make install_linux_musl_deps
usage: make install_macos_deps
DockerでRustHoundを使用して、すべての依存関係を確実に用意します。
docker build --rm -t rusthound .
# その後
docker run --rm -v ./:/usr/src/rusthound rusthound windows
docker run --rm -v ./:/usr/src/rusthound rusthound linux_musl
docker run --rm -v ./:/usr/src/rusthound rusthound macos
システムにRustをインストールする必要があります。
https://www.rust-lang.org/fr/tools/install
RustHoundはKerberosとGSSAPIをサポートしています。そのため、Clangとその開発ライブラリ、およびKerberos開発ライブラリが必要です。DebianとUbuntuでは、clang-N、libclang-N-dev、libkrb5-devを意味します。
例:
# Debian/Ubuntu
sudo apt-get -y update && sudo apt-get -y install gcc clang libclang-dev libgssapi-krb5-2 libkrb5-dev libsasl2-modules-gssapi-mit musl-tools gcc-mingw-w64-x86-64
以下は、cargoコマンドを使用した"release"と"debug"バージョンのコンパイル方法です。
git clone https://github.com/OPENCYBER-FR/RustHound
cd RustHound
cargo build --release
# またはデバッグバージョン
cargo b
結果はtarget/releaseまたはtarget/debugフォルダにあります。
以下に、Linuxから各OSのコンパイル方法を示します。 別のコンパイルシステムが必要な場合は、このリンク先のリストを参照してください: https://doc.rust-lang.org/nightly/rustc/platform-support.html
# Linux用のrustupとCargoをインストール
curl https://sh.rustup.rs -sSf | sh
# Linuxの依存関係を追加
rustup install stable-x86_64-unknown-linux-gnu
rustup target add x86_64-unknown-linux-gnu
# Linux向け静的コンパイル
git clone https://github.com/OPENCYBER-FR/RustHound
cd RustHound
CFLAGS="-lrt";LDFLAGS="-lrt";RUSTFLAGS='-C target-feature=+crt-static';cargo build --release --target x86_64-unknown-linux-gnu
結果はtarget/x86_64-unknown-linux-gnu/releaseフォルダにあります。
# LinuxにrustupとCargoをインストール
curl https://sh.rustup.rs -sSf | sh
# Windowsの依存関係を追加
rustup install stable-x86_64-pc-windows-gnu
rustup target add x86_64-pc-windows-gnu
# Windows向け静的コンパイル
git clone https://github.com/OPENCYBER-FR/RustHound
cd RustHound
RUSTFLAGS="-C target-feature=+crt-static" cargo build --release --target x86_64-pc-windows-gnu
結果はtarget/x86_64-pc-windows-gnu/releaseフォルダにあります。
素晴らしいドキュメント: https://wapl.es/rust/2019/02/17/rust-cross-compile-linux-to-macos.html
# LinuxにrustupとCargoをインストール
curl https://sh.rustup.rs -sSf | sh
# macOSツールチェーンを追加
sudo git clone https://github.com/tpoechtrager/osxcross /usr/local/bin/osxcross
sudo wget -P /usr/local/bin/osxcross/ -nc https://s3.dockerproject.org/darwin/v2/MacOSX10.10.sdk.tar.xz && sudo mv /usr/local/bin/osxcross/MacOSX10.10.sdk.tar.xz /usr/local/bin/osxcross/tarballs/
sudo UNATTENDED=yes OSX_VERSION_MIN=10.7 /usr/local/bin/osxcross/build.sh
sudo chmod 775 /usr/local/bin/osxcross/ -R
export PATH="/usr/local/bin/osxcross/target/bin:$PATH"
# Cargoにx86_64-apple-darwinターゲット用の正しいリンカを指定するため、プロジェクトの.cargo/configファイルに以下を追加します:
grep 'target.x86_64-apple-darwin' ~/.cargo/config || echo "[target.x86_64-apple-darwin]" >> ~/.cargo/config
grep 'linker = "x86_64-apple-darwin14-clang"' ~/.cargo/config || echo 'linker = "x86_64-apple-darwin14-clang"' >> ~/.cargo/config
grep 'ar = "x86_64-apple-darwin14-clang"' ~/.cargo/config || echo 'ar = "x86_64-apple-darwin14-clang"' >> ~/.cargo/config
# macOS向け静的コンパイル
git clone https://github.com/OPENCYBER-FR/RustHound
cd RustHound
RUSTFLAGS="-C target-feature=+crt-static" cargo build --release --target x86_64-apple-darwin --features nogssapi
結果はtarget/x86_64-apple-darwin/releaseフォルダにあります。
💡 最適化されたRustHoundのコンパイルを得るには、
Cargo.tomlファイルの末尾に以下のコンパイルパラメータを追加します。
[profile.release]
opt-level = "z"
lto = true
strip = true
codegen-units = 1
panic = "abort"
バイナリのサイズが大幅に最小化されます。 基本的なcargoコンパイラコマンドを使用できます。
make windows
詳細はこちら
git clone https://github.com/OPENCYBER-FR/RustHound
cd RustHound
cargo doc --open --no-deps
Usage: rusthound [OPTIONS] --domain <domain>
Options:
-v... Set the level of verbosity
-h, --help Print help information
-V, --version Print version information
REQUIRED VALUES:
-d, --domain <domain> Domain name like: DOMAIN.LOCAL