
Rust로 작성된 BloodHound Community Edition용 Active Directory 데이터 수집기. 🦀
RustHound-CE는 Rust로 작성된 크로스 플랫폼 및 크로스 컴파일 BloodHound 수집기 도구로, Linux, Windows, macOS와 호환됩니다. 따라서 BloodHound Community Edition에서 분석할 수 있는 모든 JSON 파일을 생성합니다. 이 버전은 BloodHound Community Edition과만 호환됩니다. BloodHound Legacy와 호환되는 버전은 NeverHack의 github에서 확인할 수 있습니다.
RustHound는 제가 Armature Technologies(이후 Opencyber, 그다음 NeverHack으로 개명)에서 펜테스터로 일하던 시절에 만들어졌습니다. 원래 RustHound 프로젝트를 연구하고 개발할 시간을 주신 NeverHack에 감사드립니다. 원본 프로젝트는 여전히 그들의 github에서 확인할 수 있습니다. 우리는 두 버전 모두에 기여하기 위해 계속 협력하기로 했습니다. 이 버전은 커뮤니티 에디션과 호환되며, NeverHack 버전은 BloodHound의 Legacy 버전과 호환됩니다.
이 프로젝트는 다음과 같이 make 명령으로 직접 컴파일할 수 있습니다:
# Compile it for your current system
make release
# Compile it for Windows
make windows
또는 아래와 같이 docker를 사용할 수 있습니다:
docker build --rm -t rusthound-ce .
# Then
docker run --rm -v $PWD:/usr/src/rusthound-ce rusthound-ce help
docker run --rm -v $PWD:/usr/src/rusthound-ce rusthound-ce release
docker run --rm -v $PWD:/usr/src/rusthound-ce rusthound-ce windows
docker run --rm -v $PWD:/usr/src/rusthound-ce rusthound-ce linux
필수 종속성이 설치되어 있는지 확인하세요.
# Install and/or update RustHound-CE from cargo command
cargo install rusthound-ce
다음은 도메인 객체를 수집하고 BloodHound CE에 가져올 json 파일이 포함된 zip 아카이브를 얻기 위한 명령 예시입니다:
rusthound-ce -d DOMAIN.LOCAL -u [email protected] -z
RustHound-CE를 컴파일하는 방법이나 RustHound-CE를 사용하는 방법에 대한 더 많은 정보와 예시는 도움말 페이지에서 직접 확인할 수 있습니다.