此版本仅与 BloodHound Legacy 4.x 兼容
与 BloodHound Community Edition (CE) 兼容的版本可在此处找到 RustHound-CE。
并非所有 SharpHound 的功能都已实现。RustHound 中存在一些 SharpHound 或 BloodHound-Python 中没有的功能。请参考路线图了解更多信息。
RustHound 是一个跨平台的 BloodHound 收集工具,使用 Rust 编写,兼容 Linux、Windows 和 macOS。
无 AV 检测且交叉编译。
RustHound 生成用户、组、计算机、OU、GPO、容器和域 JSON 文件,可使用 BloodHound 进行分析。
💡 如果你能使用 SharpHound,请使用它。 如果 SharpHound 被 AV 检测到或不兼容你的操作系统,请将 RustHound 作为备用解决方案。
你可以使用 make 命令安装 RustHound 或为 Linux 或 Windows 编译它。
make install
rusthound -h
Makefile 中的更多命令:
Default:
usage: make install
usage: make uninstall
usage: make debug
usage: make release
Static:
usage: make windows
usage: make windows_x64
usage: make windows_x86
usage: make linux_aarch64
usage: make linux_x86_64
usage: make linux_musl
usage: make macos
usage: make arm_musl
usage: make armv7
Without cli argument:
usage: make windows_noargs
Dependencies:
usage: make install_windows_deps
usage: make install_linux_musl_deps
usage: make install_macos_deps
使用 Docker 运行 RustHound 以确保拥有所有依赖项。
docker build --rm -t rusthound .
# 然后
docker run --rm -v ./:/usr/src/rusthound rusthound windows
docker run --rm -v ./:/usr/src/rusthound rusthound linux_musl
docker run --rm -v ./:/usr/src/rusthound rusthound macos
你需要在系统上安装 Rust。
https://www.rust-lang.org/fr/tools/install
RustHound 支持 Kerberos 和 GSSAPI。因此,它需要 Clang 及其开发库,以及 Kerberos 开发库。在 Debian 和 Ubuntu 上,这意味着需要 clang-N、libclang-N-dev 和 libkrb5-dev。
例如:
# Debian/Ubuntu
sudo apt-get -y update && sudo apt-get -y install gcc clang libclang-dev libgssapi-krb5-2 libkrb5-dev libsasl2-modules-gssapi-mit musl-tools gcc-mingw-w64-x86-64
以下是如何使用 cargo 命令编译 "release" 和 "debug" 版本。
git clone https://github.com/OPENCYBER-FR/RustHound
cd RustHound
cargo build --release
# 或 debug 版本
cargo b
结果可以在 target/release 或 target/debug 文件夹中找到。
以下是从 Linux 编译每个操作系统的方法。 如果你需要另一种编译系统,请查阅此链接中的列表:https://doc.rust-lang.org/nightly/rustc/platform-support.html
# 为 Linux 安装 rustup 和 Cargo
curl https://sh.rustup.rs -sSf | sh
# 添加 Linux 依赖
rustup install stable-x86_64-unknown-linux-gnu
rustup target add x86_64-unknown-linux-gnu
# 为 Linux 静态编译
git clone https://github.com/OPENCYBER-FR/RustHound
cd RustHound
CFLAGS="-lrt";LDFLAGS="-lrt";RUSTFLAGS='-C target-feature=+crt-static';cargo build --release --target x86_64-unknown-linux-gnu
结果可以在 target/x86_64-unknown-linux-gnu/release 文件夹中找到。
# 在 Linux 上安装 rustup 和 Cargo
curl https://sh.rustup.rs -sSf | sh
# 添加 Windows 依赖
rustup install stable-x86_64-pc-windows-gnu
rustup target add x86_64-pc-windows-gnu
# 为 Windows 静态编译
git clone https://github.com/OPENCYBER-FR/RustHound
cd RustHound
RUSTFLAGS="-C target-feature=+crt-static" cargo build --release --target x86_64-pc-windows-gnu
结果可以在 target/x86_64-pc-windows-gnu/release 文件夹中找到。
出色的文档:https://wapl.es/rust/2019/02/17/rust-cross-compile-linux-to-macos.html
# 在 Linux 上安装 rustup 和 Cargo
curl https://sh.rustup.rs -sSf | sh
# 添加 macOS 工具链
sudo git clone https://github.com/tpoechtrager/osxcross /usr/local/bin/osxcross
sudo wget -P /usr/local/bin/osxcross/ -nc https://s3.dockerproject.org/darwin/v2/MacOSX10.10.sdk.tar.xz && sudo mv /usr/local/bin/osxcross/MacOSX10.10.sdk.tar.xz /usr/local/bin/osxcross/tarballs/
sudo UNATTENDED=yes OSX_VERSION_MIN=10.7 /usr/local/bin/osxcross/build.sh
sudo chmod 775 /usr/local/bin/osxcross/ -R
export PATH="/usr/local/bin/osxcross/target/bin:$PATH"
# 需要告诉 Cargo 为 x86_64-apple-darwin 目标使用正确的链接器,因此将以下内容添加到项目的 .cargo/config 文件中:
grep 'target.x86_64-apple-darwin' ~/.cargo/config || echo "[target.x86_64-apple-darwin]" >> ~/.cargo/config
grep 'linker = "x86_64-apple-darwin14-clang"' ~/.cargo/config || echo 'linker = "x86_64-apple-darwin14-clang"' >> ~/.cargo/config
grep 'ar = "x86_64-apple-darwin14-clang"' ~/.cargo/config || echo 'ar = "x86_64-apple-darwin14-clang"' >> ~/.cargo/config
# 为 macOS 静态编译
git clone https://github.com/OPENCYBER-FR/RustHound
cd RustHound
RUSTFLAGS="-C target-feature=+crt-static" cargo build --release --target x86_64-apple-darwin --features nogssapi
结果可以在 target/x86_64-apple-darwin/release 文件夹中找到。
💡 要获得 RustHound 的优化编译,请在
Cargo.toml文件末尾添加以下编译参数。
[profile.release]
opt-level = "z"
lto = true
strip = true
codegen-units = 1
panic = "abort"
二进制文件的大小将大幅减小。 可以使用基本的 cargo 编译器命令。
make windows
更多信息请点击此处
git clone https://github.com/OPENCYBER-FR/RustHound
cd RustHound
cargo doc --open --no-deps
Usage: rusthound [OPTIONS] --domain <domain>
Options:
-v... Set the level of verbosity
-h, --help Print help information
-V, --version Print version information
REQUIRED VALUES:
-d, --domain <domain> Domain name like: DOMAIN.LOCAL
OPTIONAL VALUES:
-u, --ldapusername <ldapusername> LDAP username, like: [email protected]
-p, --ldappassword <ldappassword> LDAP password
-f, --ldapfqdn <ldapfqdn> Domain Controler FQDN like: DC01.DOMAIN.LOCAL or just DC01
-i, --ldapip <ldapip> Domain Controller IP address like: 192.168.1.10
-P, --ldapport <ldapport> LDAP port [default: 389]
-n, --name-server <name-server> Alternative IP address name server to use for DNS queries
-o, --output <output> Output directory where you would like to save JSON files [default: ./]