Skip to main content

Crate adhammer_bloodhound

Crate adhammer_bloodhound 

Source
Expand description

BloodHound export — turn a collected Snapshot into BloodHound CE ingest JSON that the BloodHound UI ingests, so the in-process control-path graph becomes explorable in the tool every AD team already uses. Targets the BloodHound Community Edition ingest format: one file per node type (users/computers/groups/domains/ous/gpos/containers), each a {"data":[…],"meta":{…}} document, packaged into a single .zip.

The meta.version field in this crate’s built-in exporter is emitted as 5 (the historical BloodHound-CE ingest schema this crate first targeted). The opt-in [rusthound_ce] adapter (feature rusthound-ce) delegates to RustHound-CE upstream, which currently emits meta.version = 6 and additional ADCS-extension file types (aiacas/enterprisecas/rootcas/certtemplates/issuancepolicies/ntauthstores). Both are accepted by current BloodHound-CE releases.

Node identity: SIDs for security principals, GUIDs for OUs/GPOs/containers. Edges come from group membership (Members) and from ACEs parsed out of nTSecurityDescriptor — the same rights the control-path graph walks, mapped to BloodHound RightNames.

Functions§

export_files
Build the full set of BloodHound JSON files (filename, bytes) for a snapshot.
export_zip
Export a snapshot to a single BloodHound .zip at path.