rusthound_ce/lib.rs
1//! <p align="center">
2//! <picture>
3//! <source media="(prefers-color-scheme: dark)" srcset="https://github.com/g0h4n/RustHound-CE/raw/main/img/rusthoundce-transparent-dark-theme.png">
4//! <source media="(prefers-color-scheme: light)" srcset="https://github.com/g0h4n/RustHound-CE/raw/main/img/rusthoundce-transparent-light-theme.png">
5//! <img src="https://github.com/g0h4n/RustHound-CE/raw/main/img/rusthoundce-transparent-dark-theme.png" alt="rusthound-ce logo" width='250' />
6//! </picture>
7//! </p>
8//! <hr />
9//!
10//! RustHound-CE is a cross-platform and cross-compiled BloodHound collector tool written in Rust, making it compatible with Linux, Windows, and macOS. It therefore generates all the JSON files that can be analyzed by BloodHound Community Edition. This version is only compatible with [BloodHound Community Edition](https://github.com/SpecterOps/BloodHound). The version compatible with [BloodHound Legacy](https://github.com/BloodHoundAD/BloodHound) can be found on [NeverHack's github](https://github.com/NH-RED-TEAM/RustHound).
11//!
12//!
13//! You can either run the binary:
14//! ```ignore
15//! ---------------------------------------------------
16//! Initializing RustHound-CE at 13:37:00 UTC on 01/12/23
17//! Powered by @g0h4n_0
18//! ---------------------------------------------------
19//!
20//! Active Directory data collector for BloodHound Community Edition.
21//! g0h4n <https://twitter.com/g0h4n_0>
22//!
23//! Usage: rusthound-ce [OPTIONS] --domain <domain>
24//!
25//! Options:
26//! -v... Set the level of verbosity
27//! -h, --help Print help
28//! -V, --version Print version
29//!
30//! REQUIRED VALUES:
31//! -d, --domain <domain> Domain name like: DOMAIN.LOCAL
32//!
33//! OPTIONAL VALUES:
34//! -u, --ldapusername <ldapusername> LDAP username, like: user@domain.local
35//! -p, --ldappassword <ldappassword> LDAP password
36//! -H, --hashes <hashes> NT hash for pass-the-hash authentication (NTLM), accept [NTHASH, :NTHASH, LMHASH:NTHASH]
37//! -f, --ldapfqdn <ldapfqdn> Domain Controller FQDN like: DC01.DOMAIN.LOCAL or just DC01
38//! -i, --ldapip <ldapip> Domain Controller IP address like: 192.168.1.10
39//! -P, --ldapport <ldapport> LDAP port [default: 389, or 636 with --ldaps]
40//! -n, --name-server <name-server> Alternative IP address name server to use for DNS queries
41//! -o, --output <output> Output directory where you would like to save JSON files [default: ./]
42//!
43//! CERTIFICATE AUTHENTICATION:
44//! --pfx <pfx> PFX/PKCS#12 client certificate for certificate authentication (Pass-the-Certificate). Uses StartTLS by default, or LDAPS with --ldaps
45//! --pfx-pass <pfx-pass> Password protecting the PFX file (optional)
46//! --crt <crt> PEM client certificate for certificate authentication (use with --key)
47//! --key <key> PEM private key for certificate authentication (use with --crt)
48//!
49//! OPTIONAL FLAGS:
50//! -c, --collectionmethod [<COLLECTIONMETHOD>]
51//! Which information to collect. Supported: All (LDAP, SMB, HTTP), DCOnly (LDAP + SYSVOL, no member-machine connections), Session (user sessions over RPC), RegistryOnly (sessions over WINREG), LdapOnly (LDAP only, no machine or SYSVOL) (default: All) [possible values: All, DCOnly, Session, RegistryOnly, LdapOnly]
52//! --ldap-filter <ldap-filter>
53//! Use custom ldap-filter default is : (objectClass=*)
54//! --ldaps
55//! Force LDAPS using for request like: ldaps://DOMAIN.LOCAL/
56//! -k, --kerberos
57//! Use Kerberos authentication. Grabs credentials from ccache file (KRB5CCNAME) based on target parameters for Linux.
58//! --dns-tcp
59//! Use TCP instead of UDP for DNS queries
60//! -z, --zip
61//! Compress the JSON files into a zip archive
62//! --cache
63//! Cache LDAP search results to disk (reduce memory usage on large domains)
64//! --cache-buffer <cache_buffer>
65//! Buffer size to use when caching [default: 1000]
66//! --resume
67//! Resume the collection from the last saved state
68//!
69//! OPTIONAL MODULES:
70//! --fqdn-resolver Use fqdn-resolver module to get computers IP address
71//! ```
72//!
73//! Or build your own using the ldap_search() function:
74//! ```ignore
75//! # use rusthound::ldap::ldap_search;
76//! # let ldaps = true;
77//! # let ip = Some("127.0.0.1");
78//! # let port = Some(676);
79//! # let domain = "DOMAIN.COM";
80//! # let ldapfqdn = "ad1.domain.com";
81//! # let username = Some("user");
82//! # let password = Some("pwd");
83//! # let kerberos= false;
84//! let result = ldap_search(
85//! &ldaps,
86//! &Some(ip),
87//! &Some(port),
88//! &domain,
89//! &ldapfqdn,
90//! &username,
91//! &password,
92//! kerberos,
93//! );
94//! ```
95//!
96pub mod args;
97pub mod banner;
98pub mod transport;
99pub mod utils;
100pub mod api;
101pub mod modules;
102
103pub mod enums;
104pub mod json;
105pub mod objects;
106pub (crate) mod storage;
107
108
109extern crate bitflags;
110extern crate chrono;
111extern crate regex;
112
113// Reimport key functions and structure
114#[doc(inline)]
115pub use transport::ldap::ldap_auth;
116#[doc(inline)]
117pub use ldap3::SearchEntry;
118
119pub use json::maker::make_result;
120pub use api::{prepare_results_from_source, prepare_results_from_disk};
121pub use storage::{Storage, EntrySource, DiskStorage, DiskStorageReader};