rusthound_ce/lib.rs
1//! <p align="center">
2//! <picture>
3//! <source media="(prefers-color-scheme: dark)" srcset="https://github.com/g0h4n/RustHound-CE/raw/main/img/rusthoundce-transparent-dark-theme.png">
4//! <source media="(prefers-color-scheme: light)" srcset="https://github.com/g0h4n/RustHound-CE/raw/main/img/rusthoundce-transparent-light-theme.png">
5//! <img src="https://github.com/g0h4n/RustHound-CE/raw/main/img/rusthoundce-transparent-dark-theme.png" alt="rusthound-ce logo" width='250' />
6//! </picture>
7//! </p>
8//! <hr />
9//!
10//! RustHound-CE is a cross-platform and cross-compiled BloodHound collector tool written in Rust, making it compatible with Linux, Windows, and macOS. It therefore generates all the JSON files that can be analyzed by BloodHound Community Edition. This version is only compatible with [BloodHound Community Edition](https://github.com/SpecterOps/BloodHound). The version compatible with [BloodHound Legacy](https://github.com/BloodHoundAD/BloodHound) can be found on [NeverHack's github](https://github.com/NH-RED-TEAM/RustHound).
11//!
12//! RustHound-CE can be use as a library. The pipeline is exposed as two composable
13//! functions, see [INTEGRATION.md](https://github.com/g0h4n/RustHound-CE/blob/main/INTEGRATION.md)
14//! for the full guide.
15//!
16//! Authenticate, then run the whole collection:
17//! ```ignore
18//! use rusthound_ce::{ldap_auth, run_collection, args::{Options, CollectionMethod}};
19//!
20//! # async fn demo() -> Result<(), Box<dyn std::error::Error>> {
21//! let options = Options {
22//! domain: "essos.local".to_string(),
23//! username: Some("daenerys.targaryen@essos.local".to_string()),
24//! password: Some("BurnThemAll!".to_string()),
25//! ldapfqdn: Some("meereen.essos.local".to_string()),
26//! ldaps: true,
27//! path: "/tmp/demo".to_string(),
28//! collection_method: CollectionMethod::All,
29//! zip: true,
30//! ..Default::default()
31//! };
32//!
33//! // 1. authenticate (simple bind, pass-the-hash, Kerberos, or certificate)
34//! let mut ldap = ldap_auth(&options).await?;
35//! // 2. collect -> parse -> modules -> JSON/zip, returns the output path
36//! let out = run_collection(&mut ldap, &options).await?;
37//! println!("Output written to {out}");
38//! # Ok(())
39//! # }
40//! ```
41//!
42//! Or bring your own already-authenticated `ldap3::Ldap` session (for example
43//! one bound with a client certificate) and skip `ldap_auth`:
44//! ```ignore
45//! use rusthound_ce::{run_collection, args::{Options, CollectionMethod}};
46//!
47//! # async fn demo(ldap: &mut ldap3::Ldap, mut options: Options) -> Result<(), Box<dyn std::error::Error>> {
48//! options.collection_method = CollectionMethod::LdapOnly; // no SMB creds over cert auth
49//! let out = run_collection(ldap, &options).await?;
50//! println!("Output written to {out}");
51//! # Ok(())
52//! # }
53//! ```
54//!
55pub mod args;
56pub mod banner;
57pub mod transport;
58pub mod utils;
59pub mod api;
60pub mod modules;
61
62pub mod enums;
63pub mod json;
64pub mod objects;
65pub (crate) mod storage;
66
67
68extern crate bitflags;
69extern crate chrono;
70extern crate regex;
71
72// Reimport key functions and structure
73#[doc(inline)]
74pub use transport::ldap::ldap_auth;
75#[doc(inline)]
76pub use ldap3::SearchEntry;
77
78pub use json::maker::make_result;
79pub use api::{prepare_results_from_source, prepare_results_from_disk};
80pub use storage::{Storage, EntrySource, DiskStorage, DiskStorageReader};