Skip to main content

Module sessions

Module sessions 

Source
Expand description

Session-collection module for RustHound-CE (issue #46 - HasSession) https://bloodhound.specterops.io/resources/edges/has-session#hassession https://github.com/g0h4n/HasSession-rs

Runs AFTER the LDAP phase, from modules::run_modules, and only when the collection method actually contacts machines (i.e. NOT DCOnly).

Three native RPC paths (all provided by the dcerpc crate), mapped to the BloodHound CE computer schema:

SRVSVC / NetrSessionEnum -> Computer.Sessions (HasSession) WKSSVC / NetrWkstaUserEnum -> Computer.PrivilegedSessions (LoggedOn) WINREG / HKEY_USERS -> Computer.RegistrySessions (LoggedOn)

SharpHound-style behaviour baked in:

  • reachability pre-check on 445 with a hard timeout (skip dead hosts);
  • “active computer” filter based on pwdLastSet age (ComputerExpiryDays);
  • DCOnly never reaches this module;
  • bounded concurrency (throttle) instead of a serial loop;
  • names resolved to SIDs using the already-collected LDAP data.

Authentication reuses the SMB transport: password, pass the hash, or a Kerberos ticket (pass the ticket) when –kerberos is set. Kerberos material is built per host, since the AP-REQ targets that host’s cifs/ SPN.

The target host is the computer FQDN (properties.name, from dNSHostName). We do NOT use the fqdn->ip map: connections go to the FQDN and rely on DNS.

Functions§

run