Expand description
Session-collection module for RustHound-CE (issue #46 - HasSession) https://bloodhound.specterops.io/resources/edges/has-session#hassession https://github.com/g0h4n/HasSession-rs
Runs AFTER the LDAP phase, from modules::run_modules, and only when the
collection method actually contacts machines (i.e. NOT DCOnly).
Three native RPC paths (all provided by the dcerpc crate), mapped to the
BloodHound CE computer schema:
SRVSVC / NetrSessionEnum -> Computer.Sessions (HasSession) WKSSVC / NetrWkstaUserEnum -> Computer.PrivilegedSessions (LoggedOn) WINREG / HKEY_USERS -> Computer.RegistrySessions (LoggedOn)
SharpHound-style behaviour baked in:
- reachability pre-check on 445 with a hard timeout (skip dead hosts);
- “active computer” filter based on pwdLastSet age (ComputerExpiryDays);
- DCOnly never reaches this module;
- bounded concurrency (throttle) instead of a serial loop;
- names resolved to SIDs using the already-collected LDAP data.
Authentication reuses the SMB transport: password, pass the hash, or a
Kerberos ticket (pass the ticket) when –kerberos is set. Kerberos material
is built per host, since the AP-REQ targets that host’s cifs/
The target host is the computer FQDN (properties.name, from dNSHostName). We do NOT use the fqdn->ip map: connections go to the FQDN and rely on DNS.