Expand description
RustHound-CE is a cross-platform and cross-compiled BloodHound collector tool written in Rust, making it compatible with Linux, Windows, and macOS. It therefore generates all the JSON files that can be analyzed by BloodHound Community Edition. This version is only compatible with BloodHound Community Edition. The version compatible with BloodHound Legacy can be found on NeverHack’s github.
RustHound-CE can be use as a library. The pipeline is exposed as two composable functions, see INTEGRATION.md for the full guide.
Authenticate, then run the whole collection:
ⓘ
use rusthound_ce::{ldap_auth, run_collection, args::{Options, CollectionMethod}};
let options = Options {
domain: "essos.local".to_string(),
username: Some("daenerys.targaryen@essos.local".to_string()),
password: Some("BurnThemAll!".to_string()),
ldapfqdn: Some("meereen.essos.local".to_string()),
ldaps: true,
path: "/tmp/demo".to_string(),
collection_method: CollectionMethod::All,
zip: true,
..Default::default()
};
// 1. authenticate (simple bind, pass-the-hash, Kerberos, or certificate)
let mut ldap = ldap_auth(&options).await?;
// 2. collect -> parse -> modules -> JSON/zip, returns the output path
let out = run_collection(&mut ldap, &options).await?;
println!("Output written to {out}");Or bring your own already-authenticated ldap3::Ldap session (for example
one bound with a client certificate) and skip ldap_auth:
ⓘ
use rusthound_ce::{run_collection, args::{Options, CollectionMethod}};
options.collection_method = CollectionMethod::LdapOnly; // no SMB creds over cert auth
let out = run_collection(ldap, &options).await?;
println!("Output written to {out}");Re-exports§
pub use json::maker::make_result;pub use api::prepare_results_from_source;pub use api::prepare_results_from_disk;
Modules§
- api
- args
- Parsing arguments
- banner
- Launch and end banners
- enums
- Utils to extract data from ldap network packets
- json
- Utils to parse json output from ldap library
- modules
- List of RustHound add-on modules
- objects
- All structure needed by RustHound-CE.
- transport
- Network transports used by RustHound-CE to talk to Active Directory.
- utils
- All utils functions like timestamp, crypto etc
Structs§
- Search
Entry - Parsed search result entry.
Traits§
- Entry
Source - Used to iterate over LDAP search entries.
- Storage
Functions§
- ldap_
auth - Connect to the DC and authenticate, returning a ready
ldap3::Ldapsession. The method is picked fromoptions: certificate (pfxorcrt/key), NTLM pass-the-hash (hashes), Kerberos (kerberos), else simple bind. Certificate auth defaults to StartTLS on 389, or LDAPS 636 with--ldaps. The caller owns the session (never unbound here).