Skip to main content

Crate rusthound_ce

Crate rusthound_ce 

Source
Expand description

rusthound-ce logo


RustHound-CE is a cross-platform and cross-compiled BloodHound collector tool written in Rust, making it compatible with Linux, Windows, and macOS. It therefore generates all the JSON files that can be analyzed by BloodHound Community Edition. This version is only compatible with BloodHound Community Edition. The version compatible with BloodHound Legacy can be found on NeverHack’s github.

RustHound-CE can be use as a library. The pipeline is exposed as two composable functions, see INTEGRATION.md for the full guide.

Authenticate, then run the whole collection:

ⓘ
use rusthound_ce::{ldap_auth, run_collection, args::{Options, CollectionMethod}};

let options = Options {
    domain: "essos.local".to_string(),
    username: Some("daenerys.targaryen@essos.local".to_string()),
    password: Some("BurnThemAll!".to_string()),
    ldapfqdn: Some("meereen.essos.local".to_string()),
    ldaps: true,
    path: "/tmp/demo".to_string(),
    collection_method: CollectionMethod::All,
    zip: true,
    ..Default::default()
};

// 1. authenticate (simple bind, pass-the-hash, Kerberos, or certificate)
let mut ldap = ldap_auth(&options).await?;
// 2. collect -> parse -> modules -> JSON/zip, returns the output path
let out = run_collection(&mut ldap, &options).await?;
println!("Output written to {out}");

Or bring your own already-authenticated ldap3::Ldap session (for example one bound with a client certificate) and skip ldap_auth:

ⓘ
use rusthound_ce::{run_collection, args::{Options, CollectionMethod}};

options.collection_method = CollectionMethod::LdapOnly; // no SMB creds over cert auth
let out = run_collection(ldap, &options).await?;
println!("Output written to {out}");

Re-exports§

pub use json::maker::make_result;
pub use api::prepare_results_from_source;
pub use api::prepare_results_from_disk;

Modules§

api
args
Parsing arguments
banner
Launch and end banners
enums
Utils to extract data from ldap network packets
json
Utils to parse json output from ldap library
modules
List of RustHound add-on modules
objects
All structure needed by RustHound-CE.
transport
Network transports used by RustHound-CE to talk to Active Directory.
utils
All utils functions like timestamp, crypto etc

Structs§

SearchEntry
Parsed search result entry.

Traits§

EntrySource
Used to iterate over LDAP search entries.
Storage

Functions§

ldap_auth
Connect to the DC and authenticate, returning a ready ldap3::Ldap session. The method is picked from options: certificate (pfx or crt/key), NTLM pass-the-hash (hashes), Kerberos (kerberos), else simple bind. Certificate auth defaults to StartTLS on 389, or LDAPS 636 with --ldaps. The caller owns the session (never unbound here).

Type Aliases§

DiskStorage
DiskStorageReader