rusthound_ce/lib.rs
1//! <p align="center">
2//! <picture>
3//! <source media="(prefers-color-scheme: dark)" srcset="https://github.com/g0h4n/RustHound-CE/raw/main/img/rusthoundce-transparent-dark-theme.png">
4//! <source media="(prefers-color-scheme: light)" srcset="https://github.com/g0h4n/RustHound-CE/raw/main/img/rusthoundce-transparent-light-theme.png">
5//! <img src="https://github.com/g0h4n/RustHound-CE/raw/main/img/rusthoundce-transparent-dark-theme.png" alt="rusthound-ce logo" width='250' />
6//! </picture>
7//! </p>
8//! <hr />
9//!
10//! RustHound-CE is a cross-platform and cross-compiled BloodHound collector tool written in Rust, making it compatible with Linux, Windows, and macOS. It therefore generates all the JSON files that can be analyzed by BloodHound Community Edition. This version is only compatible with [BloodHound Community Edition](https://github.com/SpecterOps/BloodHound). The version compatible with [BloodHound Legacy](https://github.com/BloodHoundAD/BloodHound) can be found on [NeverHack's github](https://github.com/NH-RED-TEAM/RustHound).
11//!
12//!
13//! You can either run the binary:
14//! ```ignore
15//! ---------------------------------------------------
16//! Initializing RustHound-CE at 13:37:00 UTC on 01/12/23
17//! Powered by @g0h4n_0
18//! ---------------------------------------------------
19//!
20//! Active Directory data collector for BloodHound Community Edition.
21//! g0h4n <https://twitter.com/g0h4n_0>
22//!
23//! Usage: rusthound-ce [OPTIONS] --domain <domain>
24//!
25//! Options:
26//! -v... Set the level of verbosity
27//! -h, --help Print help
28//! -V, --version Print version
29//!
30//! REQUIRED VALUES:
31//! -d, --domain <domain> Domain name like: DOMAIN.LOCAL
32//!
33//! OPTIONAL VALUES:
34//! -u, --ldapusername <ldapusername> LDAP username, like: user@domain.local
35//! -p, --ldappassword <ldappassword> LDAP password
36//! -H, --hashes <hashes> NT hash for pass-the-hash authentication (NTLM), accept [NTHASH, :NTHASH, LMHASH:NTHASH]
37//! -f, --ldapfqdn <ldapfqdn> Domain Controller FQDN like: DC01.DOMAIN.LOCAL or just DC01
38//! -i, --ldapip <ldapip> Domain Controller IP address like: 192.168.1.10
39//! -P, --ldapport <ldapport> LDAP port [default: 389]
40//! -n, --name-server <name-server> Alternative IP address name server to use for DNS queries
41//! -o, --output <output> Output directory where you would like to save JSON files [default: ./]
42//!
43//! OPTIONAL FLAGS:
44//! -c, --collectionmethod [<COLLECTIONMETHOD>]
45//! Which information to collect. Supported: All (LDAP,SMB,HTTP requests), DCOnly (no computer connections, only LDAP requests). (default: All) [possible values: All, DCOnly]
46//! --ldap-filter <ldap-filter>
47//! Use custom ldap-filter default is : (objectClass=*)
48//! --ldaps
49//! Force LDAPS using for request like: ldaps://DOMAIN.LOCAL/
50//! -k, --kerberos
51//! Use Kerberos authentication. Grabs credentials from ccache file (KRB5CCNAME) based on target parameters for Linux.
52//! --dns-tcp
53//! Use TCP instead of UDP for DNS queries
54//! -z, --zip
55//! Compress the JSON files into a zip archive
56//! --cache
57//! Cache LDAP search results to disk (reduce memory usage on large domains)
58//! --cache-buffer <cache_buffer>
59//! Buffer size to use when caching [default: 1000]
60//! --resume
61//! Resume the collection from the last saved state
62//!
63//! OPTIONAL MODULES:
64//! --fqdn-resolver Use fqdn-resolver module to get computers IP address
65//! ```
66//!
67//! Or build your own using the ldap_search() function:
68//! ```ignore
69//! # use rusthound::ldap::ldap_search;
70//! # let ldaps = true;
71//! # let ip = Some("127.0.0.1");
72//! # let port = Some(676);
73//! # let domain = "DOMAIN.COM";
74//! # let ldapfqdn = "ad1.domain.com";
75//! # let username = Some("user");
76//! # let password = Some("pwd");
77//! # let kerberos= false;
78//! let result = ldap_search(
79//! &ldaps,
80//! &Some(ip),
81//! &Some(port),
82//! &domain,
83//! &ldapfqdn,
84//! &username,
85//! &password,
86//! kerberos,
87//! );
88//! ```
89//!
90pub mod args;
91pub mod banner;
92pub mod transport;
93pub mod utils;
94pub mod api;
95pub mod modules;
96
97pub mod enums;
98pub mod json;
99pub mod objects;
100pub (crate) mod storage;
101
102
103extern crate bitflags;
104extern crate chrono;
105extern crate regex;
106
107// Reimport key functions and structure
108#[doc(inline)]
109pub use transport::ldap::ldap_search;
110#[doc(inline)]
111pub use ldap3::SearchEntry;
112
113pub use json::maker::make_result;
114pub use api::{prepare_results_from_source, prepare_results_from_disk};
115pub use storage::{Storage, EntrySource, DiskStorage, DiskStorageReader};