In the 2021 Colonial Pipeline breach, attackers moved laterally through Active Directory for days before triggering ransomware. The path existed. No one had mapped it. BloodHound maps it — before attackers do. This guide shows you exactly how to use it, with real output and defender context at every step.
Collecting AD Data with SharpHound
BloodHound is a graph-based AD analysis tool. It visualizes relationships between users, groups, computers, and GPOs to expose privilege escalation paths that would take hours to find manually. SharpHound is its data collector — a .NET binary you run on a domain-joined machine.
From a foothold on CORP-WKS-014 (192.0.2.44), authenticated as domain user j.porter, run the collector:
SharpHound.exe -c All --zipfilename corp_ad_data --outputdirectory C:\Temp\
[+] Resolved Collection Methods: Group, LocalAdmin, GPOLocalGroup, Session,
LoggedOn, Trusts, ACL, Container, RDP, ObjectProps, DCOM, SPNTargets
[+] Initializing SharpHound at 09:14:32 on 10/03/2026
[+] Flags: Group, LocalAdmin, Session, LoggedOn, ACL, ObjectProps, Trusts
[+] Connecting to LDAP at corp-dc01.corp.internal:389
[+] Found 1,847 users, 412 groups, 203 computers
[+] Enumeration finished in 00:02:17
[+] Compressing data to C:\Temp\corp_ad_data.zip
That ZIP is your intelligence package. It contains JSON files mapping every relationship BloodHound needs: group memberships, session data, ACL edges, local admin rights. Upload it to the BloodHound CE interface at http://localhost:7474 and the graph populates instantly.
From a defender standpoint, SharpHound traffic is detectable. It fires a high volume of LDAP queries in a short window. Enable LDAP query logging on your domain controllers and alert on any single account issuing more than 500 LDAP searches in under five minutes.
Finding the Attack Path: From Helpdesk to Domain Admin
Once data is loaded, run the built-in query “Shortest Paths to Domain Admins.” Here is what the Neo4j Cypher query looks like under the hood — useful if you are querying the database directly:
MATCH p=shortestPath(
(u:User {name:"J.PORTER@CORP.INTERNAL"})-[*1..]->
(g:Group {name:"DOMAIN ADMINS@CORP.INTERNAL"})
)
RETURN p
-- Path returned:
J.PORTER@CORP.INTERNAL
--[MemberOf]-->
HELPDESK@CORP.INTERNAL
--[GenericWrite]-->
SVC_BACKUP@CORP.INTERNAL
--[MemberOf]-->
SERVER OPERATORS@CORP.INTERNAL
--[GenericAll]-->
CORP-DC01.CORP.INTERNAL
--[DCSync Equivalent via AdminSDHolder]-->
Read that path left to right. j.porter is in the Helpdesk group. Helpdesk has GenericWrite over the svc_backup service account — meaning anyone in Helpdesk can modify that account’s attributes, including adding an SPN and kerberoasting it, or resetting its password outright. svc_backup sits in Server Operators, which has GenericAll over CORP-DC01. Game over.
An attacker executes this in three moves: reset svc_backup‘s password, authenticate as that account, then abuse Server Operators rights to dump credentials from the DC. A pentester documents every edge. A defender needs to kill at least one link in that chain to break the path entirely.
The highest-value fix here is the GenericWrite edge. Helpdesk should never have write permissions on a service account that holds privileged group membership. Run the BloodHound query for “Shortest Paths from Owned Principals” after marking your regular user accounts as owned — it will surface every path like this one across the entire domain.
Hardening: Breaking Attack Paths Before Attackers Walk Them
BloodHound is not just a red team tool. Pull the “All Shortest Paths to Domain Admins” query and export the edges. Sort by edge type. Focus on these four first because they are consistently exploitable and often misconfigured:
- GenericWrite / GenericAll — full object control, often set accidentally via delegation
- WriteDACL — lets an attacker grant themselves any permission on the object
- ForceChangePassword — password reset without knowing current credentials
- Owns — object owner has implicit WriteDACL and WriteOwner
For each dangerous ACL edge, use PowerShell to confirm and remediate:
# Confirm ACL on svc_backup
Get-ADUser svc_backup | Get-ACL | Format-List
# Remove GenericWrite from HELPDESK group
$acl = Get-Acl "AD:CN=svc_backup,OU=ServiceAccounts,DC=corp,DC=internal"
$rule = $acl.Access | Where-Object {
$_.IdentityReference -like "*HELPDESK*" -and
$_.ActiveDirectoryRights -match "GenericWrite"
}
$acl.RemoveAccessRule($rule)
Set-Acl -AclObject $acl "AD:CN=svc_backup,OU=ServiceAccounts,DC=corp,DC=internal"
# Output
Success: ACE removed for CORP\HELPDESK on CN=svc_backup
After making changes, re-run SharpHound and reload the data. Confirm the edge is gone in the graph. This is the feedback loop defenders need — collect, analyze, fix, verify.
Also enable Protected Users security group membership for all privileged accounts and tier your admin accounts. BloodHound will show far fewer viable paths against a properly tiered AD environment.
What To Do Now
Download BloodHound Community Edition from the official GitHub repo, run SharpHound against your own domain today with a standard user account, and query “Shortest Paths to Domain Admins.” If you see a path shorter than five hops, you have a critical finding to remediate before the end of the week. The path is already there — the only question is who finds it first.
