Hunting for LDAP Enumerations (Bloodhound_Sharphound)

Hunting for LDAP Enumeration via BloodHoundBloodHound is a powerful tool used by attackers to visualize and plan attacks on Active Directory environments. Its ability to enumerate LDAP and generate a comprehensive domain map makes it a critical threat to monitor. Here’s how to detect and mitigate its use, focusing on the use of SharpHound for data collection.
Attack Workflow
Detection Techniques
Event Analysis
Example Event Details:
Query Example for SIEM
Mitigation Steps
Key Points
Last updated