BloodHound / SharpHound AD Reconnaissance Response
Triggered when BloodHound/SharpHound collection behavior, heavy LDAP/SMB enumeration, or access to a honey object is detected in the environment; aims to identify the source account and host and close exposed AD attack paths; no evidence of credential theft or lateral movement.
Prepare
5 steps- Telemetry validation
Periodically verify that Sysmon (EID 1/3/10/18), account auditing (EID 4624/4625/4662/4768/4769), LDAP query logging (EID 1644, `Field Engineering` registry value `5`), and named pipe auditing (EID 5145, Detailed File Share enabled) are being collected on DCs and critical member servers
- Honey objects
Deploy honey service accounts with attractive SPNs and low `logonCount` values, along with honey AD objects; define SIEM rules so that every access to these objects generates a high-confidence alert
- SAM/session enumeration hardening
Verify that NetCease/SAMRi10 or the "Network access: Restrict clients allowed to make remote calls to SAM" GPO is applied in the environment and that compatibility testing is complete; these measures may break some management tools and monitoring scripts — notify affected teams in advance
- ACL and delegation inventory
Confirm that `GenericAll`/`WriteDacl`/`WriteOwner` and write rights on OUs are periodically inventoried via defensive BloodHound audits, and that objects with unconstrained delegation are listed
- Escalation chain
Document the SOC L1 → SOC L2/IR analyst → AD administrator (tier-0) → IR lead → CISO chain; isolation and account disablement decisions cannot be made by L1 alone