T1087.002DiscoveryIntermediate
A comprehensive map of Active Directory reconnaissance with BloodHound/SharpHound: collection methods (Default, All, DCOnly, Session, LoggedOn, ACL, Trusts, Container), node/edge types and Cypher attack path queries, OpSec/noise assessment, LDAP 1644 + 5145-based detection, session enumeration hardening, and ACL hygiene. A technical reference for SOC/DFIR and red/purple teams.
13 min read
Exploit
Prevention
Detection