Windows file creation for SharpHound/BloodHound collection output filenames

Flags SharpHound/BloodHound default collection export files (zip and multiple JSON datasets) from Windows file events.

FreeReviewedSigma · High · v1
Product
windows
Category
file_event
Author
C.J. May (SigmaHQ), DRL 1.1
Published
2022-08-09
Updated
2026-07-30

ATT&CK techniques

Execution → Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule identifies Windows file events whose target filenames match default BloodHound/SharpHound collection outputs, including BloodHound.zip and JSON exports for computers, containers, groups, OUs, and users. Attackers commonly collect directory data to enumerate and map Active Directory relationships, and these exported files provide a concrete artifact of that discovery activity. The detection relies on file event telemetry containing process image paths and target filenames.

Related detections9 linkedT1069.002 — drag to rearrange
Windows PowerShell module commandlet names matching known exploitation and post-exploitation tooling
Windows Process Creation: Suspicious PowerShell Commandlets Used by Known Exploitation Tools
Windows Process Execution of Bloodhound/SharpHound Command-Line Collection Options
Windows PowerShell ScriptBlock detects known malicious commandlet names used by exploitation frameworks
Windows Process Creation: Execution of Net.exe or Net1.exe
Suspicious Group Discovery - Command (via process_creation)
Windows File Events: ADExplorer .dat Snapshot Written by ADExp.exe or ADExplorer.exe
Windows: Sysinternals ADExplorer invoked with snapshot flag to create AD database snapshot
Windows Process Creation: Sysinternals ADExplorer Snapshot Exports Active Directory Database
Windows file creation for SharpHound/BloodHound collection output filenames
Pivot detection · T1069.002 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.