Windows Process Execution of Bloodhound/SharpHound Command-Line Collection Options

Alerts on SharpHound/Bloodhound-like processes launching with discovery-focused command-line parameters.

FreeReviewedSigma · High · v2
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2019-12-20
Updated
2026-07-31

ATT&CK techniques

Execution → Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags Windows process creation events where the executable and metadata indicate BloodHound/SharpHound, and the command line contains common collection and collection-method parameters. Attackers rely on Bloodhound/SharpHound-style discovery tooling to enumerate Active Directory relationships and configuration for subsequent targeting. The detection depends on process creation telemetry capturing Image/metadata fields and full CommandLine content.

Related detections9 linkedT1069.002 — drag to rearrange
Windows PowerShell module commandlet names matching known exploitation and post-exploitation tooling
Windows Process Creation: Suspicious PowerShell Commandlets Used by Known Exploitation Tools
Windows file creation for SharpHound/BloodHound collection output filenames
Windows PowerShell ScriptBlock detects known malicious commandlet names used by exploitation frameworks
Windows Process Creation: Execution of Net.exe or Net1.exe
Suspicious Group Discovery - Command (via process_creation)
Windows File Events: ADExplorer .dat Snapshot Written by ADExp.exe or ADExplorer.exe
Windows: Sysinternals ADExplorer invoked with snapshot flag to create AD database snapshot
Windows Process Creation: Sysinternals ADExplorer Snapshot Exports Active Directory Database
Windows Process Execution of Bloodhound/SharpHound Command-Line Collection Options
Pivot detection · T1069.002 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.