Skip to content

Latest commit

 

History

26 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 

Repository files navigation

BloodHoundAnalyzer

Overview

BloodHoundAnalyzer is a bash script designed to automate the deployment, data import, and analysis of BloodHound CE (Community Edition), an Active Directory (AD) security tool. This script facilitates the setup and management of BloodHound CE containers, import of data, and running various analysis tools on the collected data.

Features

  • Data Collection: Includes bloodhound-ce-python for AD data collection
  • Multi-Domain Support: Deploy separate BloodHound CE instances for different domains
  • Automated Container Management: Start, stop, and clean BloodHound CE containers with custom naming
  • Custom Port Configuration: Configure custom ports for Neo4j and BloodHound web interface
  • Automatic Password Management: Automatically reset admin password to a standard password
  • Multiple Data Import Formats: Import .zip files, .json files, or folders containing JSON files
  • Integrated Analysis Tools: Run AD-miner, GoodHound, Ransomulator, PlumHound, ad-recon, and BloodHound QuickWin
  • Project Listing: View all deployed BloodHound projects and their status

Prerequisites

Before using BloodHoundAnalyzer, ensure you have the following installed:

  • Python 3 with venv support
  • Linux environment (tested on Ubuntu/Debian) or WSL2 on Windows

Run the install.sh script to install the required tools:

  • bloodhound-ce-python: Python-based AD data collector for BloodHound CE
  • bloodhound-cli: BloodHound CE command-line interface
  • AD-miner: Generates comprehensive AD security reports
  • GoodHound: Identifies high-value attack paths
  • Ransomulator: Simulates ransomware attack paths
  • BloodHound QuickWin: Quick analysis script
  • PlumHound: Task-based analysis tool
  • ad-recon: AD pathing and transitive rights analysis
# Install BloodHoundAnalyzer
git clone https://github.com/lefayjey/BloodHoundAnalyzer
cd BloodHoundAnalyzer
chmod +x ./install.sh
./install.sh

Usage

Run the script with one or more modules as detailed below:

chmod +x ./BloodHoundAnalyzer.sh
./BloodHoundAnalyzer.sh [OPTIONS]

Options

  • -d, --domain DOMAIN
    Specify the AD domain to analyze (required for most operations).
    Containers will be named: <domain>-graph-db-1, <domain>-app-db-1, <domain>-bloodhound-1

  • -o, --output OUTPUT_DIR
    Specify the directory where analysis results will be saved.
    Default: /opt/BA_output

  • -D, --data DATA_PATH
    Specify the path to BloodHound data:

    • .zip file (SharpHound collection)
    • .json file (single collection file)
    • Folder containing .json files
  • -M, --modules MODULES
    Comma-separated modules to execute:

    • list: List all deployed BloodHound projects and their status
    • start: Start BloodHound CE containers for the specified domain
    • import: Import BloodHound data (automatically starts containers if needed)
    • analyze: Run analysis tools (AD-miner, GoodHound, Ransomulator, BloodHound QuickWin)
    • stop: Stop BloodHound CE containers (preserves data volumes)
    • clean: Remove BloodHound CE containers, volumes, and project data
  • --bolt-port PORT
    Specify Neo4j Bolt port (default: 7687)

  • --neo4j-port PORT
    Specify Neo4j HTTP port (default: 7474)

  • --web-port PORT
    Specify BloodHound web interface port (default: 7080)

  • -h, --help
    Display the help message

Examples

List All Deployed Projects

./BloodHoundAnalyzer.sh -M list

Deploy BloodHound CE for a Domain

./BloodHoundAnalyzer.sh -M start -d contoso.local

Access at: http://127.0.0.1:7080/ui/login

  • Username: admin

To change the default admin password used by the Bash script, edit the custom_password variable in BloodHoundAnalyzer.sh before running start/import:

custom_password="YourNewStrongPasswordHere"

Deploy with Custom Ports

./BloodHoundAnalyzer.sh -M start -d contoso.local --bolt-port 7688 --neo4j-port 7475 --web-port 7081

Import BloodHound Data

Import a ZIP file:

./BloodHoundAnalyzer.sh -M import -d contoso.local -D /path/to/bloodhound_data.zip

Import JSON files from a folder:

./BloodHoundAnalyzer.sh -M import -d contoso.local -D /path/to/json_folder/

Run Analysis Tools

./BloodHoundAnalyzer.sh -M analyze -d contoso.local -o /opt/reports

This will generate:

  • AD-miner HTML report in ADMinerReport_contoso.local/
  • GoodHound analysis in GoodHound_contoso.local/
  • BloodHound QuickWin output in bhqc_contoso.local.txt
  • Ransomulator results in ransomulator_contoso.local.txt
  • PlumHound reports in PlumHound_contoso.local/
  • ad-recon analysis in ad-recon_contoso.local/

Complete Workflow (Import + Analyze)

./BloodHoundAnalyzer.sh -M import,analyze -d contoso.local -D /path/to/data.zip -o /opt/reports

Stop BloodHound CE Containers

./BloodHoundAnalyzer.sh -M stop -d contoso.local

Note: Volumes are preserved for restart

Clean Up Deployment

./BloodHoundAnalyzer.sh -M clean -d contoso.local

Warning: This removes containers, volumes, and project data permanently!

Multiple Domains (Isolated Instances)

Deploy and manage multiple domains simultaneously:

# Deploy first domain
./BloodHoundAnalyzer.sh -M start -d corp.local --web-port 7080

# Deploy second domain with different ports
./BloodHoundAnalyzer.sh -M start -d dev.local --web-port 7081 --bolt-port 7688 --neo4j-port 7475

# List all projects
./BloodHoundAnalyzer.sh -M list

Windows Deployer (BloodHoundDeployer.ps1)

A PowerShell script (BloodHoundDeployer.ps1) is provided for managing BloodHound CE instances on Windows using Docker Desktop. It covers container lifecycle and data import — analysis tools (Linux-only) are intentionally excluded.

Windows Prerequisites

  • Windows 10/11 or Windows Server 2019+
  • Docker Desktop installed and running
  • PowerShell 5.1+ (ships with Windows)

Deployer Modules

Module Description
list List deployed projects and container status
start Deploy and start BloodHound CE for a domain
import Import BloodHound data (.zip, .json, or folder of .json)
stop Stop containers (preserves volumes for restart)
delete Remove containers + project files (preserves volumes)
clean Full cleanup: containers, volumes, and project files

Changing the Default Password

The admin password is set in the $DefaultCustomPassword variable near the top of BloodHoundDeployer.ps1. Edit this line before first use:

$DefaultCustomPassword = 'YourNewStrongPasswordHere'

Deployer Usage

# List all projects
.\BloodHoundDeployer.ps1 -Modules list

# Deploy BloodHound CE for a domain
.\BloodHoundDeployer.ps1 -Modules start -Domain contoso.local

# Deploy with custom ports
.\BloodHoundDeployer.ps1 -Modules start -Domain contoso.local -BoltPort 7688 -Neo4jPort 7475 -WebPort 7081

# Import a ZIP file
.\BloodHoundDeployer.ps1 -Modules import -Domain contoso.local -DataPath C:\Data\bloodhound.zip

# Import JSON files from a folder
.\BloodHoundDeployer.ps1 -Modules import -Domain contoso.local -DataPath C:\Data\json_folder\

# Stop containers
.\BloodHoundDeployer.ps1 -Modules stop -Domain contoso.local

# Delete project (keep volumes)
.\BloodHoundDeployer.ps1 -Modules delete -Domain contoso.local

# Full clean (skip confirmation)
.\BloodHoundDeployer.ps1 -Modules clean -Domain contoso.local -Force

# Combined: start + import
.\BloodHoundDeployer.ps1 -Modules start,import -Domain contoso.local -DataPath C:\Data\bloodhound.zip

Deployer Options

Option Description
-Domain AD domain name (required for start/import/stop/delete/clean)
-DataPath Path to BloodHound data (required for import)
-BoltPort Neo4j Bolt port (default: 7687)
-Neo4jPort Neo4j HTTP port (default: 7474)
-WebPort BloodHound web port (default: 7080)
-Force Skip confirmation prompts for delete/clean
-Help Display help message

Directory Structure

/opt/BA_tools/
├── bloodhound-cli           # BloodHound CE CLI
├── .venv/                   # Python virtual environment
├── bhqc.py                  # BloodHound QuickWin script
├── ransomulator.py          # Ransomulator script
└── projects/
    ├── contoso.local/       # Project directory per domain
    │   ├── docker-compose.yml
    │   └── .env
    └── corp.local/
        ├── docker-compose.yml
        └── .env

/opt/BA_output/              # Analysis output directory
├── contoso.local/
│   ├── ADMinerReport_contoso.local/
│   ├── ad-recon_contoso.local/
│   ├── GoodHound_contoso.local/
│   ├── PlumHound_contoso.local/
│   ├── bhqc_contoso.local.txt
│   └── ransomulator_contoso.local.csv
└── corp.local/
    └── ...

Containers Won't Start

# Check Docker is running
docker ps

# Check container logs
docker logs <domain>-bloodhound-1

# Clean and restart
./BloodHoundAnalyzer.sh -M clean -d domain.local
./BloodHoundAnalyzer.sh -M start -d domain.local

Import Fails

# Check API accessibility
curl http://127.0.0.1:7080/api/version

# Check container logs
docker logs <domain>-bloodhound-1

# Verify data file format (should be .zip or .json)

Acknowledgments

BloodHoundAnalyzer uses the following tools:

Author

lefayjey - GitHub

About

BloodHound Automation: Collection, Analysis and Data Import

Topics

Resources

Stars

23 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages