Bloodhound
If SID is displayed it is a local account. BloodHound uses this representation of a principal when the domain identifier of the SID is from a local machine
Use Collection Loops to not miss information
Bloodhound ingestor
can also use -dns-tcp
All computers in domain:
All Users in domain:
To get active sessions:
--Loop --LoopDuration 00:10:00
to loop
To check users who can RDP
Check for SQLAdmin User:
If found:
Then use mssqlclient:
Last updated
Was this helpful?