Last seven days
- First activity
- Aug 1, 2026
- Last activity
- Aug 8, 2026
- Feed role
- C2 / Distribution
- Host form
- 43 IP / 23 hostnames
SharpHound is an open-source Microsoft C#-based Active Directory reconnaissance and data-ingestion tool for BloodHound.
Profile source: Mallory opens in a new tabSharpHound
SharpHound is an open-source Microsoft C#-based Active Directory reconnaissance and data-ingestion tool for BloodHound. The content consistently describes it being used to collect and map Active Directory information, including users, groups, computers, sessions, shares, SPNs, service accounts, and domain relationships, often via LDAP and RPC-based enumeration. It is associated with discovery and reconnaissance activity and is referenced in detection content for command-line usage, file modifications, LDAP query patterns, anomalous SPN requests, and RPC-based user/session/share enumeration.
The tool appears in multiple intrusion contexts. Sophos reported attackers in the Chinese state-directed Operation Crimson Palace campaign, specifically Cluster Charlie, using SharpHound in November 2023 for Active Directory infrastructure mapping after deploying Havoc and Cobalt Strike, including in-memory execution through a Cobalt Strike beacon, DLL-based deployment, and lateral movement via WMIC and scheduled tasks. Cisco Talos reported the China-nexus actor UAT-8837 using SharpHound to collect Active Directory information after gaining access through vulnerable servers or compromised credentials, alongside tools such as EarthWorm, DWAgent, Impacket, Rubeus, GoExec, and Certipy, while targeting critical infrastructure sectors in North America. Additional reporting ties SharpHound to UNC3944 reconnaissance behavior and to Ryuk and BlackSuit intrusion activity for Active Directory discovery.
High-confidence behaviors directly mentioned in the content include in-memory loading without writing the tool to disk, deployment as a DLL, execution through Cobalt Strike, and use for enterprise network and Active Directory topology mapping. The content does not present SharpHound as self-propagating malware or ransomware; rather, it is repeatedly characterized as a legitimate/open-source reconnaissance utility frequently abused by threat actors during post-compromise discovery.
C2 tracking
Derp observations, rolling seven-day window
Samples
4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 4e5cebe1908e12e8a4ed1198fb01fb87871dbe54847855b11b3540dbc47bbe88 54942b5bcfc9add448903934fc61f4e02bf2dc6378a65f0aa4af346e858fe9d3 c2214a8b8c88c91a009891f3f10bbb2d8aa18a15580bd12c82dfcf2477f0c846 c26e2475ef60ba969bb66c9b464b498efb1da0bf7360ff7545c1db3b707bdbed 2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce c322fa3e02a79ecead674bc4a8e67b71d14632427f8dc9a380b0f588941bbf1a f270a80b90acb4302bb29b2f4c7436f6d7eedc4738ca63351f59f22bd59ce28d f5ebd8f8e5217df1c726beb523c00d49992d6d205589509cbe2c581b6aab29b6 84b8ec2f3b29a10f88d21fc7617cdfecac1c2c76303086b41471beb5f563f65c Reported operators
UNC3944 will also use network reconnaissance tools like ADRecon, ADExplorer, and SharpHound.
SharpHound, to collect Active Directory information
"...most likely accomplished through the use of SharpHound, a Microsoft C#-based data 'injestor' tool for BloodHound..."
Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.