Last seven days
- First activity
- Aug 29, 2026
- Last activity
- Sep 3, 2026
- Feed role
- C2 / Distribution
- Host form
- 74 IP / 39 hostnames
SharpHound is an open-source Microsoft C#-based Active Directory reconnaissance and data-ingestion tool for BloodHound.
Profile source: Mallory opens in a new tabSharpHound
SharpHound is an open-source Microsoft C#-based Active Directory reconnaissance and data-ingestion tool for BloodHound. The content consistently describes it being used to collect and map Active Directory information, including users, groups, computers, sessions, shares, SPNs, service accounts, and domain relationships, often via LDAP and RPC-based enumeration. It is associated with discovery and reconnaissance activity and is referenced in detection content for command-line usage, file modifications, LDAP query patterns, anomalous SPN requests, and RPC-based user/session/share enumeration.
The tool appears in multiple intrusion contexts. Sophos reported attackers in the Chinese state-directed Operation Crimson Palace campaign, specifically Cluster Charlie, using SharpHound in November 2023 for Active Directory infrastructure mapping after deploying Havoc and Cobalt Strike, including in-memory execution through a Cobalt Strike beacon, DLL-based deployment, and lateral movement via WMIC and scheduled tasks. Cisco Talos reported the China-nexus actor UAT-8837 using SharpHound to collect Active Directory information after gaining access through vulnerable servers or compromised credentials, alongside tools such as EarthWorm, DWAgent, Impacket, Rubeus, GoExec, and Certipy, while targeting critical infrastructure sectors in North America. Additional reporting ties SharpHound to UNC3944 reconnaissance behavior and to Ryuk and BlackSuit intrusion activity for Active Directory discovery.
High-confidence behaviors directly mentioned in the content include in-memory loading without writing the tool to disk, deployment as a DLL, execution through Cobalt Strike, and use for enterprise network and Active Directory topology mapping. The content does not present SharpHound as self-propagating malware or ransomware; rather, it is repeatedly characterized as a legitimate/open-source reconnaissance utility frequently abused by threat actors during post-compromise discovery.
C2 tracking
Derp observations, rolling seven-day window
Samples
1b723594e574c00aac2c946ff738a0454f7c24f6ebc84ae45a6af9628b08cb96 40b643468356c0fd751893647ad0dc9e2a0019427e4f5f0e2f6e559efcecb977 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 65ba3988d38f83b9ee1f31cafa5bd37dc6b72279f5618aac94d71a904efa0cac d780677e97da00b2b90849741720c1a02e758356630b63242a18074775c69e1c 3c6126417211aacd1bb0ebadcd474747890e8930a4684ccabe448d1390b3c064 82d918003e4c428c6f3c09996b98bf51f582bd94daea05dd00a458eaeb6a2f31 86169823504bfb77ddf5e199fa2c683db27fcf06bf4f385f114e48e089120986 f1fdb3e045eff53d860bb757980dd194b392910fc8a9b640bae912388cda9c4c 029330cc5fcc1564bf80605028ac25b289f3883b860fd95311b125471e62d688 Reported operators
UNC3944 will also use network reconnaissance tools like ADRecon, ADExplorer, and SharpHound.
SharpHound, to collect Active Directory information
"...most likely accomplished through the use of SharpHound, a Microsoft C#-based data 'injestor' tool for BloodHound..."
Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.