Last seven days
- First activity
- Jul 20, 2026
- Last activity
- Jul 21, 2026
- Feed role
- C2 / Distribution
- Host form
- 16 IP / 26 hostnames
SharpHound is an open-source Microsoft C#-based Active Directory reconnaissance and data-ingestion tool for BloodHound.
Profile source: Mallory opens in a new tabSharpHound
SharpHound is an open-source Microsoft C#-based Active Directory reconnaissance and data-ingestion tool for BloodHound. The content consistently describes it being used to collect and map Active Directory information, including users, groups, computers, sessions, shares, SPNs, service accounts, and domain relationships, often via LDAP and RPC-based enumeration. It is associated with discovery and reconnaissance activity and is referenced in detection content for command-line usage, file modifications, LDAP query patterns, anomalous SPN requests, and RPC-based user/session/share enumeration.
The tool appears in multiple intrusion contexts. Sophos reported attackers in the Chinese state-directed Operation Crimson Palace campaign, specifically Cluster Charlie, using SharpHound in November 2023 for Active Directory infrastructure mapping after deploying Havoc and Cobalt Strike, including in-memory execution through a Cobalt Strike beacon, DLL-based deployment, and lateral movement via WMIC and scheduled tasks. Cisco Talos reported the China-nexus actor UAT-8837 using SharpHound to collect Active Directory information after gaining access through vulnerable servers or compromised credentials, alongside tools such as EarthWorm, DWAgent, Impacket, Rubeus, GoExec, and Certipy, while targeting critical infrastructure sectors in North America. Additional reporting ties SharpHound to UNC3944 reconnaissance behavior and to Ryuk and BlackSuit intrusion activity for Active Directory discovery.
High-confidence behaviors directly mentioned in the content include in-memory loading without writing the tool to disk, deployment as a DLL, execution through Cobalt Strike, and use for enterprise network and Active Directory topology mapping. The content does not present SharpHound as self-propagating malware or ransomware; rather, it is repeatedly characterized as a legitimate/open-source reconnaissance utility frequently abused by threat actors during post-compromise discovery.
C2 tracking
Derp observations, rolling seven-day window
Samples
27dc2e511f4da03bc10b975156996133c8654defc24d40b829ff7d955be4e2ce 2e74827318235a497133219963a2205cd8d7779a195ec67d740d825599210932 5594d4a2153e25d5de0de21bc958e1d11a341679ea2fec2123567fa3547c7847 7ef34bf0c59089432586e8847b5a8d7439a28ed3aca3254fab49ef13723be65e c4617e465670873ca7de2d8898e8c349d8189b86561fc5b8996c4d8bab251801 2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 5bcc428f37655c7bc16110cc2127c510f66827a382cb1c9fa251b15a7d2c214b 65ba3988d38f83b9ee1f31cafa5bd37dc6b72279f5618aac94d71a904efa0cac 9cd9c0a79450290b1ac0ea3235df6cd68332cc5a426991fa1d53eb7f19ec5a09 Reported operators
UNC3944 will also use network reconnaissance tools like ADRecon, ADExplorer, and SharpHound.
SharpHound, to collect Active Directory information
"...most likely accomplished through the use of SharpHound, a Microsoft C#-based data 'injestor' tool for BloodHound..."
Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.