SharpHound

SharpHound collection reference

Use the current BloodHound CE collector from its official release channel. SharpHound.ps1 and Invoke-BloodHound belong to legacy BloodHound workflows and should not appear in a current runbook.

Preflight

Bounded first pass

Start with the narrowest methods needed to answer the assessment question. For an initial directory-relationship snapshot, use an explicit domain and a bounded method such as DCOnly when supported by the installed release:

SharpHound.exe --CollectionMethods DCOnly --Domain CONTOSO.LOCAL --OutputDirectory C:\Engagement\Evidence

Do not treat All as a default. Host and session methods can contact many systems and collect sensitive relationship data. Add them only when the rules of engagement name them and the expected telemetry has been agreed.

Evidence and cleanup

Record collector version and checksum, selected methods, start and end times, domain, source host, output hashes, and defender observations. Remove collection archives from endpoints after secure transfer and apply the engagement retention policy.