Launch neo4j database service

net start neo4j

Launch SharpHound collector

# Launch a cmd as domain user
runas /netonly /noprofile /user:${domain}\${user} cmd.exe

# Launch collector
SharpHound.exe -c all -d ${domain} --domaincontroller ${dcIp} --overrideusername ${domainUser} --ldapusername ${domainUser} --ldappassword ${password}

Save the BH database or load external database

  1. Stop Neo4j
  2. Open the Neo4j configuration folder /etc/neo4j/neo4j.conf
  3. Uncomment the ligne dbms.default_database=neo4j and replace the name by the name you want
  4. Restart Neo4j

The database shoudl be here : /var/lib/neo4j/data/databases/

BloundHound Quick Win

