1200KM / sigma-rule
BloodHound Collection Files — Sigma Rule
Sigma rule 02773bed-83bf-469f-b7ff-e676e7d78bab. BloodHound Collection Files — Sigma Rule. Detects default file names outputted by the BloodHound collection tool SharpHound
Rule metadata and linked tags
Author: C.J. May. Source status: test; severity: high. Source dates: 2022-08-09 / 2026-02-19.
{
"product": "windows",
"category": "file_event"
}Pinned original Sigma rule · Detection Rule License 1.1
Source SHA-256: 9a10039f41f0f9ca5424571728d37838da43ca8aa84d44af4a0dc9166fc80969
Detection logic
Original source YAML. Source-tag agreement is not proof of complete semantic coverage. This rule has not been compiled for a SIEM backend or validated against live telemetry here.
title: BloodHound Collection Files
id: 02773bed-83bf-469f-b7ff-e676e7d78bab
status: test
description: Detects default file names outputted by the BloodHound collection tool SharpHound
references:
- https://academy.hackthebox.com/course/preview/active-directory-bloodhound/bloodhound--data-collection
author: C.J. May
date: 2022-08-09
modified: 2026-02-19
tags:
- attack.discovery
- attack.t1087.001
- attack.t1087.002
- attack.t1482
- attack.t1069.001
- attack.t1069.002
- attack.execution
- attack.t1059.001
logsource:
product: windows
category: file_event
detection:
selection:
TargetFilename|endswith:
- 'BloodHound.zip'
- '_computers.json'
- '_containers.json'
# - '_domains.json' # prone to false positives with ProbabilisticRevealTokenRegistry function in Google Chrome
- '_gpos.json'
- '_groups.json'
- '_ous.json'
- '_users.json'
filter_optional_ms_winapps:
Image|endswith: '\svchost.exe'
TargetFilename|startswith: 'C:\Program Files\WindowsApps\Microsoft.'
TargetFilename|endswith: '\pocket_containers.json'
condition: selection and not 1 of filter_optional_*
falsepositives:
- Some false positives may arise in some environment and this may require some tuning. Add additional filters or reduce level depending on the level of noise
level: high
False positives
- Some false positives may arise in some environment and this may require some tuning. Add additional filters or reduce level depending on the level of noise
Source references
Connected ecosystem references
Exact source-tagged techniques
- T1059.001 · PowerShell · Detection rules & anomalies
- T1069.001 · Local Groups · Detection rules & anomalies
- T1069.002 · Domain Groups · Detection rules & anomalies
- T1087.001 · Local Account · Detection rules & anomalies
- T1087.002 · Domain Account · Detection rules & anomalies
- T1482 · Domain Trust Discovery · Detection rules & anomalies
Telemetry review
Read the original logsource above, then inspect the linked detection workspaces for technique-level sensor context. No per-rule telemetry equivalence is inferred.
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.