sharphound.exe
Sources: observed in the EchoTrail lab on Windows 11.
Summary
sharphound.exe (SharpHound), by SpecterOps.
sharphound.exe is not in the 2025 snapshot. It was observed in EchoTrail's behavior lab on Windows 11 24H2 on 2026-09-24 installed from zip_url package https://github.com/SpecterOps/SharpHound/releases/download/v2.16.0/SharpHound_v2.16.0_windows_x86.zip.
Get this in your tools
The same record for sharphound.exe, by REST or as an MCP tool. Free key, no card.
curl -H "Authorization: Bearer $ECHOTRAIL_KEY" \
https://api.echotrail.io/v1/process/sharphound.exeFree returns the summary. Team returns the full record you see on this page. Endpoint docs
Behavior
Top Paths
- C:\lab\in
Top Hashes (SHA256)
- 8ff1323436329d3d122926f3f1f5cb0f2f587eb515e1d4fb17459cedf41e84dd
Process Ancestry
Top Grandparents
Top Parents
Lab record
- Installed from
- zip_url https://github.com/SpecterOps/SharpHound/releases/download/v2.16.0/SharpHound_v2.16.0_windows_x86.zip
- Publisher
- unknown, unsigned
- Persistence
- none
- Network
- none
- Command lines
- 1 pattern (1 launch)
- DLL loads
- 61 patterns (63 loads)
- Registry writes
- 0 patterns (0 writes)
- File writes
- 10 patterns (10 writes)
- HTTP requests
- 0 patterns (0 requests)
- TLS connections
- 0 patterns (0 handshakes)
- Named pipes
- 1 pattern (1 event)
- Process access
- 0 patterns (0 events)
- Driver loads
- 0 patterns (0 loads)
- PowerShell blocks
- 0 patterns (0 blocks)
- Remote threads
- 0 patterns (0 events)
- Audit events
- 1 pattern (1 event)
Full record on Team.
Security Analysis
What does sharphound.exe normally do?
Legitimate use is an authorized assessor or internal AD security team running SharpHound interactively from a console on a domain-joined workstation, typically with collection-method flags (e.g. /c All, /c DCOnly, -d domain.local, --stealth) and an output ZIP/JSON dropped in the working directory for upload to BloodHound. In the lab the binary ran once as C:\lab\in\SharpHound.exe with the '/S' flag, launched from powershell.exe, and was unsigned (no Authenticode signature present) despite carrying SpecterOps/SharpHound version metadata. No network connections were attributed to sharphound.exe in the capture and no autoruns, services or persistence artifacts were created; the only DNS oddities in the window were 'WIN11-LAB', '..localmachine' and 'wpad' name lookups, consistent with a non-domain-joined host where LDAP/AD discovery fails immediately. All other process, file-write, registry and network activity in the capture (Defender platform updates, OneDriveSetup/OneDrive, Microsoft Edge/WebView2 update chain) is unrelated Windows background maintenance. Expect LDAP/389 and LDAPS/636 to domain controllers, SMB/445 and RPC to member hosts, and burst-like fan-out to many internal IPs on a real domain.
When is sharphound.exe suspicious?
Renamed or repackaged copies of the binary (original filename SharpHound.exe with a different on-disk name, or SharpHound version resources on an unsigned/oddly-signed file) running from C:\Users\Public, %TEMP%, %APPDATA%, C:\ProgramData or a WebDAV/UNC path. Execution parented by powershell.exe, cmd.exe, wscript/mshta, an Office app, a service/WMI host, PSEXESVC, or an EDR-visible beacon process rather than an interactive admin shell; execution under SYSTEM or a freshly compromised service account; or via the in-memory PowerShell (Invoke-BloodHound / SharpHound.ps1) or Cobalt Strike execute-assembly variants where no EXE ever touches disk. Command-line tells include /c All, --CollectionMethods All,LoggedOn,Session,ACL, --Stealth, --LdapUsername/--LdapPassword, --DomainController, --ZipPassword, --OutputDirectory pointing to a staging folder, or looping runs against multiple domains/trusts. Behavioral tells: a single non-DC host opening LDAP/LDAPS to every domain controller and SMB/445 or RPC to hundreds or thousands of internal hosts within minutes, creation of *_BloodHound.zip or ????????????_*.json (users.json, computers.json, groups.json, sessions.json) files, off-hours execution, and the ZIP being immediately staged, renamed or exfiltrated to cloud storage or an attacker share.
How do attackers abuse sharphound.exe?
SharpHound is a dual-use offensive tool and is routinely repurposed by real intrusion sets. Ransomware affiliates and access brokers (Conti, LockBit, BlackCat/ALPHV, Black Basta, Akira, Royal, FIN6/FIN7, Vice Society) drop SharpHound.exe or run the Invoke-BloodHound PowerShell/Cobalt Strike execute-assembly variant shortly after initial access to map domain admin paths, Kerberoastable accounts, unconstrained delegation, ACL abuse edges and high-value targets before privilege escalation and mass encryption. State-sponsored actors use it for the same AD reconnaissance step. Operators commonly rename the binary to innocuous names, run it as an embedded .NET assembly in memory to bypass file-based AV, use --Stealth or DCOnly to reduce noise, encrypt the output ZIP with --ZipPassword, and then exfiltrate the JSON/ZIP for offline analysis. The collected data directly feeds follow-on Kerberoasting/AS-REP roasting, DCSync target selection, GPO and ACL abuse, and lateral movement path planning; possession of the output itself is a strong pre-ransomware indicator.
Detection guidance
Alert on any execution of a PE whose version resources say SharpHound/BloodHound regardless of filename, and on the known hashes of released builds; pair this with a rule for .NET assemblies that generate high-volume LDAP queries from a non-DC endpoint. Hunt for creation of files matching *_BloodHound.zip and ^[0-9]{14}_(users|computers|groups|sessions|gpos|domains|containers)\.json, and for Sysmon 3/network telemetry showing one workstation making LDAP/389, LDAPS/636 and SMB/445 connections to an anomalous count of distinct internal hosts in a short window. Enable and monitor Directory Service Access auditing (4662) and LDAP query logging / Event 1644 on domain controllers for the bulk objectClass=* and ms-Mcs-AdmPwd style sweeps SharpHound produces, plus 4624/4634 spikes from session enumeration. Since in-memory execution leaves no image on disk, watch for CLR loading (clr.dll/clrjit.dll) inside powershell.exe, rundll32.exe or unbacked memory regions in beacon processes, and for ETW/AMSI events referencing SharpHound classes. Treat any hit in a production environment as suspicious unless it maps to an approved, ticketed assessment window and a known assessor host.
Ask Rocky about sharphound.exe
Rocky is the free chat demo. It answers from this same dataset, no account needed.
This page is the Team-tier API record for sharphound.exe. The free tier returns the summary, 500 lookups a month. Or ask Rocky.