1 00:00:00,330 --> 00:00:03,960 Welcome to this video on installing bloodhound. 2 00:00:03,960 --> 00:00:10,870 So bloodhound is a tool that's going to download the data essentially of Active Directory. 3 00:00:10,920 --> 00:00:16,380 Once we're on a machine or on a network it's going to be able to download the data for us and what it's 4 00:00:16,380 --> 00:00:19,560 going to do is visualize that data in a graph. 5 00:00:19,560 --> 00:00:25,410 So we're going to be able to identify a lot of information about a network very very quickly. 6 00:00:25,500 --> 00:00:32,280 So it could take us a long time otherwise to you know attempt this and try to try to figure out you 7 00:00:32,290 --> 00:00:37,830 know all these complex paths that you might be able to have in the network to get to a domain admin 8 00:00:38,030 --> 00:00:41,010 where bloodhound figures that out really quick for you. 9 00:00:41,010 --> 00:00:49,650 So this is developed by the team over at spectre ops and that's Waldo harm joy and Captain Jesus they're 10 00:00:49,650 --> 00:00:50,510 a great team. 11 00:00:50,520 --> 00:00:55,620 Actually one of the references you're gonna have blog references is going to be for harm joy here at 12 00:00:55,620 --> 00:00:56,190 the end. 13 00:00:56,190 --> 00:01:02,850 So I recommend reading their material because they are the active directory gurus among other people 14 00:01:02,850 --> 00:01:03,870 in this field. 15 00:01:03,930 --> 00:01:06,870 So installing bloodhound is fairly straightforward here. 16 00:01:06,870 --> 00:01:13,170 We're going to go ahead and just say aft installed bloodhound on our Cally machine and it's going to 17 00:01:13,170 --> 00:01:19,200 be three hundred and fifty three megabytes of additional disk space. 18 00:01:19,230 --> 00:01:19,940 What does that mean. 19 00:01:19,950 --> 00:01:22,190 That means this is going to take a while. 20 00:01:22,350 --> 00:01:25,460 So go ahead and pause the video. 21 00:01:25,590 --> 00:01:30,570 Let this do it install let it do its thing and then meet me back once you're all set up and ready to 22 00:01:30,570 --> 00:01:36,780 go and we'll continue on with the instructions that took for ever for some reason I don't know what's 23 00:01:36,780 --> 00:01:38,950 going on with my internet today I guess it's slow. 24 00:01:39,120 --> 00:01:41,210 Hopefully years is a lot faster. 25 00:01:41,280 --> 00:01:46,630 So what runs on a tool called neo for J. 26 00:01:46,680 --> 00:01:49,670 Actually you can see it setting up here neo for J. 27 00:01:49,680 --> 00:01:51,340 We're gonna have to set that up really quick. 28 00:01:51,360 --> 00:01:59,120 So let's go ahead and say neo for J console and we'll we're gonna do is we're going to change our default 29 00:01:59,150 --> 00:02:05,000 password here just so we're not using default credentials and we're going to be a little bit better 30 00:02:05,000 --> 00:02:05,950 on security. 31 00:02:05,990 --> 00:02:08,180 You can see it boots up at this local house. 32 00:02:08,180 --> 00:02:15,170 Let's go ahead to open this up if we can and we should gain access to this site. 33 00:02:15,680 --> 00:02:16,750 So OK. 34 00:02:16,800 --> 00:02:20,640 Your username password are going to be neo for J. 35 00:02:20,640 --> 00:02:22,420 That's gonna allow us to connect. 36 00:02:22,590 --> 00:02:25,210 So neo for j just like the user name. 37 00:02:25,230 --> 00:02:26,750 Go ahead and say connect. 38 00:02:26,910 --> 00:02:28,900 And now it's going to ask you for a new password. 39 00:02:28,890 --> 00:02:31,980 So go ahead and put whatever password you want in there. 40 00:02:31,980 --> 00:02:36,870 I'm going to use the very weak password of password OK. 41 00:02:36,910 --> 00:02:40,750 So you are all set up your connected you are good to go. 42 00:02:40,750 --> 00:02:48,930 So now go ahead and close your browser window and now we can go ahead and open up let's open up a new 43 00:02:48,930 --> 00:02:56,470 tab and we'll say bloodhound should just start typing it auto tab I'll make this bigger so you can see 44 00:02:56,470 --> 00:03:02,380 it and you can see the green checkmark here means we are connected to the database. 45 00:03:02,390 --> 00:03:04,610 So go ahead and just put it in Neo for J. 46 00:03:04,880 --> 00:03:11,720 Putting your password on the go ahead and save my password log in success and now you should be brought 47 00:03:11,720 --> 00:03:13,330 to this. 48 00:03:13,350 --> 00:03:14,960 Says no data returned from the query. 49 00:03:14,960 --> 00:03:21,500 Because we haven't provided any data yet so we are we've got bloodhounds set up now we're gonna go use 50 00:03:21,500 --> 00:03:28,100 what's called an adjuster get some data back from our Active Directory and then we'll see what we can 51 00:03:28,100 --> 00:03:28,880 do with that data. 52 00:03:28,880 --> 00:03:31,910 So let's go ahead and pull data within gesture.