
ShareHound - Mapping Network Share Rights into BloodHound OpenGraph
Source: YouTube · SpecterOps · published Jan 21, 2026 · 1:01:45
This webinar introduces ShareHound, a new open graph collector for SpecterOps that maps network file shares into BloodHound using the open graph technology introduced in BloodHound 8 2:05.
Key Takeaways:
• ShareHound addresses a blind spot in data collection by enabling auditors to map network shares, which often contain low-hanging fruits like passwords, scripts, and sensitive diagrams 2:10.
• The tool uses a custom Domain Specific Language called ShareQL for flexible rule-based filtering, with a VS Code extension available for syntax highlighting and autocompletion 2:22.
• Network shares are critical to audit as they remain common ransomware entry points through misconfigured permissions like Full Control or Write access 2:28.
• Once ingested into BloodHound, Cypher queries can identify users with dangerous permissions on shares, locate specific files like VMDKs, and visualize directory trees as attack paths 2:33.
• ShareHound does not read file contents to avoid bandwidth issues, so it cannot directly detect GPP passwords, though this could be added as a future feature 2:42.
ShareHound provides security teams with scalable network share mapping capabilities, transforming previously difficult-to-audit file structures into actionable attack path visualizations within BloodHound.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Remy, it seems like your audio is not working anymore, >> unfortunately. >> There you are. >> All right. Yeah, we will wait for around like 1 minute or two and then we'll get started until like everyone can jump into the webinar. All right. Well, let's get started. So in this webinar we are going to explore a new open graph collector that I wrote for spectrups uh where we uh looked at um how we can map uh file shares into blueown uh with the new open graph technology that was introduced in blueon 8 and we are going to see what was the problem behind that what new opportunities it um it's um opening for us as auditors to find new paths that are using at network shares and uh we are going to look at um how we can use this tool and I will do a little demo with a few use cases. So the first th…