SharpHound
- First seen
- 2016-12-01 00:00:00
- Malware type
- credential-stealer, spyware
- Last IoC activity
- 2026-07-20 15:59:15
- Profile updated
- 2026-07-07 13:17:03
Targeted industries: government-and-public-sector financial-services healthcare-and-pharmaceutical technology-and-telecommunications
Context
According to its Github repository, SharpHound is a C# Data Collector for BloodHound.
Detection coverage
- 4 YARA rules
Detection rules
- SEKOIA_Tool_Sharphoundpowershell_Strings (yara-rule)
- SEKOIA_Tool_Sharphoundexecutable_Strings (yara-rule)
- SIGNATURE_BASE_HKTL_Rusthound (yara-rule)
- FIREEYE_RT_Hacktool_MSIL_Sharphound_3 (yara-rule)
Reports & references
- Cisco Talos — Uat 8837 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Sharphound (report)