SharpHound

First seen
2016-12-01 00:00:00
Malware type
credential-stealer, spyware
Last IoC activity
2026-07-20 15:59:15
Profile updated
2026-07-07 13:17:03

Targeted industries: government-and-public-sector financial-services healthcare-and-pharmaceutical technology-and-telecommunications

Context

According to its Github repository, SharpHound is a C# Data Collector for BloodHound.

Detection coverage

  • 4 YARA rules

Detection rules

  • SEKOIA_Tool_Sharphoundpowershell_Strings (yara-rule)
  • SEKOIA_Tool_Sharphoundexecutable_Strings (yara-rule)
  • SIGNATURE_BASE_HKTL_Rusthound (yara-rule)
  • FIREEYE_RT_Hacktool_MSIL_Sharphound_3 (yara-rule)

Reports & references

  • Cisco Talos — Uat 8837 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Sharphound (report)

External references