ENNAENNA

PingCastle vs SharpHound

GitHub Stats

2.8k
Stars
1.3k
341
Forks
254
56
Issues
38
13d ago
Updated
4d ago
-
License
GPL-3.0
C#
Language
C#

About PingCastle

PingCastle performs rapid Active Directory security assessments by analyzing domain configuration, trust relationships, user accounts, group policies, and delegation settings. It produces a comprehensive risk score across four categories: stale objects, privileged accounts, trust relationships, and anomalies. PingCastle identifies password policy weaknesses, dangerous delegations, abandoned admin accounts, SMB signing issues, and dozens of other AD security concerns. Reports are generated as interactive HTML with remediation priorities. It runs without elevated privileges and completes assessments in minutes even on large domains.

About SharpHound

SharpHound is the official data collector for BloodHound, a tool used to visualize Active Directory environments. Written in C#, it enumerates Active Directory objects, sessions, access control lists (ACLs), and trust relationships, providing data for graph-based analysis of potential attack paths. SharpHound is essential for red teams seeking to understand and exploit complex Active Directory structures, enhancing strategic attack planning.

Platform Support

🪟windows
🪟windows

Tags

Shared

active-directory

PingCastle only

security-assessmentrisk-scoringdomain-auditmisconfiguration

SharpHound only

enumerationbloodhoundgraph-datacollector