SpecterOps / SpecterOps/SharpHoundCommon

Performance degradation when SharpHound attempts to resolve unresolvable SIDs

Open
#203 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

ticketed
Dominant language
C#
Stars
104
Forks
56
Avg merge
3d 23h
Merged PRs (30d)
2

Description

When running SharpHound from a non-domain-joined Windows machine using supplied credentials, if target objects in the domain contain unresolvable SIDs (e.g., due to stale entries from broken two-way trusts), the tool repeatedly attempts to resolve them.

  • Environment
  1. SharpHound Version: 2.6.5
  2. SharpHoundCommon Version: 4.2.6
  3. Command : SharpHound -c DCOnly --ldapusername domainuser@ludus.domain --ldappassword ******** -d ludus.domain -v 1 --skipportcheck --disablecertverification --disablesigning --domaincontroller ludus.domain
  • Conditions
  1. The machine executing SharpHound is not joined to the domain
  2. Some AD objects contain SIDs from a previously trusted domain (e.g., due to removed two-way trust)
  3. unresolvable SID (from a previously trusted domain) was present on many AD objects.
  4. Total object count is large (e.g., 500,000+ objects)
  • Screenshot
  1. non-domain-joined Image

  2. domain-joined Image

  • Observed Behavior
  1. SharpHound attempts to resolve unknown or external SIDs via DirectoryContext using GetDomain(...)
  2. Each failed resolution logs:
    System.DirectoryServices.ActiveDirectory.ActiveDirectoryOperationException: Current security context is not associated with an Active Directory domain or forest.
  • Comparison Results
Scenario Cache Execution Time
Domain-joined host ❌ / ✅ 13 mins
Non-domain host, same creds 30 mins
Non-domain host, same creds 90 mins

Is it possible to add unresolvable SID cache to avoid repeated requests or disable try get unresolvable SID?

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by tracing the SID-resolution path that uses DirectoryContext and GetDomain(...), then reproduce the non-domain-joined command and compare behavior with and without the existing cache. Done means repeated failures for the same unresolvable SID no longer trigger repeated requests, or the resolution attempt can be disabled, with the observed timing and error behavior covered by verification.

Written by the indexing model from the issue text.

Assessment

Tech stack
csharp
Domain
performance, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
42/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.