SharpHound Execution for AD Reconnaissance and BloodHound Collection
Detects the execution of BloodHound/SharpHound reconnaissance tools and the presence of their generated output files (ZIP or JSON format) on a host. This rule monitors both the process creation events associated with the tool's execution and file creation events indicative of data staging or collection output.
Microsoft Sentinel (KQL)

