> ## Documentation Index
> Fetch the complete documentation index at: https://specterops-feat-poc-api-playground.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# SharpHound Enterprise System Requirements and Deployment Process

<img noZoom src="https://mintcdn.com/specterops-feat-poc-api-playground/5XJ7p5p7xL9ZwxE2/assets/enterprise-edition-pill-tag.svg?fit=max&auto=format&n=5XJ7p5p7xL9ZwxE2&q=85&s=5935d09eed22feb3daa90beb0a34b571" alt="Applies to BloodHound Enterprise only" width="225" height="45" data-path="assets/enterprise-edition-pill-tag.svg" />

The SharpHound Enterprise service is a critical element in your deployment that collects and uploads data about your environment to your BloodHound Enterprise instance for processing and analysis.

SharpHound Enterprise is deployed as a signed Windows service, runs under the context of a domain account, and collects from one or more domains utilizing the configured service account.

## Deployment Process Overview

To collect Active Directory data with SharpHound and ingest it into BloodHound for analysis:

1. Provision a Server that meets or exceeds the recommended Hardware, Software, and Network requirements below.
2. Create a Service Account or [gMSA](/install-data-collector/install-sharphound/create-gmsa) that SharpHound will run as with the Service Account Requirements below.
3. [Install and Upgrade SharpHound Enterprise](/install-data-collector/install-sharphound/installation-upgrade)
4. [Create a BloodHound Enterprise collector client](/collect-data/enterprise-collection/create-collector)
5. [Run an On Demand Scan](/collect-data/enterprise-collection/on-demand-scan) or [Create a data collection schedule](/collect-data/enterprise-collection/collection-schedule)

## Server Requirements

### Hardware

| Resource            | Minimum          | Recommended      | Large enterprise |
| ------------------- | ---------------- | ---------------- | ---------------- |
| **Processor Cores** | 2 physical cores | 4 physical cores | 6 physical cores |
| **Memory**          | 4GB RAM          | 16GB RAM         | 32GB RAM         |
| **Hard disk space** | 1GB for logging  | 5GB for logging  | 20GB for logging |

**These recommendations should be considered a baseline and may need to be increased depending on the size and complexity of your environments.**

Minimums apply to test or development deployments.
Where multiple collectors are deployed on a single host, scaling wll be necessary to maintain performance.

### Software

* Windows Server 2019+
* .NET 4.7.2+

### Network

* TLS on 443/TCP to your BloodHound Enterprise SaaS tenant URL (proxy is supported)
* LDAP to at least one domain controller in each domain requiring collection.
  * By default, SharpHound will attempt LDAP over SSL first, then fall back to LDAP if SSL is unavailable.
    * LDAP over SSL on 636/TCP (configurable port)
    * LDAP on 389/TCP (configurable port)
  * LDAP over SSL is enforceable.
  * [LDAP channel signing](https://www.hub.trimarcsecurity.com/post/ldap-channel-binding-and-signing) is used for all queries.
* \[Optional] If performing privileged collection (see [Why perform privileged collection in SharpHound](/collect-data/enterprise-collection/privileged-collection))
  * SMB/RPC on 445/TCP to all in-scope domain-joined Windows systems
  * Approximately 60-100kB network bandwidth per collection to each in-scope domain-joined Windows system
* \[Optional] If performing DC Registry and CA Registry collection (see [DC Registry and CA Registry details](/collect-data/permissions))
  * SMB/RPC on 445/TCP to all DCs and domain-joined CAs

## Service Account Requirements

The SharpHound Enterprise service will run as a domain-joined account and will utilize the permissions of that account for enumeration purposes.

* Authenticated User within any domains requiring collection
* Granted "Log on as a service" User Rights Assignment on the SharpHound Enterprise server
* \[Optional] If performing privileged collection (see [Why perform privileged collection in SharpHound](/collect-data/enterprise-collection/privileged-collection))
  * Member of the local Administrators group on all in-scope domain-joined Windows systems
* \[Optional] If performing DC Registry and CA Registry collection (see [DC Registry and CA Registry details](/collect-data/permissions))
  * Member of the local Administrators group on all domain controllers and domain-joined certificate authorities
* \[Optional]: If Active Directory tombstoning is enabled
  * Read privileges to the Deleted Objects container (see [How to let non-administrators view the Active Directory deleted objects container](https://learn.microsoft.com/en-us/troubleshoot/windows-server/identity/non-administrators-view-deleted-object-container))

See [SharpHound Data Collection and Permissions](/collect-data/permissions) for comprehensive requirement information.
