1. What SharpHound Solves for Defenders
SharpHound collects Active Directory relationship data for BloodHound analysis and is studied by defenders in authorized labs to understand what AD data enables privilege-path mapping and how to detect and harden against misuse.
SharpHound fits the "AD data collection for BloodHound (dual-use)" role in this course. Treat it as one tool in a workflow, not as a complete answer by itself. The key question is what decision quality it improves for a defender.
Before using SharpHound, define the operational question first (triage, validation, exposure review, monitoring, forensics, or documentation). Tool selection should follow the question, not the other way around.