Not into live chat? Join our new SpecterOps & BloodHound Community subreddit!
Come for the AMA, stay for the discussions: https://www.reddit.com/r/SpecterOpsCommunity/
Not into live chat? Join our new SpecterOps & BloodHound Community subreddit!
Come for the AMA, stay for the discussions: https://www.reddit.com/r/SpecterOpsCommunity/
ICYMI: The BloodHound BACK button is BACK. Just use your browser's BACK button to go BACK. 🔙
ICYMI: The BloodHound BACK button is BACK. Just use your browser's BACK button to go BACK. 🔙
Want to connect w/ other BloodHound users, or the folks building BloodHound?
Join the community Slack 👉 slack.specterops.io
Dedicated channels for:
• Active Directory
• Red Teaming
• SCCM
• Detection
...and more
Come hang with us!
Want to connect w/ other BloodHound users, or the folks building BloodHound?
Join the community Slack 👉 slack.specterops.io
Dedicated channels for:
• Active Directory
• Red Teaming
• SCCM
• Detection
...and more
Come hang with us!
This week: Relationship Shortcuts.
Instead of listing all traversable relationships in your Cypher queries, use:
[:AD_ATTACK_PATHS] for Active Directory
[:AZ_ATTACK_PATHS] for Entra ID
[:ALL_ATTACK_PATHS] for AD & Entra
This week: Relationship Shortcuts.
Instead of listing all traversable relationships in your Cypher queries, use:
[:AD_ATTACK_PATHS] for Active Directory
[:AZ_ATTACK_PATHS] for Entra ID
[:ALL_ATTACK_PATHS] for AD & Entra
The docs got a fresh new look and live at bloodhound.specterops.io — now back in the GitHub repo too, so PRs are welcome!
s/o @jonas-bk.bsky.social
The docs got a fresh new look and live at bloodhound.specterops.io — now back in the GitHub repo too, so PRs are welcome!
s/o @jonas-bk.bsky.social
Tired of the old 'Enable SMB signing everywhere' rec that isn't actually practical? BloodHound can help you convert that massive IT project into a doable risk mitigation effort, focused on those systems truly vulnerable to relay attacks.
🧵: 1/2
Tired of the old 'Enable SMB signing everywhere' rec that isn't actually practical? BloodHound can help you convert that massive IT project into a doable risk mitigation effort, focused on those systems truly vulnerable to relay attacks.
🧵: 1/2
We commonly see Domain Admins peppered across Organizational Units. This can degrade your security posture by making Group Policy enforcement hard to understand or audit.
BloodHound helps by visualizing BOTH the OU placement AND group membership.
🧵 1/2
We commonly see Domain Admins peppered across Organizational Units. This can degrade your security posture by making Group Policy enforcement hard to understand or audit.
BloodHound helps by visualizing BOTH the OU placement AND group membership.
🧵 1/2
Looking for new Attack Paths to the domain? 🔎
BH v6.3 introduces CoerceToTGT.
The edge connects principals w/ unconstrained delegation to the domain, as attackers can use those to coerce privileged computers & retrieve their TGT.
Looking for new Attack Paths to the domain? 🔎
BH v6.3 introduces CoerceToTGT.
The edge connects principals w/ unconstrained delegation to the domain, as attackers can use those to coerce privileged computers & retrieve their TGT.
Want to see attack paths in your own environment? Install BloodHound CE with three commands:
1️⃣ wget ghst.ly/3NTWRmY
2️⃣ tar -xvzf bloodhound-cli-linux-amd64.tar.gz
3️⃣ ./bloodhound-cli install
More info here: ghst.ly/3NMjhqn
Want to see attack paths in your own environment? Install BloodHound CE with three commands:
1️⃣ wget ghst.ly/3NTWRmY
2️⃣ tar -xvzf bloodhound-cli-linux-amd64.tar.gz
3️⃣ ./bloodhound-cli install
More info here: ghst.ly/3NMjhqn
Easily RETURN computers, users, and certificate templates created in the last X days where X can match anything you want. In this case we are looking for objects created in the last 365 days.
🧵: 1/3
Easily RETURN computers, users, and certificate templates created in the last X days where X can match anything you want. In this case we are looking for objects created in the last 365 days.
🧵: 1/3
With next week's release, all BloodHound CE/E users will be able to go back or forward, AND share the current view with their team members, right from the browser buttons!
s/o Stephen Hinck
With next week's release, all BloodHound CE/E users will be able to go back or forward, AND share the current view with their team members, right from the browser buttons!
s/o Stephen Hinck
In BloodHound Enterprise, CanRDP normally means:
"If I compromise this user, I can RDP directly to this machine and land inside Windows."
But Citrix changes what "RDP access" actually means.
🧵: 1/4
In BloodHound Enterprise, CanRDP normally means:
"If I compromise this user, I can RDP directly to this machine and land inside Windows."
But Citrix changes what "RDP access" actually means.
🧵: 1/4
Q: Why is not just the DA group Tier Zero but also all members?
A: BloodHound classifies a few default Tier Zero assets, then adds more w/ logic from known attack techniques.
1/8
Q: Why is not just the DA group Tier Zero but also all members?
A: BloodHound classifies a few default Tier Zero assets, then adds more w/ logic from known attack techniques.
1/8
Let's talk Tier 0 inheritance. If you're trying to unravel why some of the objects in your environment show up as Tier 0, this query will demonstrate the nuances of inheritance in 2 ways: inheritance up w/ OUs, & inheritance down w/ Groups.
🧵 1/3
Let's talk Tier 0 inheritance. If you're trying to unravel why some of the objects in your environment show up as Tier 0, this query will demonstrate the nuances of inheritance in 2 ways: inheritance up w/ OUs, & inheritance down w/ Groups.
🧵 1/3
Did you know that cypher supports regular expressions? A common use for this is to perform a case-insensitive query. For example, the query shown will return users with a SAMAccountName of "Guest" or "guest".
s/o Jacob Julian
Did you know that cypher supports regular expressions? A common use for this is to perform a case-insensitive query. For example, the query shown will return users with a SAMAccountName of "Guest" or "guest".
s/o Jacob Julian
DYK that BloodHound CE now supports deep linking? This week, we released early access support that goes beyond what the old back button offered! Go back (& forward), & share your current view of the graph w/ your fellow operators today!
1/2
DYK that BloodHound CE now supports deep linking? This week, we released early access support that goes beyond what the old back button offered! Go back (& forward), & share your current view of the graph w/ your fellow operators today!
1/2
You've successfully compromised Bob in marketing's account in an engagement. Mark it as Owned by right-clicking ➡️ "Add to Owned" ➡️ run the query "Shortest Paths from Owned objects to Tier Zero" & see your new attack paths!
(1/2)
You've successfully compromised Bob in marketing's account in an engagement. Mark it as Owned by right-clicking ➡️ "Add to Owned" ➡️ run the query "Shortest Paths from Owned objects to Tier Zero" & see your new attack paths!
(1/2)
Did you know BloodHound started with just 3 node types and a few edges? Today, it supports 36 node types and 113 edge types, uncovering a vast array of attack paths.
Explore more in our docs ➡️ ghst.ly/3WSKoS7
s/o @jonas-bk.bsky.social
Did you know BloodHound started with just 3 node types and a few edges? Today, it supports 36 node types and 113 edge types, uncovering a vast array of attack paths.
Explore more in our docs ➡️ ghst.ly/3WSKoS7
s/o @jonas-bk.bsky.social
Don't let hybrid Attack Paths compromise your privileged roles. Take action and remove these by using cloud-only accounts and shut down the attackers access with BloodHound.
🧵 1/4
Don't let hybrid Attack Paths compromise your privileged roles. Take action and remove these by using cloud-only accounts and shut down the attackers access with BloodHound.
🧵 1/4
In Active Directory, the creator of an object (user, computer, group, ...) becomes the object's owner.
What can an owner do? By default, the owner can compromise the created object.
🧵: 1/4
In Active Directory, the creator of an object (user, computer, group, ...) becomes the object's owner.
What can an owner do? By default, the owner can compromise the created object.
🧵: 1/4
This week's 🔥 topic from @martinsohn.dk: the Microsoft-wont-fix-yet "BadSuccessor" attack that abuses Server 2025's dMSA feature for domain takeover.
This 🧵 shows how you can use BloodHound to find BadSuccessor risk.
(1/9)
This week's 🔥 topic from @martinsohn.dk: the Microsoft-wont-fix-yet "BadSuccessor" attack that abuses Server 2025's dMSA feature for domain takeover.
This 🧵 shows how you can use BloodHound to find BadSuccessor risk.
(1/9)
The ability for a principal to reset the password of a user w/o knowing the password of that user can be powerful! Cypher can be used to map out paths from groups to users w/ this ability:
MATCH p=(n:Group)-[:ForceChangePassword]->(m:User)
RETURN p
s/o Jacob Julian
The ability for a principal to reset the password of a user w/o knowing the password of that user can be powerful! Cypher can be used to map out paths from groups to users w/ this ability:
MATCH p=(n:Group)-[:ForceChangePassword]->(m:User)
RETURN p
s/o Jacob Julian
Ever wondered about those obscure AD special identity groups that quietly grant permissions to every principal in your environment?
With BloodHound, you can uncover compromising permissions tied to these groups.
🧵: 1/2
Ever wondered about those obscure AD special identity groups that quietly grant permissions to every principal in your environment?
With BloodHound, you can uncover compromising permissions tied to these groups.
🧵: 1/2
Ready to take your #BloodHound skills to the next level?
Head over to the SpecterOps Tradecraft Academy and dive into our free BloodHound Basics Workshop.
(1/4)
Ready to take your #BloodHound skills to the next level?
Head over to the SpecterOps Tradecraft Academy and dive into our free BloodHound Basics Workshop.
(1/4)
Have you checked out the new Privilege Zone Management feature in BloodHound? Now you can get much more granular with selecting what's going into your privilege zones (tiers) using selectors.
Have you checked out the new Privilege Zone Management feature in BloodHound? Now you can get much more granular with selecting what's going into your privilege zones (tiers) using selectors.