Skip to content

BloodHound

BloodHound turns flat AD enumeration into a relationship graph: nodes (users, groups, computers, OUs, GPOs, domains) joined by edges representing permissions and relationships (MemberOf, AdminTo, HasSession, GenericAll, CanRDP, Owns…). Over that graph, one query answers the question that’s nearly impossible by hand: “what’s the shortest path from the account I control to Domain Admin?”. It converts thousands of scattered ACLs into a concrete attack path.

What BloodHound exploits isn’t a bug: it’s accumulated complexity. A real AD holds tens of thousands of delegated permissions, nested groups, and active sessions nobody audits together. Individually harmless relationships, chained, form a route to DA the defense team never sees because they never look at it as a graph. The attacker does.

  • Collectors (SharpHound): traverse the domain via LDAP, SMB, and sessions, producing JSON.
  • Interface (BloodHound): loads the JSON into a Neo4j database and lets you query/visualize paths.
  • Two flavors: BloodHound Community Edition (new, web, bloodhound.py/SharpHound collector) and legacy (Electron). Edges and logic are equivalent.
# from Windows (executable or in-memory DLL)
SharpHound.exe -c All --zipfilename out
# from Linux with credentials (without touching a Windows host)
bloodhound-python -u user -p pass -d domain.local -ns <DC_IP> -c All
# collection methods: Session, LoggedOn, ACL, Trusts, Group, LocalAdmin...

-c All collects ACLs, sessions, local admins, trusts, and GPOs. For stealth, --stealth or selective methods (fewer queries, less noise).

Load the ZIP and mark your starting node as Owned. Key queries:

  • “Shortest Path to Domain Admins” from your owned user/host → the direct route.
  • Kerberoastable / ASREProastable users → roasting targets (see Kerberos Attacks).
  • Unconstrained/constrained delegation → see ad-delegation.
  • Dangerous ACLs: GenericAll, WriteDacl, WriteOwner, ForceChangePassword, AddMember over privileged objects.
  • Sessions of privileged users on hosts you already control (HasSession) → credential theft there.
  • Where can my owned principals RDP / PSRemote; Computers where Domain Users are local admin.
MemberOf -> you inherit the group's permissions
AdminTo -> local admin on that computer (execution, dump)
HasSession -> that user's credentials are on that host
GenericAll -> full control of the object (reset pass, add member, RBCD)
WriteDacl -> grant yourself permissions over the object
ForceChangePassword -> change the user's password without the old one
Owns / WriteOwner -> become owner and rewrite the DACL
AllowedToDelegate -> exploitable constrained delegation
  • SharpHound / bloodhound.py — collectors (Windows / Linux).
  • BloodHound CE / AzureHound (for Entra ID / Azure AD).
  • Cypher (Neo4j language) for custom queries over the graph.
  • PlumHound, GoodHound — prioritized reporting over BloodHound data.

From “I have some account” to “I know exactly which 3 steps lead me to Domain Admin.” BloodHound doesn’t exploit by itself, but it plans the whole attack and reveals routes no human would find by hand.

  • SharpHound generates mass LDAP queries and SMB connections in a short time from a workstation → detectable pattern (event 4662, LDAP spikes, \\host\IPC$ to many computers for sessions).
  • Session enumeration (NetSessionEnum/NetWkstaUserEnum) against many hosts.
  • Execution of the SharpHound binary/DLL (signatures, Sysmon image load).
  • Fine LDAP auditing (4662) and network-logon auditing; alert on query volume per account.
  • Restrict anonymous/user NetSessionEnum (key: denies SharpHound the HasSession edge).
  • Honeytokens: “juicy” accounts that, appearing in a path and being touched, raise alerts.
  • The best control is deleting edges: audit and remove dangerous ACLs, flatten nested groups, strip local admin from domain users.
  • Implement tiering / PAW (Tier 0 admins never log on to workstations) → cuts HasSession routes.
  • Run BloodHound yourself periodically as a defensive tool: measure and reduce the paths to DA.
  • LAPS, gMSA, Protected Users, and cleanup of privileged memberships.

If you detect collection, assume the attacker already has the map: prioritize closing the short routes to DA (reset accounts in the path, remove the abusable ACLs) over chasing only the source host.

  • BloodHound isn’t a CVE: it’s methodology. It appears in ransomware reports (leaked Conti playbook, LockBit, BlackCat) as the standard pre-DA mapping tool.
  • MITRE ATT&CK: T1087 (account discovery), T1069 (groups), T1482 (trusts), T1018 (remote systems).
  • The BloodHound team (SpecterOps) documents real paths and their mitigation; the basis of the “Attack Path Management” discipline.
  • Collect with -c All (SharpHound or bloodhound.py) without errors
  • Mark owned nodes and import the ZIP
  • “Shortest Path to Domain Admins” from your principal
  • Kerberoastable / ASREProastable users
  • Dangerous ACLs (GenericAll/WriteDacl/ForceChangePassword) to privileged objects
  • Delegations (unconstrained/constrained/RBCD)
  • Privileged users’ sessions on controllable hosts
  • Custom Cypher queries for non-obvious paths