BloodHound
14
11
13.05.2026
26.08.2026
Profil laut MITRE ATT&CK
BloodHound is an Active Directory (AD) reconnaissance tool that can reveal hidden relationships and identify attack paths within an AD environment.
Vollständiges MITRE-ProfilBeschreibung und Alias-Namen stammen aus MITRE ATT&CK®.
Nennungen im Zeitverlauf
Meldungen je Monat, letzte 12 Monate.
Beobachtete Techniken
ATT&CK-Techniken, die in denselben Meldungen benannt sind — nicht das vollständige MITRE-Repertoire.
T1059.006 Python
Execution
T1003.006 DCSync
Credential Access
T1589.001 Credentials
Reconnaissance
T1566 Phishing
Initial Access
T1589.002 Email Addresses
Reconnaissance
T1003 OS Credential Dumping
Credential Access
T1018 Remote System Discovery
Discovery
T1021.001 Remote Desktop Protocol
Lateral Movement
T1021.004 SSH
Lateral Movement
T1033 System Owner/User Discovery
Discovery
T1056.001 Keylogging
Credential Access · Collection
T1059.001 PowerShell
Execution
Gemeinsam genannt
Betroffene Branchen
Meldungen
CISA red team assessments expose critical infrastructure gaps in threat detection, response and OT security
A Tale of Two SOCs: Insights From Two Red Team Assessments
NoiseHound — Detection-aware BloodHound attack-path scoring - find the quietest route to your objective, calibrated across audit/EDR/SIEM tiers.
MovementHound — PowerShell tool for active minimal-rights lateral movement enumeration, extending BloodHound Legacy
adhammer — Active Directory security-assessment toolkit in Rust — PingCastle-class audit + authorized red-team validation, on a from-scratch DCE/RPC · NTLM · SMB2 · Kerberos stack. One static binary, from Kali or Windows.
ForceHound — Salesforce identity and permission graph collector for BloodHound CE. Maps users, profiles, permission sets, roles, groups, sharing rules, connected apps, and field-level security into attack-path graphs.
AgentHound — Offensive security framework for AI agent infrastructure - recon, credential looting, model exfiltration, poisoning, and attack-path analysis across MCP, A2A, gateways, and AI services. BloodHound for the agentic stack.
RootHound — Map your path from a low-priv shell to root — like BloodHound, for local Linux privesc.
ghosthound — GhostHound is a BloodHound OpenGraph extension that surfaces Active Directory tombstone reanimation as a first-class attack path, enumerating deleted objects via SHOW_DELETED, mapping who can restore them, and revealing when a reanimated identity regains privileged group membership.
AD-PathFinder — Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data.
AIHound — Credential Scanner for Popular Desktop AI Platforms
adscan — Active Directory pentesting tool for Linux. Automated Kerberoasting, AS-REP Roasting, ADCS/ESC exploitation, DCSync, BloodHound integration, and 40+ AD attack paths. ENS Alto / NIS2 / ISO 27001 compliance reports. No Windows required.
SteppingStones — A Red Team Activity Hub
linWinPwn — linWinPwn is a bash script that streamlines the use of a number of Active Directory tools
Quellen: GitHub Trending (12), Industrial Cyber (1), CISA Alerts (1)
Alle Angaben auf dieser Seite stammen aus dem Alias-Abgleich der Meldungstexte gegen den MITRE-ATT&CK-Katalog. Beziehungen entstehen rein statistisch: Zwei Einträge gelten als verbunden, wenn sie in derselben Meldung benannt sind. Das ist keine eigenständige Attribution durch SecBoard, und eine Nennung ist kein Nachweis einer Täterschaft.