BloodHound is a dual-use security analysis and visualization tool, not a malware family. It maps relationships in Microsoft Active Directory, Entra ID, and Azure environments to identify attack paths and potentially exploitable access relationships. Its discovery capabilities include enumerating domain computers and domain controllers, collecting domain-user information, identifying domain administrator accounts, gathering user-session information, and examining domain trusts.
BloodHound uses collection components including SharpHound, which retrieves Active Directory information through .NET APIs; PowerShell-based collection is also supported. AzureHound extends the suite to cloud environments, collecting identity, group, role, application, storage, and infrastructure information through Microsoft Graph and Azure REST APIs. AzureHound is available for Windows, Linux, and macOS, and its output can be ingested into BloodHound for attack-path analysis.
Adversaries use BloodHound after obtaining access to map enterprise environments and identify opportunities for privilege escalation and lateral movement. Documented users include Chimera, OPERA1ER, LockBit affiliates, Akira affiliates, and Russian state-sponsored actors targeting U.S. cleared defense contractors. SharpHound has also appeared in GootLoader-associated infection chains. These malicious uses repurpose legitimate reconnaissance functionality; they do not make BloodHound itself a credential stealer or ransomware payload.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Chimera has obtained and used tools such as BloodHound, Cobalt Strike, Mimikatz, and PsExec.
Enables identification of AD relationships that can be exploited to gain access onto a victim’s network.
They deploy AdFind, SharpHound (a component of BloodHound), and PCHunter to map the Active Directory (AD) structure.
“They used BloodHound to collect more details on the active directory environment in order to identify the attack path on the domain.”
Prominent among the other tools used by Twelve are Cobalt Strike, Mimikatz, Chisel, BloodHound, PowerView, adPEAS, CrackMapExec, Advanced IP Scanner, and PsExec for credential theft, discovery, network mapping, and privilege escalation.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
“ENDPOINT_ENUMERATION alerts” and “SAMR enumeration across many different endpoints, including Finance, HR, factory and POS systems.”
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
For target finding, I recommend using AzureHound, the Azure component to BloodHound.
Énumération du domaine AD (droits utilisateur) via le collecteur BloodHound de NetExec.
Discovery (e.g. BloodHound) ... T1069.001, T1069.002 Enumeration of local administrators
Discovery (e.g. BloodHound) T1087.001, T1087.002, T1106, T1069.001, T1069.002
Stealth Falcon malware uses PowerShell commands to perform various functions, including gathering system information via WMI...
After gaining access to networks, the threat actors used BloodHound to map the Active Directory.
"BloodHound uses graph theory to reveal the hidden and often unintended relationships within an Active Directory or Azure environment. Attackers can use BloodHound to easily identify highly complex attack paths"
Discovery (e.g. BloodHound) T1087.001, T1087.002, T1106, T1069.001, T1069.002
The group will seek out domain administrator privileges ... or they will seek out “potentially interesting people” within an organization’s AD.
“ROADrecon's gather command uses aiohttp by default and walks every directory object type” and produces “Bulk enumeration across every object type ROADrecon knows.”
69 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Active Directory enumeration tool discussed as part of possible lateral movement and privilege-mapping activity inside the compromised environment.
Referenced through detection names indicating use or testing of Active Directory discovery and attack-path mapping capabilities within the broader framework.
An Active Directory reconnaissance and attack-path mapping tool referenced via detections tied to this threat activity.
Explicitly described as a tool for Active Directory mapping used during intrusions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.