BloodHound is an open-source post-exploitation and security assessment tool used to map relationships, privileges, and attack paths in Active Directory, Microsoft Entra ID, and Azure environments. It is primarily a graph-based visualization platform that ingests directory and identity data collected by companion ingestors such as SharpHound for on-premises Active Directory and AzureHound for cloud environments. In enterprise Windows domains, it can enumerate domain users, computers, domain controllers, administrative groups, trust relationships, and user session information to identify privilege escalation and lateral movement opportunities. In cloud and hybrid environments, the broader BloodHound suite can enumerate identities, groups, roles, applications, subscriptions, storage resources, and other infrastructure relationships to expose escalation paths across Entra ID and Azure.
BloodHound is widely used by penetration testers, red teams, and defenders for attack-path analysis, but it is also regularly used by threat actors after initial compromise. Intrusion reporting has associated its use with ransomware and espionage operations, where operators leveraged it to map Active Directory, identify domain administrator accounts, discover trust relationships, and support follow-on actions such as Kerberoasting, privilege escalation, and lateral movement. Public reporting has linked use of BloodHound or its related collectors to activity involving Russian state-sponsored actors targeting cleared defense contractors, ransomware-linked intrusions including the Capita breach, and multiple other post-compromise operations. AzureHound, part of the same suite, has also been reported in cloud-focused intrusions involving actors such as Curious Serpens, Void Blizzard, and Storm-0501.
On Windows networks, BloodHound collection has been observed via PowerShell-based SharpHound execution as well as .NET API and LDAP-based collection methods. Because it is a dual-use tool rather than malware purpose-built for covert persistence or destructive action, its presence alone does not prove malicious activity; however, in the context of unauthorized access it is a high-value reconnaissance utility that materially improves an adversary’s ability to understand identity relationships and plan privilege escalation and lateral movement.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Prominent among the other tools used by Twelve are Cobalt Strike, Mimikatz, Chisel, BloodHound, PowerView, adPEAS, CrackMapExec, Advanced IP Scanner, and PsExec for credential theft, discovery, network mapping, and privilege escalation.
During an intrusion, tools such as Cobalt Strike, PowerShell Empire, Bloodhound, PSExec... are used for network discovery and traversal, privilege escalation, staging, and ransomware deployment.
"SharpHound... for BloodHound (an open-source Active Directory analysis tool used to identify attack paths in AD environments)."
...UNC2447 has been observed using the following tools: ADFIND, BLOODHOUND...
15 distinct techniques documented for this family, organized by ATT&CK tactic.
BloodHound can use PowerShell to pull Active Directory information from the target environment.
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
For target finding, I recommend using AzureHound, the Azure component to BloodHound.
You then analyze the graph for Abusable Access Control Lists (ACLs), such as WriteDacl, GenericAll, or ForceChangePassword over higher-privileged groups like Domain Admins.
higher-privileged groups like Domain Admins or Exchange Windows Permissions. | When you learn to abuse WriteDacl permissions to add yourself to the Domain Admins group on a Medium Hack The Box machine, you are practicing the exact kill chain used in real-world corporate breaches.
Stealth Falcon malware uses PowerShell commands to perform various functions, including gathering system information via WMI...
ADFind, SharpView, and BloodHound are used for Active Directory enumeration.
60 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Active Directory enumeration tool discussed as part of possible lateral movement and privilege-mapping activity inside the compromised environment.
Referenced through detection names indicating use or testing of Active Directory discovery and attack-path mapping capabilities within the broader framework.
An Active Directory reconnaissance and attack-path mapping tool referenced via detections tied to this threat activity.
Explicitly described as a tool for Active Directory mapping used during intrusions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.