Blood Hound
Discover hidden and often unintended relationships in Active Directory using graph theory.
Open the official app on bloodhound.readthedocs.io
This tool is hosted by its maintainers. Click below to open bloodhound.readthedocs.io in a new tab — it's their official demo.
Browse security tools →What's next with Blood Hound?
Choose how you want to get started.
Use it free
Open the official tool or demo — no account needed.
Self-host it
Run the open-source version on your own infrastructure.
What is Blood Hound?
BloodHound is an open-source tool designed to analyze and visualize complex relationships within Active Directory and Azure Active Directory environments. It focuses on identifying potential paths to domain administration by leveraging graph theory to map access and identity relationships. Cybersecurity professionals, penetration testers, and red-hat teams use BloodHound to uncover hidden administrative privileges and vulnerabilities in enterprise networks. The tool addresses the challenge of navigating intricate permission structures by transforming raw data into intuitive visualizations, enabling users to assess risks and plan exploitation strategies effectively.
How it works
BloodHound is a monolithic web application combining a React frontend with Sigma.js for graph visualization and a Go-based REST API backend. It integrates with PostgreSQL for relational data storage and Neo4j for graph database operations. The tool's primary purpose is to analyze identity and access management systems, revealing indirect relationships between users, groups, and permissions that may not be immediately apparent. This helps identify potential attack vectors, such as privilege escalation paths to domain admin accounts. BloodHound uses graph theory to model relationships from data collected by SharpHound and AzureHound. It visualizes connections between users, groups, and permissions, highlighting indirect administrative access. For example, it can map how a low-privilege user might gain domain admin access through chained group memberships.
How to use it
- 1Deploy BloodHound with PostgreSQL and Neo4j databases configured for data storage and graph processing. 2. Use SharpHound or AzureHound to collect domain information via PowerShell or Azure CLI. 3. Feed the collected data into BloodHound's REST API to populate the Neo4j graph database. 4. Access the frontend to visualize and analyze relationships through interactive graph nodes and edges. Practical tips include running SharpHound with elevated privileges to capture comprehensive data and configuring Neo4j for optimal performance with large datasets.
What it can do
- active directory attack paths
Use cases
Assumptions and limitations
Assumptions
- source: https://github.com/SpecterOps/BloodHound
- license: GPL-3.0 — free to use
- privacy: Self-hosted — you control your data
Limitations
- Offensive tool — authorized penetration testing and lab use only; unauthorized use is illegal.
- Dependent on SharpHound/AzureHound for data collection, which requires elevated privileges
- Complex setup involving multiple databases and dependencies
- Potential for false positives in relationship mapping without manual validation
- Limited support for non-Microsoft identity systems
Understanding the result
Discover hidden and often unintended relationships in Active Directory using graph theory.
Tool details
- Clearly flagged when a network request is needed.
- No account, no sign-up, and no tracking of your content.
- Powered by (GPL-3.0).
- Built with
- (SpecterOps/BloodHound)
- License
- GPL-3.0
- Runs locally
- No — requires a network request
- Verification
- Not yet verified
- Input
- Query
- Output
- Text
Built with SpecterOps/BloodHound. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.
- Built with
- License
- GPL-3.0
Open-source project
OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.
References
- / — GitHub Repository
Upstream project · GitHub
- GPL-3.0 License
Upstream project
Frequently asked
How does BloodHound analyze domain administration paths?
BloodHound uses graph theory to model relationships between users, groups, and permissions. By importing data from SharpHound or AzureHound, it creates a Neo4j graph database where nodes represent entities and edges represent access relationships. The tool then identifies potential paths to domain admin by analyzing connectivity patterns, such as group memberships or Kerberos delegation, that could enable privilege escalation.
How does BloodHound handle data from different sources?
BloodHound integrates with SharpHound and AzureHound to collect data from Active Directory and Azure AD. SharpHound gathers information via PowerShell scripts, while AzureHound uses Azure CLI. The collected data is formatted into a structured JSON format and fed into BloodHound's REST API, which processes it into a Neo4j graph database. This allows BloodHound to unify disparate data sources into a cohesive visualization.
How do I collect data for BloodHound?
To collect data, run SharpHound on a domain-joined machine with administrative privileges using the command: `Invoke-SharpHound -OutputFormat json`. For Azure AD, use AzureHound with the Azure CLI to gather data. Save the output files and upload them to BloodHound's REST API endpoint to populate the graph database.
How does BloodHound compare to AttackGraph?
BloodHound focuses on visualizing existing relationships in identity systems to identify potential attack paths, while AttackGraph generates hypothetical attack scenarios based on system configurations. BloodHound is more suited for analyzing real-world access structures, whereas AttackGraph emphasizes simulating adversarial behavior. Both tools complement each other in penetration testing workflows.
What should I do if BloodHound fails to load data?
If BloodHound cannot load data, verify that the input JSON files are correctly formatted and match the expected schema. Check Neo4j logs for errors during data ingestion and ensure the PostgreSQL database is properly configured. If SharpHound/AzureHound data collection fails, review the execution environment for missing dependencies or permission issues.