attack-path-triage

Prioritize BloodHound Enterprise attack-path findings by severity and blast radius.

11|1|Updated May 4, 2026
One-click install
npx skills add https://github.com/dreadnode/capabilities --skill attack-path-triage
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: attack-path-triage
Source: https://github.com/dreadnode/capabilities/tree/main/capabilities/bloodhound-enterprise/skills/attack-path-triage
Command: npx skills add https://github.com/dreadnode/capabilities --skill attack-path-triage

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

BloodHound Enterprise generates high volumes of active attack-path findings across multi-domain Active Directory environments, making it difficult for security teams to quickly identify the highest-risk issues that require immediate remediation, leading to wasted triage time and unaddressed critical vulnerabilities.

Core Features & Use Cases

  • Automated Finding Prioritization: Ranks active attack-path findings by severity, principal blast radius, and recency to surface the most impactful issues first.
  • Accepted Risk Filtering: Automatically excludes findings marked as accepted risks to avoid redundant triage work, while still providing an auditable list of exempted items.
  • Concrete Remediation Guidance: Drills into individual findings to map attack paths and provide specific, actionable remediation steps for each high-priority issue.
  • Use Case: A security team managing a 5-domain AD environment with 1,200 active BHE attack-path findings can use this skill to generate a prioritized list of the top 25 most critical issues to address in their next remediation cycle, cutting triage time from hours to minutes.

Quick Start

Use the attack-path-triage skill to generate a ranked list of the highest-priority BloodHound Enterprise attack path findings to remediate first.

Frequently Asked Questions about attack-path-triage

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I prioritize BloodHound Enterprise attack path findings for remediation?

Prioritize BloodHound Enterprise attack path findings by ranking them based on severity, principal blast radius, and recency while excluding accepted risks to produce a capped action list. This filters high volumes of active findings to surface the highest-risk issues first.

What is the best way to triage a large volume of active directory attack paths?

Triage active directory attack paths by filtering findings across multi-domain environments using severity, blast radius, and recency. This approach identifies critical issues requiring immediate remediation and generates concrete recommendations with supporting evidence for each finding.

Can I filter out accepted risks when triaging BloodHound Enterprise findings?

Yes, you can filter out accepted risks when triaging BloodHound Enterprise findings to avoid redundant work. The triage process automatically excludes findings marked as accepted risks while still providing an auditable list of exempted items for compliance tracking.

How do I get concrete remediation steps for high-priority active directory attack paths?

To get concrete remediation steps for active directory attack paths, drill into individual findings to map the attack path. This generates specific, actionable remediation recommendations and supporting evidence tailored to each high-priority issue identified during triage.

Does attack path triage work for multi-domain Active Directory environments?

Yes, attack path triage works for multi-domain Active Directory environments by processing large volumes of BloodHound Enterprise findings. It scales to handle environments with multiple domains, cutting triage time from hours to minutes for security teams.