What problem does it solve?
Manually mapping Active Directory attack paths, identifying privilege escalation routes, and assessing domain security posture is extremely time-consuming and error-prone in large enterprise environments with thousands of objects and complex trust relationships.
Core Features & Use Cases
- Graph Database Access: Connect to BloodHound CE and Neo4j instances to query the full Active Directory graph data.
- Pre-built Attack Path Queries: Run standard queries for common analysis tasks including finding domain admins, Kerberoastable users, unconstrained delegation paths, and vulnerable ADCS templates.
- Custom Query Support: Execute arbitrary Cypher queries for specialized analysis not covered by the pre-built catalog.
- Reference Documentation: Access built-in guides for edge abuse steps, OPSEC notes, and node properties to interpret query results correctly.
- Use Case: A red teamer can use this skill to quickly identify the shortest path from a compromised low-privilege user to domain admin, while a security administrator can use it to audit AD hygiene and find high-risk misconfigurations like computers with SMB signing disabled or WebClient enabled.
Quick Start
Use the bloodhound skill to analyze Active Directory attack paths and domain security posture for your target environment after authenticating to your BloodHound and Neo4j instances.