One-click install
npx skills add https://github.com/dreadnode/capabilities --skill exposure-trending
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: exposure-trending
Source: https://github.com/dreadnode/capabilities/tree/main/capabilities/bloodhound-enterprise/skills/exposure-trending
Command: npx skills add https://github.com/dreadnode/capabilities --skill exposure-trending

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Security teams using BloodHound Enterprise struggle to quantify how their Active Directory exposure posture changes over time, and to identify which specific findings or events drove those changes without manually sifting through weeks of historical data.

Core Features & Use Cases

  • Exposure Delta Reporting: Calculates the change in overall exposure index, Tier Zero principal count, and critical risk finding count between two user-specified time windows.
  • Root Cause Attribution: Identifies which attack path categories improved or regressed, and explains the drivers behind changes (e.g., remediation work, risk acceptance expiration, Tier Zero membership growth, or data ingest failures).
  • Use Case: At the close of a remediation sprint, use this skill to generate a concise stakeholder report that proves exactly which risks were fixed and which new risks emerged, instead of manually comparing two separate BHE posture snapshots.

Quick Start

Use the exposure-trending skill to generate a 30-day exposure delta report for your BloodHound Enterprise deployment, highlighting the top movers and root causes for posture changes.

Frequently Asked Questions about exposure-trending

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I measure Active Directory exposure trends between two time periods?

Active Directory exposure trends are measured by generating delta reports that compare BloodHound Enterprise posture snapshots between two user-specified time windows. This calculates changes in exposure index, Tier Zero principal count, and critical risk findings without manual data correlation.

What is the best way to quantify post-remediation posture changes in BloodHound Enterprise?

Post-remediation posture changes are quantified by comparing exposure delta reports across two time windows. This attributes exposure fluctuations to specific root causes like finding remediation, risk acceptance expiration, or Tier Zero membership growth instead of manually sifting through historical data.

Can I attribute Active Directory exposure changes to specific root causes automatically?

Yes, Active Directory exposure changes are automatically attributed to root causes such as finding remediation, risk acceptance expiration, Tier Zero membership growth, or data ingest failures. This eliminates the need to manually correlate separate posture snapshots to identify drivers behind posture shifts.

Does exposure-trending work for periodic posture reviews in Active Directory environments?

Yes, exposure-trending works for periodic posture reviews in Active Directory environments. It generates delta reports comparing BloodHound Enterprise exposure posture between user-specified time windows to support security operations, incident response trend analysis, and remediation sprint reporting.

How do I generate a stakeholder report proving which Active Directory risks were fixed?

Stakeholder reports proving which risks were fixed are generated by calculating exposure deltas between two time windows. The report highlights top movers and explains posture change drivers, proving exactly which risks were remediated and which new risks emerged.

Why does my BloodHound Enterprise exposure index fluctuate without obvious remediation work?

BloodHound Enterprise exposure index fluctuations occur due to risk acceptance expiration, Tier Zero membership growth, or data ingest failures. Delta reporting identifies these specific root cause drivers behind posture changes between two time windows automatically.