tier-zero-audit

Audit Tier Zero asset group membership and detect access drift in Bloodhound Enterprise.

11|1|Updated May 4, 2026
One-click install
npx skills add https://github.com/dreadnode/capabilities --skill tier-zero-audit
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: tier-zero-audit
Source: https://github.com/dreadnode/capabilities/tree/main/capabilities/bloodhound-enterprise/skills/tier-zero-audit
Command: npx skills add https://github.com/dreadnode/capabilities --skill tier-zero-audit

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Unvalidated drift in Bloodhound Enterprise's Tier Zero asset group creates unmonitored high-privilege access points, allowing unvetted principals to become part of critical attack paths and increasing organizational breach risk.

Core Features & Use Cases

  • Tier Zero Membership Audit: Enumerate all members of the Tier Zero asset group, including their inclusion selectors and certification status.
  • Drift Detection: Identify unvetted additions to Tier Zero, such as stale service accounts, obsolete OUs, or misclassified groups that no longer require high-value access.
  • Certification Management: Recommend certifications for legitimate Tier Zero members and flag drift for human-approved revocation, with full audit history review for change tracking.
  • Use Case: After a domain migration, use this skill to catch legacy computer objects incorrectly added to Tier Zero and certify new service accounts with required admin access to domain controllers.

Quick Start

Ask the AI to perform a Tier Zero audit in your Bloodhound Enterprise deployment to get a full drift report and actionable certification recommendations.

Frequently Asked Questions about tier-zero-audit

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I detect access drift in Bloodhound Enterprise Tier Zero asset groups?

Audit Tier Zero membership via Bloodhound Enterprise API calls to enumerate inclusion selectors, validate certification status, and identify unvetted additions like stale service accounts or misclassified groups creating unmonitored attack paths.

What is Tier Zero access drift and why does it increase breach risk?

Tier Zero access drift occurs when unvalidated changes add unvetted principals to critical asset groups, creating unmonitored attack paths. This increases organizational breach risk by allowing stale accounts into high-privilege access positions.

Can I automate certification recommendations for Tier Zero members?

Yes, auditing Tier Zero members generates certification recommendations for legitimate principals while flagging drift for human-approved revocation, tracking changes by reviewing full audit logs via Bloodhound Enterprise API calls.

How do I audit Tier Zero members after a domain migration?

Perform a Tier Zero audit to enumerate members and catch legacy computer objects incorrectly added during migration, while validating new service accounts requiring domain controller admin access and reviewing recent change history.

Does the Tier Zero audit review change history for high-value asset groups?

Yes, the audit reviews recent change history and full audit logs for Tier Zero asset group inclusions. This validates selector logic, tracks modifications, and flags unvetted additions for human-approved revocation.