# SpecterOps: BloodHound

## BloodHound

- [BloodHound / OpenGraph (338 pages)](https://bloodhound.specterops.io/_llms/blood-hound/open-graph.md): Documentation for BloodHound / OpenGraph.

### Get Started with BloodHound

- [Introduction to BloodHound](https://bloodhound.specterops.io/get-started/introduction.md)
- [BloodHound Community Edition Custom Installation](https://bloodhound.specterops.io/get-started/custom-installation.md): Learn how to install and customize BloodHound Community Edition (BHCE).
- [Upgrade PostgreSQL](https://bloodhound.specterops.io/get-started/upgrade-postgres.md): Migrate BloodHound Community Edition from PostgreSQL 16 to 18.

#### Quickstart

- [BloodHound Enterprise Quickstart](https://bloodhound.specterops.io/get-started/quickstart/enterprise-quickstart.md)
- [BloodHound Community Edition Quickstart](https://bloodhound.specterops.io/get-started/quickstart/community-edition-quickstart.md): Set up a local instance of BloodHound Community Edition and start identifying and visualizing security risks in your environment.
- [BloodHound Community Edition Sample Data](https://bloodhound.specterops.io/get-started/quickstart/ce-ingest-sample-data.md)

#### Security Boundaries

- [BloodHound Enterprise Security Overview](https://bloodhound.specterops.io/get-started/security-boundaries/enterprise-security-overview.md)
- [Tier Zero: Members and Modification](https://bloodhound.specterops.io/get-started/security-boundaries/tier-zero-members.md)

### Install a Data Collector

- [Install Data Collectors](https://bloodhound.specterops.io/install-data-collector/overview.md)

#### Install SharpHound

- [Deploy SharpHound Enterprise](https://bloodhound.specterops.io/install-data-collector/install-sharphound/overview.md): Deploy and maintain SharpHound Enterprise for continuous automatic collection of Active Directory attack path data.
- [SharpHound Enterprise System Requirements and Deployment Process](https://bloodhound.specterops.io/install-data-collector/install-sharphound/system-requirements.md)
- [Install or upgrade SharpHound Enterprise](https://bloodhound.specterops.io/install-data-collector/install-sharphound/installation-upgrade.md): Install SharpHound Enterprise on a Windows server or upgrade an existing deployment.
- [Deploy a Tiered SharpHound Enterprise Collector Strategy](https://bloodhound.specterops.io/install-data-collector/install-sharphound/tiered-collector-strategy.md)
- [Create a gMSA for Use With SharpHound Enterprise](https://bloodhound.specterops.io/install-data-collector/install-sharphound/create-gmsa.md)
- [SharpHound Enterprise Local Configuration](https://bloodhound.specterops.io/install-data-collector/install-sharphound/local-configuration.md)
- [Modify the Service Account Used By SharpHound Enterprise](https://bloodhound.specterops.io/install-data-collector/install-sharphound/modify-service-account.md)
- [Configure ADFS for Integrated Windows Authentication](https://bloodhound.specterops.io/install-data-collector/install-sharphound/configure-adfs-iwa.md): Learn how to enable Integrated Windows Authentication for SharpHound Enterprise on your Active Directory Federation Services (ADFS) server.
- [Troubleshoot Local Collection Coverage](https://bloodhound.specterops.io/install-data-collector/install-sharphound/troubleshooting.md)

#### Install AzureHound

- [Deploying AzureHound Enterprise](https://bloodhound.specterops.io/install-data-collector/install-azurehound/overview.md)
- [AzureHound Enterprise System Requirements and Deployment Process](https://bloodhound.specterops.io/install-data-collector/install-azurehound/system-requirements.md)
- [AzureHound Enterprise Azure Configuration](https://bloodhound.specterops.io/install-data-collector/install-azurehound/azure-configuration.md): This section details creating and configuring an Enterprise Application for AzureHound within Microsoft Entra ID, including API permissions, roles, and authentication certificate.
- [Create an AzureHound Configuration](https://bloodhound.specterops.io/install-data-collector/install-azurehound/create-configuration.md): Learn how to create a configuration file for AzureHound Enterprise data collection.
- [Install and Upgrade AzureHound (Windows, Docker, or Kubernetes)](https://bloodhound.specterops.io/install-data-collector/install-azurehound/installation-options.md)
- [Run Multiple AzureHound Enterprise Collectors on One Server With Scheduled Tasks](https://bloodhound.specterops.io/install-data-collector/install-azurehound/multiple-collectors.md)

### Collect Data

- [Data Collection](https://bloodhound.specterops.io/collect-data/overview.md): Learn how to run attack path data collection and ingestion.
- [Review Data Quality](https://bloodhound.specterops.io/collect-data/data-quality.md): Use the Data Quality page to validate collected object counts, trends, and coverage after ingest.
- [AzureHound Data Collection and Permissions](https://bloodhound.specterops.io/collect-data/azurehound-data-permissions.md): Learn how AzureHound collects data and the permissions required.
- [SharpHound Data Collection and Permissions](https://bloodhound.specterops.io/collect-data/sharphound-data-permissions.md): Learn how SharpHound collects data and the permissions required.

#### BloodHound Enterprise Collection

- [BloodHound Enterprise Collection](https://bloodhound.specterops.io/collect-data/enterprise-collection/overview.md): Learn about attack path data collection in BloodHound Enterprise.
- [Data Reconciliation and Retention](https://bloodhound.specterops.io/collect-data/enterprise-collection/data-retention.md)
- [Ad-hoc BHE Data Collection with SharpHound CE](https://bloodhound.specterops.io/collect-data/enterprise-collection/ad-hoc-collection.md): Learn how to do ad-hoc data collection for BloodHound Enterprise using SharpHound Community Edition.
- [Create a Collector Client](https://bloodhound.specterops.io/collect-data/enterprise-collection/create-collector.md): Learn how to create a BloodHound Enterprise collector client.
- [Run an On Demand Scan](https://bloodhound.specterops.io/collect-data/enterprise-collection/on-demand-scan.md): Learn how to run an on demand scan with a collector client in BloodHound Enterprise.
- [Create a Data Collection Schedule](https://bloodhound.specterops.io/collect-data/enterprise-collection/collection-schedule.md): Learn how to configure an Enterprise collector client to run data collection on a schedule.
- [Monitor Data Collection](https://bloodhound.specterops.io/collect-data/enterprise-collection/monitor.md): Learn how to interpret the status of collector jobs and file uploads.
- [Manage Collector Support Bundles](https://bloodhound.specterops.io/collect-data/enterprise-collection/collector-support-bundles.md): Request, download, and delete collector support bundles in BloodHound Enterprise.
- [Privileged Collection in SharpHound](https://bloodhound.specterops.io/collect-data/enterprise-collection/privileged-collection.md)
- [Least-Privileged Collection in SharpHound](https://bloodhound.specterops.io/collect-data/enterprise-collection/least-privileged-collection.md): Learn how to collect more than AD Structure data without Domain Admin.
- [SharpHound Enterprise Cross-Trust Collection](https://bloodhound.specterops.io/collect-data/enterprise-collection/cross-trust.md): Learn how to configure SharpHound Enterprise to collect data across trusted Active Directory domains and forests.
- [SharpHound Collection FAQ](https://bloodhound.specterops.io/collect-data/enterprise-collection/faq.md): The following are common questions about the data collection capabilities provided by the SharpHound Enterprise service.

#### Community Edition Collection

- [BloodHound CE Collection](https://bloodhound.specterops.io/collect-data/ce-collection/overview.md)
- [SharpHound Community Edition](https://bloodhound.specterops.io/collect-data/ce-collection/sharphound.md): SharpHound Community Edition (CE) is the official data collector for BloodHound CE. It is written in C# and uses native Windows API functions and LDAP namespace functions to collect data from domain controllers and domain-joined Windows systems.
- [SharpHound Community Edition Flags](https://bloodhound.specterops.io/collect-data/ce-collection/sharphound-flags.md)
- [Create a gMSA for Use With SharpHound Community Edition](https://bloodhound.specterops.io/collect-data/ce-collection/create-gmsa-community-edition.md)
- [AzureHound Community Edition](https://bloodhound.specterops.io/collect-data/ce-collection/azurehound.md)
- [AzureHound Community Edition Flags](https://bloodhound.specterops.io/collect-data/ce-collection/azurehound-flags.md)

### OpenHound

- [OpenHound Overview](https://bloodhound.specterops.io/openhound/overview.md): Learn about the OpenHound framework.
- [OpenHound for BloodHound Community Edition](https://bloodhound.specterops.io/openhound/community.md): Learn about the OpenHound framework for BHCE.
- [Configuration](https://bloodhound.specterops.io/openhound/configuration.md): Learn about configuring the OpenHound framework.

#### Enterprise

- [OpenHound for BloodHound Enterprise](https://bloodhound.specterops.io/openhound/enterprise.md): Learn about the OpenHound framework for BloodHound Enterprise.
- [Upload Extension Assets](https://bloodhound.specterops.io/openhound/upload-extension-assets.md): Upload saved queries and Privilege Zone rules for OpenHound extensions.
- [Deploy with Docker Compose](https://bloodhound.specterops.io/openhound/deploy-with-compose.md): Deploy OpenHound for BloodHound Enterprise with Docker Compose.
- [Deploy with Kubernetes](https://bloodhound.specterops.io/openhound/deploy-with-kubernetes.md): Deploy OpenHound for BloodHound Enterprise in a Kubernetes cluster.

#### Collectors

##### Jamf

- [Overview](https://bloodhound.specterops.io/openhound/collectors/jamf/overview.md): Learn about the SpecterOps-supported OpenHound Jamf collector for BloodHound.
- [Configure the Collector](https://bloodhound.specterops.io/openhound/collectors/jamf/collect-data.md): Configure the OpenHound Jamf collector to gather data from your Jamf Pro tenant.

##### Github

- [Overview](https://bloodhound.specterops.io/openhound/collectors/github/overview.md): Learn about the SpecterOps-supported OpenHound GitHub collector for BloodHound.
- [Configure a Personal Access Token](https://bloodhound.specterops.io/openhound/collectors/github/configure-pat.md): Create a Fine-grained Personal Access Token for GitHub data collection.
- [Configure an Organization GitHub App](https://bloodhound.specterops.io/openhound/collectors/github/configure-app.md): Create a GitHub App in a GitHub organization for OpenHound data collection.
- [Configure an Enterprise GitHub App](https://bloodhound.specterops.io/openhound/collectors/github/configure-enterprise-app.md): Create a GitHub App in a GitHub Enterprise account for OpenHound data collection.
- [Configure the Collector](https://bloodhound.specterops.io/openhound/collectors/github/collect-data.md): Configure the GitHub collector to gather data from your GitHub organization or enterprise.
- [Troubleshooting](https://bloodhound.specterops.io/openhound/collectors/github/troubleshooting.md): Common issues and solutions when running the OpenHound GitHub collector.

##### Okta

- [Overview](https://bloodhound.specterops.io/openhound/collectors/okta/overview.md): Learn about the SpecterOps-supported OpenHound Okta collector for BloodHound.
- [Okta App Registration](https://bloodhound.specterops.io/openhound/collectors/okta/okta-app-registration.md): Create an API service application in Okta to authenticate the OpenHound Okta collector.
- [Configure the Collector](https://bloodhound.specterops.io/openhound/collectors/okta/collect-data.md): Configure the OpenHound Okta collector to gather data from your Okta organization.

### Analyze Attack Path Data

- [The BloodHound Dashboard](https://bloodhound.specterops.io/analyze-data/overview.md): Learn how to use the BloodHound dashboard to analyze your data and identify attack paths.
- [BloodHound Configuration](https://bloodhound.specterops.io/analyze-data/configuration.md)

#### Findings and Remediation

- [Analysis Process](https://bloodhound.specterops.io/analyze-data/findings/analysis.md): Understand how the BloodHound Enterprise analysis process works to surface findings and prioritize risk.
- [Posture](https://bloodhound.specterops.io/analyze-data/findings/posture.md): Learn how to use the Posture page to track your organization's risk posture over time and measure the impact of your remediation efforts.

##### Attack Paths

- [Overview](https://bloodhound.specterops.io/analyze-data/findings/attack-paths.md): Learn about Attack Path findings in BloodHound Enterprise, including how to view, filter, and prioritize them for remediation.
- [Graph View](https://bloodhound.specterops.io/analyze-data/findings/graph-view.md): Review the exposure and impact of Attack Path findings in BloodHound Enterprise and access remediation guidance.
- [Table View](https://bloodhound.specterops.io/analyze-data/findings/table-view.md): Review, filter, and sort Attack Path findings at scale in BloodHound Enterprise.
- [Risk Acceptance](https://bloodhound.specterops.io/analyze-data/findings/risk-acceptance.md): Learn how to accept findings as known risks in BloodHound Enterprise, and understand the difference between acceptance and remediation.

#### Explore

- [Search and pathfinding](https://bloodhound.specterops.io/analyze-data/explore/search.md): Search for objects and visualize relationships between them in the graph.
- [Search with Cypher](https://bloodhound.specterops.io/analyze-data/explore/cypher-search.md): Start exploring BloodHound's prebuilt Cypher queries to uncover relationships and gain deeper insights into your environment.
- [Supported Cypher Syntax](https://bloodhound.specterops.io/analyze-data/explore/cypher-supported.md): This page documents the supported openCypher Syntax that BloodHound officially supports

#### Privilege Zones

- [Overview](https://bloodhound.specterops.io/analyze-data/privilege-zones/overview.md): Define protected boundaries in BloodHound and analyze attack paths that violate your security model.
- [Zones](https://bloodhound.specterops.io/analyze-data/privilege-zones/zones.md): Organize and categorize objects in your environment using Privilege Zones.
- [Labels](https://bloodhound.specterops.io/analyze-data/privilege-zones/labels.md): Learn how to use labels to categorize and manage objects within Privilege Zones for better organization.
- [Rules](https://bloodhound.specterops.io/analyze-data/privilege-zones/rules.md): Learn how to create, manage, and optimize rules in Privilege Zones to enhance BloodHound's analysis.
- [Default Rules](https://bloodhound.specterops.io/analyze-data/privilege-zones/default-rules.md): Explore and understand the default rules in Privilege Zones.
- [Certification](https://bloodhound.specterops.io/analyze-data/privilege-zones/certification.md): Understand the certification process for Privilege Zones and how to manage member approvals.
- [History](https://bloodhound.specterops.io/analyze-data/privilege-zones/history.md): Review the audit log of changes made to Privilege Zones over time.

##### Use Cases

- [Plan Attack Path Management](https://bloodhound.specterops.io/analyze-data/privilege-zones/use-cases/attack-path-management-journey.md): Expand Privilege Zones beyond Tier Zero by connecting Attack Path Management to business priorities.
- [Extend a Traditional Tiering Model](https://bloodhound.specterops.io/analyze-data/privilege-zones/use-cases/extend-traditional-tiering-model.md): Use Privilege Zones to test whether administrative tier boundaries hold up against real attack paths.
- [Protect Critical Applications and Environments](https://bloodhound.specterops.io/analyze-data/privilege-zones/use-cases/protect-critical-app-or-regulated-environment.md): Model critical applications and regulated environments as Privilege Zones for focused attack path analysis.
- [Run Remediation Campaigns](https://bloodhound.specterops.io/analyze-data/privilege-zones/use-cases/run-remediation-campaigns.md): Use Privilege Zones to create bounded remediation campaigns with clear scope, ownership, and progress tracking.
- [Protect Critical GitHub Repositories](https://bloodhound.specterops.io/analyze-data/privilege-zones/use-cases/protect-critical-github-repos.md): Model high-impact GitHub repositories, workflows, and deployment paths as protected Privilege Zone boundaries.
- [Protect Jamf Administration](https://bloodhound.specterops.io/analyze-data/privilege-zones/use-cases/protect-jamf-administration.md): Model Jamf administration and sensitive managed Mac boundaries as Privilege Zones for focused analysis.

### Manage BloodHound

- [Administration](https://bloodhound.specterops.io/manage-bloodhound/overview.md): Configure, secure, and administer your BloodHound environment.
- [BloodHound Shortcuts](https://bloodhound.specterops.io/manage-bloodhound/bh-shortcuts.md): List of the keyboard shortcuts available in BloodHound
- [BloodHound Configuration Supplement](https://bloodhound.specterops.io/manage-bloodhound/bh-config.md): This page provides example configuration details for BloodHound and BloodHound Enterprise
- [SharpHound Enterprise Service Hardening](https://bloodhound.specterops.io/manage-bloodhound/securing-bloodhound-and-collectors/sharphound-hardening.md): The BloodHound team recommends the hardening actions described on this page to protect the SharpHound service account. The hardening recommendations are focused on the remediation of the attack techniques targeting service accounts.

#### Authentication and Authorization

- [Authentication and Authorization](https://bloodhound.specterops.io/manage-bloodhound/auth/overview.md): Create and administer users of BloodHound using built-in authentication or SAML.
- [Administer Users and Roles](https://bloodhound.specterops.io/manage-bloodhound/auth/users-and-roles.md)
- [Configure ETAC](https://bloodhound.specterops.io/manage-bloodhound/auth/environment-targeted-access-control.md): Configure Environment Targeted Access Control to limit user access by environment.
- [Enable/Disable Multi-Factor Authentication](https://bloodhound.specterops.io/manage-bloodhound/auth/mfa.md)

##### OIDC

- [OIDC in BloodHound](https://bloodhound.specterops.io/manage-bloodhound/auth/oidc.md): BloodHound supports OIDC for Single Sign On to authenticate users to your tenant environment.
- [OIDC: Okta Configuration](https://bloodhound.specterops.io/manage-bloodhound/auth/oidc-okta.md): This document provides instructions for creating an application within Okta for compatibility with BloodHound Enterprise.

##### SAML

- [SAML in BloodHound](https://bloodhound.specterops.io/manage-bloodhound/auth/saml.md): BloodHound supports SAML 2.0 for Single Sign On to authenticate users to your tenant environment.
- [SAML: ADFS Configuration](https://bloodhound.specterops.io/manage-bloodhound/auth/saml-adfs.md): This document provides instructions for creating an application within ADFS for compatibility with BloodHound Enterprise.
- [SAML: Auth0 Configuration](https://bloodhound.specterops.io/manage-bloodhound/auth/saml-auth0.md): This document provides instructions for creating an application within Auth0 for compatibility with BloodHound Enterprise.
- [SAML: Entra ID Configuration](https://bloodhound.specterops.io/manage-bloodhound/auth/saml-entra-id.md): This document provides instructions for creating an application within Entra ID for compatibility with BloodHound Enterprise.
- [SAML: Google IDP Configuration](https://bloodhound.specterops.io/manage-bloodhound/auth/saml-google.md): This document provides instructions for creating an application within Google for compatibility with BloodHound Enterprise.
- [SAML: Okta Configuration](https://bloodhound.specterops.io/manage-bloodhound/auth/saml-okta.md): This document provides instructions for creating an application within Okta for compatibility with BloodHound Enterprise.

#### Alerts

- [Overview](https://bloodhound.specterops.io/manage-bloodhound/alerts/overview.md): Monitor alert events and webhook delivery in BloodHound Enterprise.
- [Configure alert channels and rules](https://bloodhound.specterops.io/manage-bloodhound/alerts/configure.md): Create an alert channel, test it, and create a rule that sends alert events to it.
- [Troubleshoot](https://bloodhound.specterops.io/manage-bloodhound/alerts/troubleshoot.md): Diagnose webhook configuration, delivery, and signature validation failures.

#### BloodHound Enterprise Compliance Framework

- [BloodHound Enterprise Compliance Framework](https://bloodhound.specterops.io/manage-bloodhound/compliance-framework/overview.md)
- [BloodHound Enterprise Compliance Framework Resource](https://bloodhound.specterops.io/manage-bloodhound/compliance-framework/resources.md): BloodHound Enterprise aids numerous organizations in meeting their compliance requirements through our continuous monitoring of identity Attack Path exposure within their environments. We're eager to support you and your auditors in gaining a deeper understanding of the inner workings of BloodHound…
- [BloodHound Enterprise NIST SP 800-171 Compliance Resource](https://bloodhound.specterops.io/manage-bloodhound/compliance-framework/nist-sp-800-171.md): The Following information is meant to provide a more detailed and in-depth view of compliance items that BloodHound Enterprise can assist in providing coverage for.
- [BloodHound Enterprise NIST SP 800-53 Rev.8 Compliance Resource](https://bloodhound.specterops.io/manage-bloodhound/compliance-framework/nist-sp-800-53.md)
- [BloodHound Enterprise NIST CSF v2 Compliance Resource](https://bloodhound.specterops.io/manage-bloodhound/compliance-framework/nist-csf-v2.md): The Following information is meant to provide a more detailed and in-depth view of compliance items that BloodHound Enterprise can provide coverage for.
- [BloodHound Enterprise NIST CSF v1.1 Compliance Resource](https://bloodhound.specterops.io/manage-bloodhound/compliance-framework/nist-csf-v1-1.md): The Following information is meant to provide a more detailed and in-depth view of compliance items that BloodHound Enterprise can provide coverage for.

### API & Integrations

- [API and Integrations](https://bloodhound.specterops.io/integrations/overview.md): Leverage BloodHound's REST API and third-party integrations to extend functionality and maximize your security infrastructure investments.

#### BloodHound API

- [Work With the BloodHound API](https://bloodhound.specterops.io/integrations/bloodhound-api/working-with-api.md)
- [BloodHound JSON Formats](https://bloodhound.specterops.io/integrations/bloodhound-api/json-formats.md)

#### Webhooks

- [Alert Webhook Contract](https://bloodhound.specterops.io/integrations/webhooks/alert-webhook-contract.md): Validate and process signed alert events sent to BloodHound Enterprise webhooks.

#### Cortex XSOAR

- [Integrate BloodHound Enterprise with Cortex XSOAR](https://bloodhound.specterops.io/integrations/cortex-xsoar/configure.md): Learn how to integrate BloodHound Enterprise with Cortex XSOAR by Palo Alto Networks.
- [Use Cortex XSOAR with BloodHound Enterprise](https://bloodhound.specterops.io/integrations/cortex-xsoar/use.md): Learn how to use Cortex XSOAR with BloodHound Enterprise to monitor and manage attack path findings.
- [Cortex XSOAR integration design reference](https://bloodhound.specterops.io/integrations/cortex-xsoar/reference.md): Technical reference and design details for the BloodHound Enterprise Cortex XSOAR integration.

#### Google SecOps

- [Integrate BloodHound Enterprise in Google SecOps](https://bloodhound.specterops.io/integrations/google-secops/configure.md): Learn how to install and configure the BloodHound Enterprise integration and connector in Google SecOps.
- [Use Google SecOps with BloodHound Enterprise](https://bloodhound.specterops.io/integrations/google-secops/use.md): Learn how to investigate BloodHound Enterprise findings in Google SecOps by using cases, alerts, events, playbooks, and actions.
- [Troubleshoot the Google SecOps integration](https://bloodhound.specterops.io/integrations/google-secops/troubleshoot.md): Learn how to diagnose and resolve common Google SecOps integration issues with BloodHound Enterprise.
- [Google SecOps integration design reference](https://bloodhound.specterops.io/integrations/google-secops/reference.md): Technical reference for the BloodHound Enterprise integration for Google SecOps, including architecture, authentication, connector flow, and API usage.

#### Atlassian

##### Jira

- [Integrate BloodHound Enterprise with Jira](https://bloodhound.specterops.io/integrations/atlassian/jira/configure.md): Learn how to install and configure the Jira integration for BloodHound Enterprise.
- [Use Jira with BloodHound Enterprise](https://bloodhound.specterops.io/integrations/atlassian/jira/use.md): Learn how to review and manage Jira issues created from BloodHound Enterprise findings.
- [Troubleshoot the Jira integration](https://bloodhound.specterops.io/integrations/atlassian/jira/troubleshoot.md): Learn how to diagnose and resolve common Jira integration issues with BloodHound Enterprise.
- [Jira integration design reference](https://bloodhound.specterops.io/integrations/atlassian/jira/reference.md): Technical reference for the Jira integration, including its Atlassian Forge architecture, schedules, and API usage.

#### ServiceNow

##### Security Incident Response

- [Integrate BloodHound Enterprise with ServiceNow Security Incident Response](https://bloodhound.specterops.io/integrations/service-now/security-incident-response/configure.md): Learn how to install and configure the integration to automate the creation of security incidents based on attack path findings.
- [Use Security Incident Response Integration with BloodHound Enterprise](https://bloodhound.specterops.io/integrations/service-now/security-incident-response/use.md): Learn how to use the ServiceNow Security Incident Response integration to manage security incidents based on BloodHound Enterprise attack path findings.

##### Vulnerability Response

- [Integrate BloodHound Enterprise with ServiceNow Vulnerability Response](https://bloodhound.specterops.io/integrations/service-now/vulnerability-response/configure.md): Learn how to install and configure the integration to automate vulnerability management based on attack path findings.
- [Use the Vulnerability Response Integration with BloodHound Enterprise](https://bloodhound.specterops.io/integrations/service-now/vulnerability-response/use.md): Learn how to navigate the Vulnerability Manager Workspace to see attack path data from BloodHound Enterprise.
- [Troubleshoot Common Issues](https://bloodhound.specterops.io/integrations/service-now/vulnerability-response/troubleshoot.md): Learn how to troubleshoot common installation, configuration, and performance issues with the Vulnerability Response Integration for ServiceNow.

#### Splunk

##### SIEM

- [Integrate BloodHound Enterprise with Splunk SIEM](https://bloodhound.specterops.io/integrations/splunk/siem/install.md): Learn how to install and configure the BloodHound Enterprise Splunk app to ingest BloodHound Enterprise data into Splunk.
- [Use the BloodHound Enterprise Splunk app](https://bloodhound.specterops.io/integrations/splunk/siem/use.md): Learn how to use the BloodHound Enterprise Splunk app to visualize and analyze BloodHound Enterprise data within Splunk.
- [Troubleshoot the BloodHound Enterprise Splunk app](https://bloodhound.specterops.io/integrations/splunk/siem/troubleshoot.md): Learn how to troubleshoot common issues with the BloodHound Enterprise Splunk app using the BHE Integration Health dashboard.

##### SOAR

- [Integrate BloodHound Enterprise with Splunk SOAR](https://bloodhound.specterops.io/integrations/splunk/soar/configure.md): Learn how to install and configure the BloodHound Enterprise Splunk SOAR app to ingest attack path findings into Splunk SOAR.
- [Use the Splunk SOAR integration for BloodHound Enterprise](https://bloodhound.specterops.io/integrations/splunk/soar/use.md): Learn how to use the BloodHound Enterprise Splunk SOAR app to view attack path findings in Splunk SOAR.

### On-premises BloodHound Enterprise

- [On-premises BloodHound Enterprise](https://bloodhound.specterops.io/on-premises/overview.md): Learn about self-hosted deployment for BloodHound Enterprise, giving you full control over your infrastructure and data.
- [Architecture](https://bloodhound.specterops.io/on-premises/architecture.md): Understand the architecture, components, and data flow of on-premises deployments of BloodHound Enterprise.
- [System Requirements](https://bloodhound.specterops.io/on-premises/system-requirements.md): Review hardware, software, and network requirements for the embedded cluster deployment option of an on-premises instance of BloodHound Enterprise.
- [Install and Configure](https://bloodhound.specterops.io/on-premises/install.md): Use this guide to install and configure an on-premises instance of BloodHound Enterprise with the embedded cluster deployment option.
- [Upgrade an external PostgreSQL database](https://bloodhound.specterops.io/on-premises/upgrade-postgres.md): Upgrade an external PostgreSQL database from version 16 to 18 for on-premises deployments of BloodHound Enterprise.

### Resources

- [Resources](https://bloodhound.specterops.io/resources/overview.md): Access comprehensive documentation about BloodHound graph components, terminology definitions, release information, and how to get help.
- [Legacy BloodHound](https://bloodhound.specterops.io/resources/legacy.md)

#### Nodes

- [About BloodHound Nodes](https://bloodhound.specterops.io/resources/nodes/overview.md)
- [ADLocalGroup](https://bloodhound.specterops.io/resources/nodes/ad-local-group.md)
- [AIACA](https://bloodhound.specterops.io/resources/nodes/aiaca.md)
- [AZApp](https://bloodhound.specterops.io/resources/nodes/az-app.md)
- [AZAutomationAccount](https://bloodhound.specterops.io/resources/nodes/az-automation-account.md)
- [AZBase](https://bloodhound.specterops.io/resources/nodes/az-base.md)
- [AZContainerRegistry](https://bloodhound.specterops.io/resources/nodes/az-container-registry.md)
- [AZDevice](https://bloodhound.specterops.io/resources/nodes/az-device.md)
- [AZFederatedIdentityCredential](https://bloodhound.specterops.io/resources/nodes/az-federated-identity-credential.md): The AZFederatedIdentityCredential node represents a Federated Identity Credential (FIC) configured on an Azure App Registration, which allows an external identity provider to authenticate as the application without a password or certificate.
- [AZFunctionApp](https://bloodhound.specterops.io/resources/nodes/az-function-app.md)
- [AZGroup](https://bloodhound.specterops.io/resources/nodes/az-group.md)
- [AZKeyVault](https://bloodhound.specterops.io/resources/nodes/az-key-vault.md)
- [AZLogicApp](https://bloodhound.specterops.io/resources/nodes/az-logic-app.md)
- [AZManagedCluster](https://bloodhound.specterops.io/resources/nodes/az-managed-cluster.md)
- [AZManagementGroup](https://bloodhound.specterops.io/resources/nodes/az-management-group.md)
- [AZResourceGroup](https://bloodhound.specterops.io/resources/nodes/az-resource-group.md)
- [AZRole](https://bloodhound.specterops.io/resources/nodes/az-role.md)
- [AZServicePrincipal](https://bloodhound.specterops.io/resources/nodes/az-service-principal.md)
- [AZSubscription](https://bloodhound.specterops.io/resources/nodes/az-subscription.md)
- [AZTenant](https://bloodhound.specterops.io/resources/nodes/az-tenant.md)
- [AZUser](https://bloodhound.specterops.io/resources/nodes/az-user.md)
- [AZVM](https://bloodhound.specterops.io/resources/nodes/az-vm.md)
- [AZVMScaleSet](https://bloodhound.specterops.io/resources/nodes/az-vm-scale-set.md)
- [AZWebApp](https://bloodhound.specterops.io/resources/nodes/az-web-app.md)
- [Base](https://bloodhound.specterops.io/resources/nodes/base.md)
- [CertTemplate](https://bloodhound.specterops.io/resources/nodes/cert-template.md)
- [Computer](https://bloodhound.specterops.io/resources/nodes/computer.md)
- [Container](https://bloodhound.specterops.io/resources/nodes/container.md)
- [Domain](https://bloodhound.specterops.io/resources/nodes/domain.md)
- [EnterpriseCA](https://bloodhound.specterops.io/resources/nodes/enterprise-ca.md)
- [GPO](https://bloodhound.specterops.io/resources/nodes/gpo.md)
- [Group](https://bloodhound.specterops.io/resources/nodes/group.md)
- [IssuancePolicy](https://bloodhound.specterops.io/resources/nodes/issuance-policy.md)
- [Meta](https://bloodhound.specterops.io/resources/nodes/meta.md): Nodes generated and used by analysis
- [NTAuthStore](https://bloodhound.specterops.io/resources/nodes/nt-auth-store.md)
- [OU](https://bloodhound.specterops.io/resources/nodes/ou.md)
- [RootCA](https://bloodhound.specterops.io/resources/nodes/root-ca.md)
- [User](https://bloodhound.specterops.io/resources/nodes/user.md)

#### Edges

- [About BloodHound Edges](https://bloodhound.specterops.io/resources/edges/overview.md): Edges are part of the graph construct and are represented as links/relationships that connect one node to another node.
- [Traversable and Non-Traversable Edge Types](https://bloodhound.specterops.io/resources/edges/traversable-edges.md): Details on traversable and non-traversable edge types in BloodHound
- [AbuseTGTDelegation](https://bloodhound.specterops.io/resources/edges/abuse-tgt-delegation.md): The trust from the target node domain to the source node domain has TGT delegation enabled. When a resource in the source node domain is configured with unconstrained delegation, principals from the target node domain will automatically forward their Ticket Granting Ticket (TGT) to that resource upo…
- [ADCSESC1](https://bloodhound.specterops.io/resources/edges/adcs-esc1.md): This edge indicates that the principal has permission to enroll on one or more certificate templates, allowing them to specify an alternate subject name and use the certificate for authentication. They also have enrollment permission for an enterprise CA with the necessary templates published.
- [ADCSESC10a](https://bloodhound.specterops.io/resources/edges/adcs-esc10a.md): This edge indicates that the principal has control over a victim principal with permission to enroll on one or more certificate templates, configured to enable certificate authentication and require the userPrincipalName (UPN) of the enrollee included in the Subject Alternative Name (SAN).
- [ADCSESC10b](https://bloodhound.specterops.io/resources/edges/adcs-esc10b.md): The principal has control over a victim computer with permission to enroll on one or more certificate templates, configured to enable certificate authentication, and require the `dNSHostName` of the enrollee included in the Subject Alternative Name (SAN).
- [ADCSESC13](https://bloodhound.specterops.io/resources/edges/adcs-esc13.md): The ADCSESC13 edge indicates that the principal has the privileges to perform the ADCS ESC13 abuse against the target AD group. The principal has enrollment rights on a certificate template configured with an issuance policy extension.
- [ADCSESC3](https://bloodhound.specterops.io/resources/edges/adcs-esc3.md): The principal has permission to enroll on a certificate allowing them to obtain an enrollment agent certificate.
- [ADCSESC4](https://bloodhound.specterops.io/resources/edges/adcs-esc4.md): The ADCSESC4 edge indicates that the principal has the privileges to perform the ADCS ESC4 abuse against the target AD domain.
- [ADCSESC6a](https://bloodhound.specterops.io/resources/edges/adcs-esc6a.md): The principal has permission to enroll on one or more certificate templates allowing for authentication.
- [ADCSESC6b](https://bloodhound.specterops.io/resources/edges/adcs-esc6b.md): The principal has permission to enroll on one or more certificate templates allowing for authentication.
- [ADCSESC9a](https://bloodhound.specterops.io/resources/edges/adcs-esc9a.md): The principal has control over a victim principal with permission to enroll on one or more certificate templates, configured to: 1) enable certificate authentication, 2) require the `userPrincipalName` (UPN) of the enrollee included in the Subject Alternative Name (SAN), and 3) do not have the secur…
- [ADCSESC9b](https://bloodhound.specterops.io/resources/edges/adcs-esc9b.md): The principal has control over a victim computer with permission to enroll on one or more certificate templates, configured to: 1) enable certificate authentication, 2) require the `dNSHostName`  of the enrollee included in the Subject Alternative Name (SAN), and 3) not have the security extension e…
- [AddAllowedToAct](https://bloodhound.specterops.io/resources/edges/add-allowed-to-act.md): This edge means it's possible to modify the msDS-AllowedToActOnBehalfOfOtherIdentity property of a target.
- [AddKeyCredentialLink](https://bloodhound.specterops.io/resources/edges/add-key-credential-link.md): The ability to write to the “msds-KeyCredentialLink” property on a user or computer. Writing to this property allows an attacker to create “Shadow Credentials” on the object and authenticate as the principal using kerberos PKINIT.
- [AddMember](https://bloodhound.specterops.io/resources/edges/add-member.md): This edge indicates the principal has the ability to add arbitrary principals to the target security group. Because of security group delegation, the members of a security group have the same privileges as that group.
- [AddSelf](https://bloodhound.specterops.io/resources/edges/add-self.md): This edge indicates the principal has the ability to add itself to the target security group. Because of security group delegation, the members of a security group have the same privileges as that group.
- [AdminTo](https://bloodhound.specterops.io/resources/edges/admin-to.md): This edge indicates that principal is a local administrator on the target computer.
- [AllExtendedRights](https://bloodhound.specterops.io/resources/edges/all-extended-rights.md): Extended rights are special rights granted on objects which allow reading of privileged attributes, as well as performing special actions.
- [AllowedToAct](https://bloodhound.specterops.io/resources/edges/allowed-to-act.md): This edge allows an attacker to abuse resource-based constrained delegation to compromise the target. This property is a binary DACL that controls what security principals can pretend to be any domain user to the particular computer object.
- [AllowedToDelegate](https://bloodhound.specterops.io/resources/edges/allowed-to-delegate.md): The constrained delegation primitive allows a principal to authenticate as any user to specific services (found in the msds-AllowedToDelegateTo LDAP property in the source node tab) on the target computer.
- [AZAddMembers](https://bloodhound.specterops.io/resources/edges/az-add-members.md): The ability to add other principals to an Azure security group
- [AZAddOwner](https://bloodhound.specterops.io/resources/edges/az-add-owner.md): This edge is created during post-processing.
- [AZAddSecret](https://bloodhound.specterops.io/resources/edges/az-add-secret.md): Azure provides several systems and mechanisms for granting control of securable objects within Entra ID, including tenant-scoped admin roles, object-scoped admin roles, explicit object ownership, and API permissions.
- [AZAKSContributor](https://bloodhound.specterops.io/resources/edges/az-aks-contributor.md): The Azure Kubernetes Service Contributor role grants full control of the target Azure Kubernetes Service Managed Cluster.
- [AZAppAdmin](https://bloodhound.specterops.io/resources/edges/az-app-admin.md): The principal has the Application Administrator Entra ID role active and can control tenant-resident apps.
- [AZAuthenticatesTo](https://bloodhound.specterops.io/resources/edges/az-authenticates-to.md): The AZAuthenticatesTo edge indicates that a Federated Identity Credential (FIC) is configured on an Azure App Registration, allowing an external identity provider to authenticate as the application without a password or certificate.
- [AZAutomationContributor](https://bloodhound.specterops.io/resources/edges/az-automation-contributor.md): The Azure Automation Contributor role grants full control of the target Azure Automation Account. This includes the ability to execute arbitrary commands on the Automation Account.
- [AZAvereContributor](https://bloodhound.specterops.io/resources/edges/az-avere-contributor.md): Any principal granted the Avere Contributor role, scoped to the affected VM, can reset the built-in administrator password on the VM.
- [AZCloudAppAdmin](https://bloodhound.specterops.io/resources/edges/az-cloud-app-admin.md): The principal has the Cloud Application Administrator Entra ID role active and can control tenant-resident apps.
- [AZContains](https://bloodhound.specterops.io/resources/edges/az-contains.md): This indicates that the parent object contains the child object, such as a resource group containing a virtual machine, or a tenant “containing” a subscription.
- [AZContributor](https://bloodhound.specterops.io/resources/edges/az-contributor.md): The contributor role grants almost all abusable privileges in all circumstances, with some exceptions. Those exceptions are not collected by AzureHound.
- [AZExecuteCommand](https://bloodhound.specterops.io/resources/edges/az-execute-command.md): Principals with the Intune Administrators role are able to execute arbitrary PowerShell scripts on devices that are joined to the Azure tenant.
- [AZGetCertificates](https://bloodhound.specterops.io/resources/edges/az-get-certificates.md): The ability to read certificates from key vaults.
- [AZGetKeys](https://bloodhound.specterops.io/resources/edges/az-get-keys.md): The ability to read keys from key vaults.
- [AZGetSecrets](https://bloodhound.specterops.io/resources/edges/az-get-secrets.md): The ability to read secrets from key vaults.
- [AZGlobalAdmin](https://bloodhound.specterops.io/resources/edges/az-global-admin.md): The principal has the Global Administrator Entra ID role active against the target tenant. In other words, the principal is a Global Admin. Global Admins can do almost anything against almost every object type in the tenant, this is the highest privilege role in Azure.
- [AZHasRole](https://bloodhound.specterops.io/resources/edges/az-has-role.md): The principal has an active assignment to the Entra ID role. This includes permanent assignments, and temporary assignments via Privileged Identity Management (PIM). If the principal is assigned eligibility via PIM the principal will also have an [AZRoleEligible](/resources/edges/az-role-eligible) e…
- [AZKeyVaultKVContributor](https://bloodhound.specterops.io/resources/edges/az-key-vault-contributor.md): The Key Vault Contributor role grants full control of the target Key Vault. This includes the ability to read all secrets stored on the Key Vault.
- [AZLogicAppContributor](https://bloodhound.specterops.io/resources/edges/az-logic-app-contributor.md): The Logic Contributor role grants full control of the target Logic App. This includes the ability to execute arbitrary commands on the Logic App.
- [AZManagedIdentity](https://bloodhound.specterops.io/resources/edges/az-managed-identity.md): Azure resources like Virtual Machines, Logic Apps, and Automation Accounts can be assigned to either System- or User-Assigned Managed Identities.
- [AZMemberOf](https://bloodhound.specterops.io/resources/edges/az-member-of.md): The given asset is a member of the group.
- [AZMGAddMember](https://bloodhound.specterops.io/resources/edges/az-mg-add-member.md): This edge is created during post-processing.
- [AZMGAddOwner](https://bloodhound.specterops.io/resources/edges/az-mg-add-owner.md): This edge is created during post-processing.
- [AZMGAddSecret](https://bloodhound.specterops.io/resources/edges/az-mg-add-secret.md): This edge is created during post-processing.
- [AZMGAppRoleAssignment_ReadWrite_All](https://bloodhound.specterops.io/resources/edges/az-mg-app-role-assignment-readwrite-all.md): This edge is created when a Service Principal has been granted the AppRoleAssignment.ReadWrite.All edge.
- [AZMGApplication_ReadWrite_All](https://bloodhound.specterops.io/resources/edges/az-mg-application-readwrite-all.md): This edge is created when a Service Principal has been granted the Application.ReadWrite.All edge.
- [AZMGDirectory_ReadWrite_All](https://bloodhound.specterops.io/resources/edges/az-mg-directory-readwrite-all.md): This edge is created when a Service Principal has been granted the Directory.ReadWrite.All edge.
- [AZMGGrantAppRoles](https://bloodhound.specterops.io/resources/edges/az-mg-grant-app-roles.md): This edge is created during post-processing.
- [AZMGGrantRole](https://bloodhound.specterops.io/resources/edges/az-mg-grant-role.md): This edge is created during post-processing.
- [AZMGGroupMember_ReadWrite_All](https://bloodhound.specterops.io/resources/edges/az-mg-group-member-readwrite-all.md): This edge is created when a Service Principal has been granted the GroupMember.ReadWrite.All edge.
- [AZMGGroup_ReadWrite_All](https://bloodhound.specterops.io/resources/edges/az-mg-group-readwrite-all.md): This edge is created when a Service Principal has been granted the Group.ReadWrite.All edge.
- [AZMGRoleManagement_ReadWrite_Directory](https://bloodhound.specterops.io/resources/edges/az-mg-role-management-readwrite-directory.md): This edge is created when a Service Principal has been granted the RoleManagement.ReadWrite.Directory edge.
- [AZMGServicePrincipalEndpoint_ReadWrite_All](https://bloodhound.specterops.io/resources/edges/az-mg-service-principal-endpoint-readwrite-all.md): This edge is created when a Service Principal has been granted the ServicePrincipalEndpoint.ReadWrite.All edge.
- [AZNodeResourceGroup](https://bloodhound.specterops.io/resources/edges/az-node-resource-group.md): This edge is created to link Azure Kubernetes Service Managed Clusters to the Virtual Machine Scale Sets they use to execute commands on.
- [AZOwner](https://bloodhound.specterops.io/resources/edges/az-owner.md): An Entra principal has been granted the Azure Resource Manager role called "Owner" over an Azure Resource Manager asset.
- [AZOwns](https://bloodhound.specterops.io/resources/edges/az-owns.md): An Entra principal has been added as an owner over an Entra asset.
- [AZPrivilegedAuthAdmin](https://bloodhound.specterops.io/resources/edges/az-privileged-auth-admin.md): The principal has the Privileged Authentication Administrator Entra ID role active against the target tenant.
- [AZPrivilegedRoleAdmin](https://bloodhound.specterops.io/resources/edges/az-privileged-role-admin.md): The principal has the Privileged Role Administrator Entra ID role active against the target tenant.
- [AZResetPassword](https://bloodhound.specterops.io/resources/edges/az-reset-password.md): The ability to change another user’s password without knowing their current password.
- [AZRoleApprover](https://bloodhound.specterops.io/resources/edges/az-role-approver.md): The principal is designated as an approver in the Privileged Identity Management (PIM) policy for the Entra ID role. PIM policies may require principals with the [AZRoleEligible](/resources/edges/az-role-eligible) edge to get approval from role approvers before activation takes effect.
- [AZRoleEligible](https://bloodhound.specterops.io/resources/edges/az-role-eligible.md): The principal is eligible for assignment to the Entra ID role via Privileged Identity Management (PIM). When the role is active the principal will also have an [AZHasRole](/resources/edges/az-has-role) edge to the role.
- [AZRunsAs](https://bloodhound.specterops.io/resources/edges/az-runs-as.md): The Azure App runs as the Service Principal when it needs to authenticate to the tenant.
- [AZScopedTo](https://bloodhound.specterops.io/resources/edges/az-scoped-to.md): Is used to distinguish whether an EntraID (AzureAD) admin role such as Application Administrator or Cloud Application Administrator is scoped to the tenant or to a particular app registration or service principal.
- [AZUserAccessAdministrator](https://bloodhound.specterops.io/resources/edges/az-user-access-administrator.md): The User Access Admin role can edit roles against many other objects.
- [AZVMAdminLogin](https://bloodhound.specterops.io/resources/edges/az-vm-admin-login.md): When a virtual machine is configured to allow logon with Azure credentials, the VM automatically has certain principals added to its local administrators group, including any principal granted the Virtual Machine Administrator Login (or “VMAL”) admin role.
- [AZVMContributor](https://bloodhound.specterops.io/resources/edges/az-vm-contributor.md): The Virtual Machine contributor role grants almost all abusable privileges against Virtual Machines.
- [AZWebsiteContributor](https://bloodhound.specterops.io/resources/edges/az-website-contributor.md): The Website Contributor role grants full control of the target Function App or Web App. Full control of either of those types of resources allows for arbitrary command execution against the target resoruce.
- [CanPSRemote](https://bloodhound.specterops.io/resources/edges/can-ps-remote.md): PS Session access allows you to enter an interactive session with the target computer. If authenticating as a low privilege user, a privilege escalation may allow you to gain high privileges on the system.
- [CanRDP](https://bloodhound.specterops.io/resources/edges/can-rdp.md): Remote Desktop access allows you to enter an interactive session with the target computer. If authenticating as a low privilege user, a privilege escalation may allow you to gain high privileges on the system.
- [ClaimSpecialIdentity](https://bloodhound.specterops.io/resources/edges/claim-special-identity.md): The ClaimSpecialIdentity edge represents the ability to obtain an access token containing a special identity (group) SID.
- [CoerceAndRelayNTLMToADCS](https://bloodhound.specterops.io/resources/edges/coerce-and-relay-ntlm-to-adcs.md): The target computer can be coerced to authenticate via NTLM to an ADCS server, allowing an attacker to obtain a certificate for domain authentication.
- [CoerceAndRelayNTLMToLDAP](https://bloodhound.specterops.io/resources/edges/coerce-and-relay-ntlm-to-ldap.md): The target computer can be coerced to authenticate via NTLM to an LDAP service on a domain controller that does not require LDAP signing, allowing an attacker to abuse Active Directory permissions or obtain administrative access to the target computer.
- [CoerceAndRelayNTLMToLDAPS](https://bloodhound.specterops.io/resources/edges/coerce-and-relay-ntlm-to-ldaps.md): The target computer can be coerced to authenticate via NTLM to an LDAPS service on a domain controller that does not require LDAPS channel binding, allowing an attacker to abuse Active Directory permissions or obtain administrative access to the target computer.
- [CoerceAndRelayNTLMToSMB](https://bloodhound.specterops.io/resources/edges/coerce-and-relay-ntlm-to-smb.md): An attacker can coerce a computer to authenticate via NTLM to an SMB service on a target computer that does not enforce SMB signing, allowing the attacker to gain administrative access to the target computer.
- [CoerceToTGT](https://bloodhound.specterops.io/resources/edges/coerce-to-tgt.md): The computer/user account is configured with Kerberos unconstrained delegation.
- [Contains](https://bloodhound.specterops.io/resources/edges/contains.md): GPOs linked to a container apply to all objects that are contained by the container. Additionally, ACEs set on a parent OU may inherit down to child objects.
- [CrossForestTrust](https://bloodhound.specterops.io/resources/edges/cross-forest-trust.md): The CrossForestTrust edge represents a trust relationship between two domains/forests. In this relationship, the source node domain has a cross-forest (interforest) trust to the destination node domain, allowing principals (users and computers) from the destination domain to access resources in the…
- [DCFor](https://bloodhound.specterops.io/resources/edges/dc-for.md): This edge indicates that the computer is a domain controller for the domain. This edge is not created for read-only domain controllers.
- [DCSync](https://bloodhound.specterops.io/resources/edges/dc-sync.md): This edge represents the combination of GetChanges and GetChangesAll. The combination of both these privileges grants a principal the ability to perform the DCSync attack.
- [DelegatedEnrollmentAgent](https://bloodhound.specterops.io/resources/edges/delegated-enrollment-agent.md): The source principal node is delegated the privilege to enroll certificates of the destination certificate template node as an enrollment agent.
- [DumpSMSAPassword](https://bloodhound.specterops.io/resources/edges/dump-smsa-password.md): A computer with this indicates that a Standalone Managed Service Account (sMSA) is installed on it.
- [Enroll](https://bloodhound.specterops.io/resources/edges/enroll.md): The target node may be a Certificate Template or an Enterprise Certification Authority.
- [EnrollOnBehalfOf](https://bloodhound.specterops.io/resources/edges/enroll-on-behalf-of.md): The certificate template "A" is configured to be used as an enrollment agent.
- [EnterpriseCAFor](https://bloodhound.specterops.io/resources/edges/enterprise-ca-for.md): The Enterprise Certification Authority node is the enrollment service LDAP object for the target Root Certification Authority node.
- [ExecuteDCOM](https://bloodhound.specterops.io/resources/edges/execute-dcom.md): This can allow code execution under certain conditions by instantiating a COM object on a remote machine and invoking its methods.
- [ExtendedByPolicy](https://bloodhound.specterops.io/resources/edges/extended-by-policy.md): The edge indicates that a certificate template includes an issuance policy as a certificate extension.
- [ForceChangePassword](https://bloodhound.specterops.io/resources/edges/force-change-password.md): This edge indicates that the principal can reset the password of the target user without knowing the current password of that user.
- [GenericAll](https://bloodhound.specterops.io/resources/edges/generic-all.md): This is also known as full control. This privilege allows the trustee to manipulate the target object however they wish.
- [GenericWrite](https://bloodhound.specterops.io/resources/edges/generic-write.md): Generic Write access grants you the ability to write to any non-protected attribute on the target object, including "members" for a group, and "servicePrincipalNames" for a user.
- [GetChanges](https://bloodhound.specterops.io/resources/edges/get-changes.md): The principal is granted the GetChanges right on the domain.
- [GetChangesAll](https://bloodhound.specterops.io/resources/edges/get-changes-all.md): The principal is granted the GetChangesAll right on the domain.
- [GetChangesInFilteredSet](https://bloodhound.specterops.io/resources/edges/get-changes-in-filtered-set.md): The principal is allowed to synchronize (DCSync) the Filtered Attribute Set (FAS), which are the attributes not replicated to RODCs.
- [GoldenCert](https://bloodhound.specterops.io/resources/edges/golden-cert.md): The victim principal has a certificate private key that can be abused to sign "golden" certificates for authentication of any enabled principal in the AD forest of the domain.
- [GPLink](https://bloodhound.specterops.io/resources/edges/gp-link.md): A linked GPO applies its settings to objects in the linked container.
- [HasSession](https://bloodhound.specterops.io/resources/edges/has-session.md): When a user authenticates to a computer, they often leave credentials exposed on the system, which can be retrieved through LSASS injection, token manipulation or theft, or injecting into a user’s process.
- [HasSIDHistory](https://bloodhound.specterops.io/resources/edges/has-sid-history.md): The given source principal has, in its SIDHistory attribute, the SID for the target principal.
- [HasTrustKeys](https://bloodhound.specterops.io/resources/edges/has-trust-keys.md): The relationship's source node is a domain which has the trust keys for the end node trust account.
- [HostsCAService](https://bloodhound.specterops.io/resources/edges/hosts-ca-service.md): The Enterprise Certification Authority node is the enrollment service LDAP object for CA hosted on the computer node.
- [IssuedSignedBy](https://bloodhound.specterops.io/resources/edges/issued-signed-by.md): When Windows assesses the validity and trustworthiness of a certificate it verifies the certificate chain up to a trusted root certificate. The IssuedSignedBy edge represents a link within the certificate chain.
- [LocalToComputer](https://bloodhound.specterops.io/resources/edges/local-to-computer.md): The LocalGroup is a local group on the Computer.
- [ManageCA](https://bloodhound.specterops.io/resources/edges/manage-ca.md): The principal has the "Manage CA", also known as "CA Administrator", permission on the Enterprise CA.
- [ManageCertificates](https://bloodhound.specterops.io/resources/edges/manage-certificates.md): The principal has the "Manage Certificates", also known as "CA Officer", permission on the Enterprise CA.
- [MemberOf](https://bloodhound.specterops.io/resources/edges/member-of.md): Groups in active directory grant their members any privileges the group itself has.
- [MemberOfLocalGroup](https://bloodhound.specterops.io/resources/edges/member-of-local-group.md): From a Principal to LocalGroup. Principal is a member of the LocalGroup.
- [NTAuthStoreFor](https://bloodhound.specterops.io/resources/edges/nt-auth-store-for.md): The NTAuthStore is the Enterprise NTAuth store (NTAuthCertificates object) for the AD forest of the domain node.
- [OIDGroupLink](https://bloodhound.specterops.io/resources/edges/oid-group-link.md): The edge indicates that an IssuancePolicy has an OID group link to a group.
- [Owns](https://bloodhound.specterops.io/resources/edges/owns.md): Object owners retain the ability to modify object security descriptors, regardless of permissions on the object’s DACL
- [OwnsLimitedRights](https://bloodhound.specterops.io/resources/edges/owns-limited-rights.md): When specific privileges on an object's DACL are explicitly granted to the `OWNER RIGHTS` SID (S-1-3-4), implicit owner rights (e.g., WriteDacl) are blocked, and the owner is granted only the specific privileges granted to OWNER RIGHTS. This can be used to limit the rights of the owner of an object.
- [OwnsRaw](https://bloodhound.specterops.io/resources/edges/owns-raw.md): This edge is established from the principal that owns an object to the owned object. This edge is processed further to determine whether implicit owner rights (e.g., WriteDacl) are blocked, which may prevent the owner from compromising the destination object.
- [ProtectAdminGroups](https://bloodhound.specterops.io/resources/edges/protect-admin-groups.md): The ProtectAdminGroups background task tattoos the AdminSDHolder security descriptor on this node.
- [PublishedTo](https://bloodhound.specterops.io/resources/edges/published-to.md): The certificate template is published to an enterprise certification authority.
- [ReadGMSAPassword](https://bloodhound.specterops.io/resources/edges/read-gmsa-password.md): This privilege allows you to read the password for a Group Managed Service Account (GMSA).
- [ReadLAPSPassword](https://bloodhound.specterops.io/resources/edges/read-laps-password.md): This privilege allows a principal to read the LAPS password from a computer.
- [RemoteInteractiveLogonRight](https://bloodhound.specterops.io/resources/edges/remote-interactive-logon-right.md): From Principal to Computer. Principal has the SeRemoteInteractiveLogonRight on the Computer.
- [RootCAFor](https://bloodhound.specterops.io/resources/edges/root-ca-for.md): The CA is trusted as a root certification authority by the domain.
- [SameForestTrust](https://bloodhound.specterops.io/resources/edges/same-forest-trust.md): The SameForestTrust edge represents a trust relationship between two domains within the same AD forest.
- [SpoofSIDHistory](https://bloodhound.specterops.io/resources/edges/spoof-sid-history.md): The cross-forest trust from the target domain to the source domain has a weak SID filtering configuration (SpoofSIDHistoryBlocked = False).
- [SQLAdmin](https://bloodhound.specterops.io/resources/edges/sql-admin.md): The user is a SQL admin on the target computer
- [SyncLAPSPassword](https://bloodhound.specterops.io/resources/edges/sync-laps-password.md): A principal with this signifies the capability of retrieving, through a directory synchronization, the value of confidential and RODC filtered attributes, such as LAPS’ _ms-Mcs-AdmPwd_.
- [SyncedToADUser](https://bloodhound.specterops.io/resources/edges/synced-to-ad-user.md): The Entra user is synchronized to the on-prem AD user.
- [SyncedToEntraUser](https://bloodhound.specterops.io/resources/edges/synced-to-entra-user.md): The on-prem AD user is synchronized to the Entra ID user.
- [TrustedForNTAuth](https://bloodhound.specterops.io/resources/edges/trusted-for-nt-auth.md): The NTAuthStore contains the certificate of the Enterprise CA.
- [WriteAccountRestrictions](https://bloodhound.specterops.io/resources/edges/write-account-restrictions.md): This edge indicates the principal has the ability to modify several properties on the target principal, most notably the msDS-AllowedToActOnBehalfOfOtherIdentity attribute.
- [WriteAltSecurityIdentities](https://bloodhound.specterops.io/resources/edges/write-alt-security-identities.md): The principal can write to the altSecurityIdentities attribute on a user or computer, enabling explicit certificate mappings and ADCS ESC14 Scenario A.
- [WriteDacl](https://bloodhound.specterops.io/resources/edges/write-dacl.md): With write access to the target object’s DACL, you can grant yourself any privilege you want on the object.
- [WriteGPLink](https://bloodhound.specterops.io/resources/edges/write-gp-link.md): The WriteGPLink edge indicates that the principal has the permissions to modify the gPLink attribute of the targeted OU/domain node.
- [WriteOwner](https://bloodhound.specterops.io/resources/edges/write-owner.md): Object owners retain the ability to modify object security descriptors, regardless of permissions on the object’s DACL.
- [WriteOwnerLimitedRights](https://bloodhound.specterops.io/resources/edges/write-owner-limited-rights.md): When specific privileges on an object's DACL are explicitly granted to the `OWNER RIGHTS` SID (S-1-3-4), and inheritance is configured for those permissions, they are inherited by the new object owner after a change in ownership. In this case, implicit owner rights are blocked, and the new owner is…
- [WriteOwnerRaw](https://bloodhound.specterops.io/resources/edges/write-owner-raw.md): This edge is established from the principal that can change the owner of an object to the owned object. This edge is processed further to determine whether implicit owner rights (e.g., WriteDacl) are blocked, which may prevent the owner from compromising the destination object.
- [WritePKIEnrollmentFlag](https://bloodhound.specterops.io/resources/edges/write-pki-enrollment-flag.md): The attacker principal has the ability to write to the msPKI-Enrollment-Flag attribute on the victim principal, which allows the attacker principal to configure "manager approval" for the certificate template and other settings.
- [WritePKINameFlag](https://bloodhound.specterops.io/resources/edges/write-pki-name-flag.md): The attacker principal has the ability to write to the msPKI-Certificate-Name-Flag attribute on the victim principal, which allows the attacker principal to configure "enrollee supplies subject" for the certificate template and other settings.
- [WritePublicInformation](https://bloodhound.specterops.io/resources/edges/write-public-information.md): The principal can write to the Public-Information property set on a user or computer, including altSecurityIdentities and servicePrincipalName.
- [WriteSPN](https://bloodhound.specterops.io/resources/edges/write-spn.md): The ability to write directly to the servicePrincipalNames attribute on a user object.

#### Glossary

- [BloodHound Glossary](https://bloodhound.specterops.io/resources/glossary/overview.md): Learn the terminology used in BloodHound software and documentation.

#### Community and Support

- [Community and Support](https://bloodhound.specterops.io/resources/community-support/overview.md): Connect with the BloodHound community, seek assistance, and find resources for support and collaboration.
- [Additional Training and Resources](https://bloodhound.specterops.io/resources/community-support/training-resources.md)
- [Get Help and Use the BloodHound Community](https://bloodhound.specterops.io/resources/community-support/getting-help.md)

#### Release Notes

- [Release Summary](https://bloodhound.specterops.io/resources/release-notes/summary.md): Stay informed about new features, enhancements, and fixed issues in the latest BloodHound releases.
- [2026-09-08 Release Notes](https://bloodhound.specterops.io/resources/release-notes/2026-09-08.md): Learn about new features, enhancements, and fixed issues in BloodHound.
- [2026-08-18 Release Notes](https://bloodhound.specterops.io/resources/release-notes/2026-08-18.md): Learn about new features, enhancements, and fixed issues in BloodHound.

##### Archive

###### 2026

- [2026-08-04 Release Notes](https://bloodhound.specterops.io/resources/release-notes/2026-08-04.md): Learn about new features, enhancements, and fixed issues in BloodHound.
- [2026-07-29 Release Notes](https://bloodhound.specterops.io/resources/release-notes/2026-07-29.md): Learn about new features, enhancements, and fixed issues in BloodHound.
- [2026-07-07 Release Notes](https://bloodhound.specterops.io/resources/release-notes/2026-07-07.md): Learn about new features, enhancements, and fixed issues in BloodHound.
- [2026-06-17 Release Notes](https://bloodhound.specterops.io/resources/release-notes/2026-06-17.md): Learn about new features, enhancements, and fixed issues in BloodHound.
- [2026-05-28 Release Notes](https://bloodhound.specterops.io/resources/release-notes/2026-05-28.md): Learn about new features, enhancements, and fixed issues in BloodHound.
- [2026-05-06 Release Notes](https://bloodhound.specterops.io/resources/release-notes/2026-05-06.md): Learn about new features, enhancements, and fixed issues in BloodHound.
- [2026-04-13 Release Notes](https://bloodhound.specterops.io/resources/release-notes/2026-04-13.md): Learn about new features, enhancements, and fixed issues in BloodHound.
- [2026-03-23 Release Notes](https://bloodhound.specterops.io/resources/release-notes/2026-03-23.md): Learn about new features, enhancements, and fixed issues in BloodHound.
- [2026-03-04 Release Notes](https://bloodhound.specterops.io/resources/release-notes/2026-03-04.md): Learn about new features, enhancements, and fixed issues in BloodHound.
- [2026-02-11 Release Notes](https://bloodhound.specterops.io/resources/release-notes/2026-02-11.md): Learn about new features, enhancements, and fixed issues in BloodHound.
- [2026-01-22 Release Notes](https://bloodhound.specterops.io/resources/release-notes/2026-01-22.md): Learn about new features, enhancements, and fixed issues in BloodHound.

###### 2025

- [2025-12-02 Release Notes (v8.4.0)](https://bloodhound.specterops.io/resources/release-notes/v8-4-0.md)
- [2025-10-30 Release Notes (v8.3.0)](https://bloodhound.specterops.io/resources/release-notes/v8-3-0.md)
- [2025-09-23 Release Notes (v8.2.0)](https://bloodhound.specterops.io/resources/release-notes/v8-2-0.md)
- [2025-08-26 Release Notes (v8.1.0)](https://bloodhound.specterops.io/resources/release-notes/v8-1-0.md)
- [2025-07-29 Release Notes (v8.0.0)](https://bloodhound.specterops.io/resources/release-notes/v8-0-0.md)
- [2025-07-09 Release Notes (v7.6.0)](https://bloodhound.specterops.io/resources/release-notes/v7-6-0.md)
- [2025-06-17 Release Notes (v7.5.0)](https://bloodhound.specterops.io/resources/release-notes/v7-5-0.md)
- [2025-06-02 Release Notes (v7.4.1)](https://bloodhound.specterops.io/resources/release-notes/v7-4-1.md)
- [2025-05-27 Release Notes (v7.4.0)](https://bloodhound.specterops.io/resources/release-notes/v7-4-0.md)
- [2025-04-22 Release Notes (v7.3.0)](https://bloodhound.specterops.io/resources/release-notes/v7-3-0.md)
- [2025-04-03 Release Notes (v7.2.1)](https://bloodhound.specterops.io/resources/release-notes/v7-2-1.md)
- [2025-03-25 Release Notes (v7.2.0)](https://bloodhound.specterops.io/resources/release-notes/v7-2-0.md)
- [2025-03-06 Release Notes (v7.1.0)](https://bloodhound.specterops.io/resources/release-notes/v7-1-0.md)
- [2025-02-05 Release Notes (v7.0.0)](https://bloodhound.specterops.io/resources/release-notes/v7-0-0.md)
- [2025-01-14 Release Notes (v6.4.0)](https://bloodhound.specterops.io/resources/release-notes/v6-4-0.md)

###### 2024

- [2024-12-09 Release Notes (v6.3.0)](https://bloodhound.specterops.io/resources/release-notes/2024-12-09-v6-3-0.md)
- [2024-11-14 Release Notes (v6.2.0)](https://bloodhound.specterops.io/resources/release-notes/2024-11-14-v6-2-0.md)
- [2024-10-22 Release Notes (v6.1.0)](https://bloodhound.specterops.io/resources/release-notes/2024-10-22-v6-1-0.md)
- [2024-09-30 Release Notes (v6.0.0)](https://bloodhound.specterops.io/resources/release-notes/2024-09-30-v6-0-0.md)
- [2024-09-10 Release Notes (v5.15.0)](https://bloodhound.specterops.io/resources/release-notes/2024-09-10-v5-15-0.md)
- [2024-08-20 Release Notes (v5.14.0)](https://bloodhound.specterops.io/resources/release-notes/2024-08-20-v5-14-0.md)
- [2024-08-06 Release Notes (v5.13.1)](https://bloodhound.specterops.io/resources/release-notes/2024-08-06-v5-13-1.md)
- [2024-08-01 Release Notes (v5.13.0)](https://bloodhound.specterops.io/resources/release-notes/2024-08-01-v5-13-0.md)
- [2024-07-17 Release Notes (v5.12.0)](https://bloodhound.specterops.io/resources/release-notes/2024-07-17-v5-12-0.md)
- [2024-06-17 Release Notes (v5.11.0)](https://bloodhound.specterops.io/resources/release-notes/2024-06-17-v5-11-0.md)
- [2024-05-28 Release Notes (v5.10.0)](https://bloodhound.specterops.io/resources/release-notes/2024-05-28-v5-10-0.md)
- [2024-05-09 Release Notes (v5.9.0)](https://bloodhound.specterops.io/resources/release-notes/2024-05-09-v5-9-0.md)
- [2024-04-15 Release Notes (v5.8.1)](https://bloodhound.specterops.io/resources/release-notes/2024-04-15-v5-8-1.md)
- [2024-03-27 Release Notes (v5.8.0)](https://bloodhound.specterops.io/resources/release-notes/2024-03-27-v5-8-0.md)
- [2024-03-04 Release Notes (v5.7.0)](https://bloodhound.specterops.io/resources/release-notes/2024-03-04-v5-7-0.md)
- [2024-02-14 Release Notes (v5.6.0)](https://bloodhound.specterops.io/resources/release-notes/2024-02-14-v5-6-0.md)
- [2024-01-23 Release Notes (v5.5.0)](https://bloodhound.specterops.io/resources/release-notes/2024-01-23-v5-5-0.md)
- [2024-01-04 Release Notes (v5.4.0)](https://bloodhound.specterops.io/resources/release-notes/2024-01-04-v5-4-0.md)

###### 2023

- [2023-12-05 Release Notes (v5.3.0)](https://bloodhound.specterops.io/resources/release-notes/2023-12-05-v5-3-0.md)
- [2023-11-06 Release (v5.2.0 - BHE Only)](https://bloodhound.specterops.io/resources/release-notes/2023-11-06-v5-2-0.md)
- [2023-10-16 Release notes (v5.1.0)](https://bloodhound.specterops.io/resources/release-notes/2023-10-16-v5-1-0.md)
- [2023-09-19 Release Notes (v5.0.9)](https://bloodhound.specterops.io/resources/release-notes/2023-09-19-v5-0-9.md)
- [2023-08-31 Release Notes (v5.0.8)](https://bloodhound.specterops.io/resources/release-notes/2023-08-31-v5-0-8.md)
- [2023-08-30 Release Notes (v5.0.7)](https://bloodhound.specterops.io/resources/release-notes/2023-08-30-v5-0-7.md)
- [2023-08-08 Release Notes](https://bloodhound.specterops.io/resources/release-notes/2023-08-08.md)
- [2023-06-20 Release Notes](https://bloodhound.specterops.io/resources/release-notes/2023-06-20.md)
- [2023-05-16 Release Notes](https://bloodhound.specterops.io/resources/release-notes/2023-05-16.md)
- [2023-04-25 Release Notes](https://bloodhound.specterops.io/resources/release-notes/2023-04-25.md)
- [2023-04-13 Release Notes](https://bloodhound.specterops.io/resources/release-notes/2023-04-13.md)
- [2023-03-27 Release Notes](https://bloodhound.specterops.io/resources/release-notes/2023-03-27.md)
- [2023-03-06 Release Notes](https://bloodhound.specterops.io/resources/release-notes/2023-03-06.md)
- [2023-02-21 Release Notes](https://bloodhound.specterops.io/resources/release-notes/2023-02-21.md)
- [2023-02-07 Release Notes](https://bloodhound.specterops.io/resources/release-notes/2023-02-07.md)
- [2023-01-31 Release Notes](https://bloodhound.specterops.io/resources/release-notes/2023-01-31.md)
- [2023-01-18 Release Notes](https://bloodhound.specterops.io/resources/release-notes/2023-01-18.md)

###### 2022

- [2022-12-19 Release Notes](https://bloodhound.specterops.io/resources/release-notes/2022-12-19.md)
- [2022-12-13 Release Notes](https://bloodhound.specterops.io/resources/release-notes/2022-12-13.md)
- [2022-11-21 Release Notes](https://bloodhound.specterops.io/resources/release-notes/2022-11-21.md)
- [2022-11-03 Release Notes](https://bloodhound.specterops.io/resources/release-notes/2022-11-03.md)
- [2022-10-24 Release Notes](https://bloodhound.specterops.io/resources/release-notes/2022-10-24.md)
- [2022-10-11 Release Notes](https://bloodhound.specterops.io/resources/release-notes/2022-10-11.md)
