Learn about Attack Path findings in BloodHound Enterprise, including how to view, filter, and prioritize them for remediation.
The Attack Paths page in BloodHound Enterprise gives you a high-level overview of where identity risk exists, how much of your environment is exposed, and which areas need attention first.These risks are represented as findings. Findings include exposure and impact metrics that quantify risk, so you can assess overall risk in one place and then use those metrics to prioritize remediation as you drill into specific finding types.The Attack Paths page has two views:
Graph view (default)
Understand how risk concentrates in a selected environment and zone, view exposure and impact metrics, and expand finding details for remediation guidance.
Table view (beta)
Triage many findings at once, compare findings across environments and zones, and preserve filter and sort context in the page URL.
An Attack Path is a chain of abusable privileges and user behaviors that creates direct or indirect connections between principals.A finding is a specific instance of an Attack Path that BloodHound Enterprise has identified as a high-value remediation point. Findings can be relationship-based (abusable paths between principals) or principal-based (risky configurations on a principal).
Findings are organized by the environment of the target nodes, not the environment where the finding is defined.For example, an OpenGraph extension can define a finding that targets Active Directory nodes. That finding appears under the relevant Active Directory domain, not the OpenGraph environment.
A relationship-based finding identifies a directional path from a lower-privileged source principal to a privileged target asset.The path represents one or more abusable connections (potentially through intermediate principals or objects) through which the source principal can take control of the target. A single finding may include multiple Attack Paths when different intermediate nodes all enable the same type of access from source to target.Relationship-based findings can have an exposure metric and an impact metric.
A list-based finding identifies a vulnerability in a specific principal where the risk originates from the principal itself (like a misconfiguration).Because the vulnerability is inherent to the principal and not based on its connection to other principals, there is no exposure to measure.List-based findings do not have an exposure metric, but they will have an impact metric.