Findings Table General Availability
Findings Prioritization Early Access
This feature is available through Early Access. Enable Findings Prioritization on the Administration > Early Access Features page to access it.
Active Directory Sites support
BloodHound now ingests and analyzes Active Directory Sites, SiteServer, and SiteSubnet objects, including their containment, ACLs, site-linked GPOs, and ServerIs relationships.Community contributionThank you to Quentin Roland for contributing this enhancement!
Tier Zero zone rules
Zone Builder now include two corresponding default rules for the Tier Zero zone:- Sites: Classifies Active Directory Site objects as Tier Zero because control over a site can enable compromise of the assets associated with it through linked Group Policy Objects.
- Domain Controller Site Servers: Classifies Site Server objects that reference Domain Controllers as Tier Zero because a malicious Group Policy Object linked to the Site could compromise the Domain Controller and its domain.
API endpoints
The API exposes the following endpoints:- Site
- Entity details:
/api/v2/sites/{object_id} - Controllers:
/api/v2/sites/{object_id}/controllers - Linked GPOs:
/api/v2/sites/{object_id}/linked-gpos - Site servers:
/api/v2/sites/{object_id}/siteservers - Site subnets:
/api/v2/sites/{object_id}/sitesubnets
- Entity details:
- Site Server: Entity details at
/api/v2/siteservers/{object_id} - Site Subnet: Entity details at
/api/v2/sitesubnets/{object_id} - GPO-to-Site: Affected Sites at
/api/v2/gpos/{object_id}/sites
DependencyThis enhancement requires upgrading to SharpHound v2.17.0 to collect the corresponding Active Directory Sites data.
Findings
Active Directory Sites collection
Collect Active Directory Sites data with SharpHound v2.17.0.SharpHound now collects Active Directory Sites, SiteServer, and SiteSubnet objects, including site-to-server and site-to-subnet mappings, site-linked GPOs, and ACLs on Site objects.Community contributionThank you to Quentin Roland for contributing this enhancement!
Active Directory collection coverage
Collect additional Active Directory structure and metadata with SharpHound v2.17.0.SharpHound now collects theBuiltin object and models it as a Container, including its well-known principal handling.Collected Active Directory nodes also expose the directory object’s objectClass as a node property.More useful Explore search results
Distinguish duplicate node names in the suggested results shown while typing in the Explore search or pathfinding text field.Suggested results now include the node’s distinguished name when multiple nodes share the same display name, making it easier to identify the correct object before opening it.Explicit empty values in the Entity Panel
See when a collected node property has an explicit empty value in the Entity Panel.The Entity Panel now preserves and displays empty arrays asNONE, and empty strings and null values as —, instead of hiding the properties outright.Accessible labels identify each placeholder as an empty array with zero values, an empty string, or a null value, making states such as empty EffectiveEKUs visible during investigation.Database Management access control
Keep the Database Management page limited to administrators.Read-only users can no longer discover or open a page that presents destructive data-wipe controls that they cannot use.Parameterized PostgreSQL query formatting
BloodHound now extracts string literal values from queries into bound parameters, reducing injection risk while preserving query behavior.These generated parameters are carried through query execution and translation caching, including values used in predicates, inserts, updates, and arrays.Responsive and accessible workflows
Use key BloodHound workflows more reliably at smaller widths, higher zoom levels, and with assistive technology.- The main navigation now automatically expands or contracts when the viewport crosses the
xlbreakpoint while respecting the user’s expansion or collapse preference. - Explore and Zone Builder now expose clearer page and table headings for screen-reader navigation.
- Explore table sorting now retains keyboard focus after a column is sorted.
- Attack Paths finding rows now reflow their content at smaller widths.
- The Manage Clients table now preserves semantic cell navigation for JAWS users.
- Attack Paths graph and information panels now respond more reliably to smaller viewport widths.
Custom client identifiers for IWA authentication
sub when no custom claim is configured), requires an exact non-empty string match, and then applies the existing issuer, audience, signature, and time-based token validation before authenticating the resolved client.Cleaner collector scheduling dialogs
Faster support bundle creation
log_archive ZIP files.This avoids unnecessary CPU work while preserving the archived logs in the bundle.Archived finding timestamps in the API
archived_at response field in the List attack path findings API to distinguish findings that have been archived from active findings. See Finding status lifecycle for more information.The field is returned as a timestamp when a finding has been archived and is omitted when it has not.Fixed Issues
Fixed Issues
The following issues have been fixed in this release:Administration
API
Resolved an issue where Entity Panels failed to render linked nodes after node information was enriched by the API at runtime.Cypher
- Resolved an issue where the Cypher-to-SQL translator could generate invalid SQL for a mixed predicate after a variable-length traversal.
- Resolved an issue where canceled request contexts could prevent the Cypher query audit log from being created.
Explore
- Resolved an issue where a node’s non-display kind could take precedence over its display kind, causing the Entity Panel header to show the wrong icon.
- Resolved an issue where node kind tooltip labels were not consistently visible above the search and pathfinding results list.
Zone Builder
- Resolved an issue where the node count table could overlap the zone details description on small screens.