Skip to main content
Use the filters on the right side of this page to narrow down the updates by component. You can select multiple filters at the same time to refine your results.
Upcoming collector deprecationBloodHound Enterprise will soon ingest collector property values exactly as collectors send them instead of normalizing values during ingest. Older AzureHound and OpenHound versions depend on server-side normalization and can create duplicate nodes or identity mismatches when this change is enabled.Starting with the November 2026 release, BloodHound Enterprise will reject client and file ingest uploads from deprecated AzureHound and OpenHound versions.Upgrade to AzureHound v3.1.0 or later and OpenHound v0.3.0 or later before then to keep data collection compatible with future versions of BloodHound Enterprise.
Attack Paths
New Feature

Findings Table General Availability

Applies to BloodHound Enterprise onlyThe Findings Table feature is now generally available. Triage findings more efficiently with clearer state and platform indicators, and new copy actions.Findings display a cross-platform badge when appropriate, use distinct muted styling and status icons for accepted, remediated, deprecated, and orphaned findings, and provide a floating action bar.
Attack Paths
New Feature

Findings Prioritization Early Access

Applies to BloodHound Enterprise onlyUse the Findings Prioritization feature as guidance to triage and remediate results in the Findings Table. When enabled, the Risk column replaces Severity and ranks findings by priority.
This feature is available through Early Access. Enable Findings Prioritization on the Administration > Early Access Features page to access it.
Data Collection
Enhancement

Active Directory Sites support

BloodHound now ingests and analyzes Active Directory Sites, SiteServer, and SiteSubnet objects, including their containment, ACLs, site-linked GPOs, and ServerIs relationships.
Community contributionThank you to Quentin Roland for contributing this enhancement!

Tier Zero zone rules

Zone Builder now include two corresponding default rules for the Tier Zero zone:
  • Sites: Classifies Active Directory Site objects as Tier Zero because control over a site can enable compromise of the assets associated with it through linked Group Policy Objects.
  • Domain Controller Site Servers: Classifies Site Server objects that reference Domain Controllers as Tier Zero because a malicious Group Policy Object linked to the Site could compromise the Domain Controller and its domain.

API endpoints

The API exposes the following endpoints:
DependencyThis enhancement requires upgrading to SharpHound v2.17.0 to collect the corresponding Active Directory Sites data.

Findings

Applies to BloodHound Enterprise onlyBloodHound Enterprise additionally surfaces the Tier Zero Computer Identified by Non-Tier Zero Site Server finding when a non-Tier Zero Site Server references a Tier Zero computer.
Data Collection
Enhancement

Active Directory Sites collection

Collect Active Directory Sites data with SharpHound v2.17.0.SharpHound now collects Active Directory Sites, SiteServer, and SiteSubnet objects, including site-to-server and site-to-subnet mappings, site-linked GPOs, and ACLs on Site objects.
Community contributionThank you to Quentin Roland for contributing this enhancement!
See Active Directory Sites support to learn about how BloodHound handles the collected Active Directory Sites data.
Data Collection
Enhancement

Active Directory collection coverage

Collect additional Active Directory structure and metadata with SharpHound v2.17.0.SharpHound now collects the Builtin object and models it as a Container, including its well-known principal handling.Collected Active Directory nodes also expose the directory object’s objectClass as a node property.
Explore
Enhancement

More useful Explore search results

Distinguish duplicate node names in the suggested results shown while typing in the Explore search or pathfinding text field.Suggested results now include the node’s distinguished name when multiple nodes share the same display name, making it easier to identify the correct object before opening it.
Explore
Enhancement

Explicit empty values in the Entity Panel

See when a collected node property has an explicit empty value in the Entity Panel.The Entity Panel now preserves and displays empty arrays as NONE, and empty strings and null values as —, instead of hiding the properties outright.Accessible labels identify each placeholder as an empty array with zero values, an empty string, or a null value, making states such as empty EffectiveEKUs visible during investigation.
Administration
Enhancement

Database Management access control

Keep the Database Management page limited to administrators.Read-only users can no longer discover or open a page that presents destructive data-wipe controls that they cannot use.
Cypher
Enhancement

Parameterized PostgreSQL query formatting

BloodHound now extracts string literal values from queries into bound parameters, reducing injection risk while preserving query behavior.These generated parameters are carried through query execution and translation caching, including values used in predicates, inserts, updates, and arrays.
Accessibility
Enhancement

Responsive and accessible workflows

Use key BloodHound workflows more reliably at smaller widths, higher zoom levels, and with assistive technology.
  • The main navigation now automatically expands or contracts when the viewport crosses the xl breakpoint while respecting the user’s expansion or collapse preference.
  • Explore and Zone Builder now expose clearer page and table headings for screen-reader navigation.
  • Explore table sorting now retains keyboard focus after a column is sorted.
Applies to BloodHound Enterprise onlyThe following changes apply to BloodHound Enterprise only:
  • Attack Paths finding rows now reflow their content at smaller widths.
  • The Manage Clients table now preserves semantic cell navigation for JAWS users.
  • Attack Paths graph and information panels now respond more reliably to smaller viewport widths.
Administration
Enhancement

Custom client identifiers for IWA authentication

Applies to BloodHound Enterprise onlyConfigure an optional Custom Client Identifier to control how BloodHound Enterprise resolves SharpHound Enterprise collector clients from Integrated Windows Authentication (IWA) bearer tokens.BloodHound Enterprise stores the identifier, reads the configured claim (or sub when no custom claim is configured), requires an exact non-empty string match, and then applies the existing issuer, audience, signature, and time-based token validation before authenticating the resolved client.
Data Collection
Enhancement

Cleaner collector scheduling dialogs

Applies to BloodHound Enterprise onlyManage SharpHound, AzureHound, and OpenHound schedules from refreshed dialogs on the Manage Clients page.The dialogs now have clearer spacing and field styling, with date, time, and recurrence controls that wrap cleanly at narrower widths.Time zone information appears directly in the time field, while SharpHound’s collection options and Advanced Options section use clearer labels, descriptions, and layout.
Data Collection
Enhancement

Faster support bundle creation

Applies to BloodHound Enterprise onlyBloodHound Enterprise now creates SharpHound Enterprise support bundles faster by skipping recompression of existing log_archive ZIP files.This avoids unnecessary CPU work while preserving the archived logs in the bundle.
API
Enhancement

Archived finding timestamps in the API

Applies to BloodHound Enterprise onlyUse the archived_at response field in the List attack path findings API to distinguish findings that have been archived from active findings. See Finding status lifecycle for more information.The field is returned as a timestamp when a finding has been archived and is omitted when it has not.
Fixed Issues

Fixed Issues

The following issues have been fixed in this release:

Administration

Applies to BloodHound Enterprise only Resolved an issue where interrupted collector support bundle uploads could leave unfinished operations or artifacts behind.

API

Resolved an issue where Entity Panels failed to render linked nodes after node information was enriched by the API at runtime.

Cypher

  • Resolved an issue where the Cypher-to-SQL translator could generate invalid SQL for a mixed predicate after a variable-length traversal.
  • Resolved an issue where canceled request contexts could prevent the Cypher query audit log from being created.

Explore

  • Resolved an issue where a node’s non-display kind could take precedence over its display kind, causing the Entity Panel header to show the wrong icon.
  • Resolved an issue where node kind tooltip labels were not consistently visible above the search and pathfinding results list.

Zone Builder

  • Resolved an issue where the node count table could overlap the zone details description on small screens.