> ## Documentation Index
> Fetch the complete documentation index at: https://bloodhound.specterops.io/llms.txt
> Use this file to discover all available pages before exploring further.

# 2026-10-07 Release Notes

> Learn about new features, enhancements, and fixed issues in BloodHound.

export const feature_0 = "Findings Prioritization"

<Tip>
  Use the filters on the right side of this page to narrow down the updates by component. You can select multiple filters at the same time to refine your results.
</Tip>

| | | | | |
| - | - | - | - | - |
| **Release** | **BloodHound** | **OpenHound** | **SharpHound** | **AzureHound** |
| 2026-10-07 | v9.8.0 | No release | v2.17.0 | No release |

<Warning>
  **Upcoming collector deprecation**

  BloodHound Enterprise will soon ingest collector property values exactly as collectors send them instead of normalizing values during ingest. Older AzureHound and OpenHound versions depend on server-side normalization and can create duplicate nodes or identity mismatches when this change is enabled.

  Starting with the November 2026 release, BloodHound Enterprise will reject client and file ingest uploads from deprecated AzureHound and OpenHound versions.

  Upgrade to AzureHound v3.1.0 or later and OpenHound v0.3.0 or later before then to keep data collection compatible with future versions of BloodHound Enterprise.
</Warning>

<Update label="BloodHound" description="New Feature" tags={["Attack Paths"]}>
  ## Findings Table <Badge color="green">General Availability</Badge>

  <img noZoom src="https://mintcdn.com/specterops/tTIczgde9H07oLXf/assets/enterprise-edition-pill-tag.svg?fit=max&auto=format&n=tTIczgde9H07oLXf&q=85&s=b682a26b342bde12302ec829e265bdb6" alt="Applies to BloodHound Enterprise only" style={{ width: "25%" }} width="225" height="45" data-path="assets/enterprise-edition-pill-tag.svg" />

  The [Findings Table](/analyze-data/findings/table-view) feature is now generally available. Triage findings more efficiently with clearer state and platform indicators, and new copy actions.

  Findings display a cross-platform badge when appropriate, use distinct muted styling and status icons for accepted, remediated, deprecated, and orphaned findings, and provide a floating action bar.
</Update>

<Update label="BloodHound" description="New Feature" tags={["Attack Paths"]}>
  ## Findings Prioritization <Badge color="yellow">Early Access</Badge>

  <img noZoom src="https://mintcdn.com/specterops/tTIczgde9H07oLXf/assets/enterprise-edition-pill-tag.svg?fit=max&auto=format&n=tTIczgde9H07oLXf&q=85&s=b682a26b342bde12302ec829e265bdb6" alt="Applies to BloodHound Enterprise only" style={{ width: "25%" }} width="225" height="45" data-path="assets/enterprise-edition-pill-tag.svg" />

  Use the [Findings Prioritization](/analyze-data/findings/table-view#prioritize-findings) feature as guidance to triage and remediate results in the **Findings Table**. When enabled, the **Risk** column replaces **Severity** and ranks findings by priority.

  <Note>
    This feature is available through Early Access. Enable **{feature_0}** on the **Administration** > **Early Access Features** page to access it.
  </Note>
</Update>

<Update label="BloodHound" description="Enhancement" tags={["Data Collection"]}>
  ## Active Directory Sites support

  BloodHound now ingests and analyzes Active Directory [Sites](/resources/nodes/site), [SiteServer](/resources/nodes/site-server), and [SiteSubnet](/resources/nodes/site-subnet) objects, including their containment, ACLs, site-linked GPOs, and [ServerIs](/resources/edges/server-is) relationships.

  <Callout icon="heart" color="#FFB74D">
    **Community contribution**

    Thank you to [Quentin Roland](https://www.linkedin.com/in/quentin-roland-07b944179/) for contributing this enhancement!
  </Callout>

  ### Tier Zero zone rules

  Zone Builder now include two corresponding [default rules](/analyze-data/privilege-zones/default-rules) for the Tier Zero zone:

  * **Sites:** Classifies Active Directory Site objects as Tier Zero because control over a site can enable compromise of the assets associated with it through linked Group Policy Objects.
  * **Domain Controller Site Servers:** Classifies Site Server objects that reference Domain Controllers as Tier Zero because a malicious Group Policy Object linked to the Site could compromise the Domain Controller and its domain.

  ### API endpoints

  The API exposes the following endpoints:

  * **Site**
    * Entity details: [`/api/v2/sites/{object_id}`](/reference/sites/get-site-entity-info)
    * Controllers: [`/api/v2/sites/{object_id}/controllers`](/reference/sites/get-site-entity-controllers)
    * Linked GPOs: [`/api/v2/sites/{object_id}/linked-gpos`](/reference/sites/get-site-entity-linked-gpos)
    * Site servers: [`/api/v2/sites/{object_id}/siteservers`](/reference/sites/get-site-entity-site-servers)
    * Site subnets: [`/api/v2/sites/{object_id}/sitesubnets`](/reference/sites/get-site-entity-site-subnets)
  * **Site Server:** Entity details at [`/api/v2/siteservers/{object_id}`](/reference/site-servers/get-site-server-entity-info)
  * **Site Subnet:** Entity details at [`/api/v2/sitesubnets/{object_id}`](/reference/site-subnets/get-site-subnet-entity-info)
  * **GPO-to-Site:** Affected Sites at [`/api/v2/gpos/{object_id}/sites`](/reference/gpos/get-gpo-entity-sites)

  <Note>
    **Dependency**

    This enhancement requires upgrading to SharpHound v2.17.0 to collect the corresponding [Active Directory Sites data](/resources/release-notes/2026-10-07#active-directory-sites-collection).
  </Note>

  ### Findings

  <img noZoom src="https://mintcdn.com/specterops/tTIczgde9H07oLXf/assets/enterprise-edition-pill-tag.svg?fit=max&auto=format&n=tTIczgde9H07oLXf&q=85&s=b682a26b342bde12302ec829e265bdb6" alt="Applies to BloodHound Enterprise only" style={{ width: "25%" }} width="225" height="45" data-path="assets/enterprise-edition-pill-tag.svg" />

  BloodHound Enterprise additionally surfaces the **Tier Zero Computer Identified by Non-Tier Zero Site Server** finding when a non-Tier Zero Site Server references a Tier Zero computer.
</Update>

<Update label="SharpHound" description="Enhancement" tags={["Data Collection"]}>
  ## Active Directory Sites collection

  Collect Active Directory Sites data with SharpHound v2.17.0.

  SharpHound now collects Active Directory [Sites](/resources/nodes/site), [SiteServer](/resources/nodes/site-server), and [SiteSubnet](/resources/nodes/site-subnet) objects, including site-to-server and site-to-subnet mappings, site-linked GPOs, and ACLs on Site objects.

  <Callout icon="heart" color="#FFB74D">
    **Community contribution**

    Thank you to [Quentin Roland](https://www.linkedin.com/in/quentin-roland-07b944179/) for contributing this enhancement!
  </Callout>

  See [Active Directory Sites support](/resources/release-notes/2026-10-07#active-directory-sites-support) to learn about how BloodHound handles the collected Active Directory Sites data.
</Update>

<Update label="SharpHound" description="Enhancement" tags={["Data Collection"]}>
  ## Active Directory collection coverage

  Collect additional Active Directory structure and metadata with SharpHound v2.17.0.

  SharpHound now collects the `Builtin` object and models it as a `Container`, including its well-known principal handling.

  Collected Active Directory nodes also expose the directory object's `objectClass` as a node property.
</Update>

<Update label="BloodHound" description="Enhancement" tags={["Explore"]}>
  ## More useful Explore search results

  Distinguish duplicate node names in the suggested results shown while typing in the **Explore** search or pathfinding text field.

  Suggested results now include the node's distinguished name when multiple nodes share the same display name, making it easier to identify the correct object before opening it.
</Update>

<Update label="BloodHound" description="Enhancement" tags={["Explore"]}>
  ## Explicit empty values in the Entity Panel

  See when a collected node property has an explicit empty value in the Entity Panel.

  The Entity Panel now preserves and displays empty arrays as `NONE`, and empty strings and null values as `—`, instead of hiding the properties outright.

  Accessible labels identify each placeholder as an empty array with zero values, an empty string, or a null value, making states such as empty `EffectiveEKUs` visible during investigation.
</Update>

<Update label="BloodHound" description="Enhancement" tags={["Administration"]}>
  ## Database Management access control

  Keep the **Database Management** page limited to administrators.

  Read-only users can no longer discover or open a page that presents destructive data-wipe controls that they cannot use.
</Update>

<Update label="BloodHound" description="Enhancement" tags={["Cypher"]}>
  ## Parameterized PostgreSQL query formatting

  BloodHound now extracts string literal values from queries into bound parameters, reducing injection risk while preserving query behavior.

  These generated parameters are carried through query execution and translation caching, including values used in predicates, inserts, updates, and arrays.
</Update>

<Update label="BloodHound" description="Enhancement" tags={["Accessibility"]}>
  ## Responsive and accessible workflows

  Use key BloodHound workflows more reliably at smaller widths, higher zoom levels, and with assistive technology.

  * &#x20;The main navigation now automatically expands or contracts when the viewport crosses the `xl` breakpoint while respecting the user's expansion or collapse preference.
  * &#x20;Explore and Zone Builder now expose clearer page and table headings for screen-reader navigation.
  * &#x20;Explore table sorting now retains keyboard focus after a column is sorted.

  <img noZoom src="https://mintcdn.com/specterops/tTIczgde9H07oLXf/assets/enterprise-edition-pill-tag.svg?fit=max&auto=format&n=tTIczgde9H07oLXf&q=85&s=b682a26b342bde12302ec829e265bdb6" alt="Applies to BloodHound Enterprise only" style={{ width: "25%" }} width="225" height="45" data-path="assets/enterprise-edition-pill-tag.svg" />

  The following changes apply to BloodHound Enterprise only:

  * &#x20;Attack Paths finding rows now reflow their content at smaller widths.
  * &#x20;The Manage Clients table now preserves semantic cell navigation for JAWS users.
  * &#x20;Attack Paths graph and information panels now respond more reliably to smaller viewport widths.
</Update>

<Update label="BloodHound" description="Enhancement" tags={["Administration"]}>
  ## Custom client identifiers for IWA authentication

  <img noZoom src="https://mintcdn.com/specterops/tTIczgde9H07oLXf/assets/enterprise-edition-pill-tag.svg?fit=max&auto=format&n=tTIczgde9H07oLXf&q=85&s=b682a26b342bde12302ec829e265bdb6" alt="Applies to BloodHound Enterprise only" style={{ width: "25%" }} width="225" height="45" data-path="assets/enterprise-edition-pill-tag.svg" />

  Configure an optional **Custom Client Identifier** to control how BloodHound Enterprise resolves SharpHound Enterprise [collector clients](/collect-data/enterprise-collection/create-collector#sharphound-enterprise) from Integrated Windows Authentication (IWA) bearer tokens.

  BloodHound Enterprise stores the identifier, reads the configured claim (or `sub` when no custom claim is configured), requires an exact non-empty string match, and then applies the existing issuer, audience, signature, and time-based token validation before authenticating the resolved client.
</Update>

<Update label="BloodHound" description="Enhancement" tags={["Data Collection"]}>
  ## Cleaner collector scheduling dialogs

  <img noZoom src="https://mintcdn.com/specterops/tTIczgde9H07oLXf/assets/enterprise-edition-pill-tag.svg?fit=max&auto=format&n=tTIczgde9H07oLXf&q=85&s=b682a26b342bde12302ec829e265bdb6" alt="Applies to BloodHound Enterprise only" style={{ width: "25%" }} width="225" height="45" data-path="assets/enterprise-edition-pill-tag.svg" />

  Manage SharpHound, AzureHound, and OpenHound schedules from refreshed dialogs on the **Manage Clients** page.

  The dialogs now have clearer spacing and field styling, with date, time, and recurrence controls that wrap cleanly at narrower widths.

  Time zone information appears directly in the time field, while SharpHound's collection options and **Advanced Options** section use clearer labels, descriptions, and layout.
</Update>

<Update label="SharpHound" description="Enhancement" tags={["Data Collection"]}>
  ## Faster support bundle creation

  <img noZoom src="https://mintcdn.com/specterops/tTIczgde9H07oLXf/assets/enterprise-edition-pill-tag.svg?fit=max&auto=format&n=tTIczgde9H07oLXf&q=85&s=b682a26b342bde12302ec829e265bdb6" alt="Applies to BloodHound Enterprise only" style={{ width: "25%" }} width="225" height="45" data-path="assets/enterprise-edition-pill-tag.svg" />

  BloodHound Enterprise now creates SharpHound Enterprise [support bundles](/collect-data/enterprise-collection/collector-support-bundles) faster by skipping recompression of existing `log_archive` ZIP files.

  This avoids unnecessary CPU work while preserving the archived logs in the bundle.
</Update>

<Update label="BloodHound" description="Enhancement" tags={["API"]}>
  ## Archived finding timestamps in the API

  <img noZoom src="https://mintcdn.com/specterops/tTIczgde9H07oLXf/assets/enterprise-edition-pill-tag.svg?fit=max&auto=format&n=tTIczgde9H07oLXf&q=85&s=b682a26b342bde12302ec829e265bdb6" alt="Applies to BloodHound Enterprise only" style={{ width: "25%" }} width="225" height="45" data-path="assets/enterprise-edition-pill-tag.svg" />

  Use the `archived_at` response field in the [List attack path findings](/reference/attack-paths/list-attack-path-findings) API to distinguish findings that have been archived from active findings. See [Finding status lifecycle](/analyze-data/findings/table-view#finding-status-lifecycle) for more information.

  The field is returned as a timestamp when a finding has been archived and is omitted when it has not.
</Update>

<Update label="BloodHound" tags={["Fixed Issues"]}>
  ## Fixed Issues

  The following issues have been fixed in this release:

  ### Administration

  <img noZoom src="https://mintcdn.com/specterops/tTIczgde9H07oLXf/assets/enterprise-edition-pill-tag.svg?fit=max&auto=format&n=tTIczgde9H07oLXf&q=85&s=b682a26b342bde12302ec829e265bdb6" alt="Applies to BloodHound Enterprise only" style={{ width: "25%" }} width="225" height="45" data-path="assets/enterprise-edition-pill-tag.svg" />

  &#x20;Resolved an issue where interrupted collector support bundle uploads could leave unfinished operations or artifacts behind.

  ### API

  &#x20;Resolved an issue where Entity Panels failed to render linked nodes after node information was enriched by the API at runtime.

  ### Cypher

  * &#x20;Resolved an issue where the Cypher-to-SQL translator could generate invalid SQL for a mixed predicate after a variable-length traversal.
  * &#x20;Resolved an issue where canceled request contexts could prevent the Cypher query audit log from being created.

  ### Explore

  * &#x20;Resolved an issue where a node's non-display kind could take precedence over its display kind, causing the Entity Panel header to show the wrong icon.
  * &#x20;Resolved an issue where node kind tooltip labels were not consistently visible above the search and pathfinding results list.

  ### Zone Builder

  * &#x20;Resolved an issue where the node count table could overlap the zone details description on small screens.
</Update>
