Netskope Threat Labs

BloodHound

ATP Sandbox Adv. HeuristicsAV

BloodHound is a legitimate open source tool that maps Active Directory and Azure environments to reveal privilege escalation paths, and security teams and cyberattackers both use it. Its collectors gather directory data, and its graph analysis highlights the shortest routes from a compromised account to high value targets such as domain administrators. Intrusion operators routinely abuse it for reconnaissance after gaining a foothold, which is why many organizations alert on its use in production environments.

First seen
May 2022
Last seen
October 2026
Bloodhound

11 techniques across 3 tactics.

TA0002 Execution

TA0007 Discovery

TA0009 Collection

  • T1560Archive Collected Data
Alert Name
Application.BloodHound.B
Application.BloodHound.C
Application.BloodHound.D
Gen:Variant.Application.BloodHound.1
Script-JS.Exploit.Bloodhound
Script-JS.Exploit.BloodHound
Script-PowerShell.Trojan.BloodHound
Win32.Malware.BloodHound
Win32.Trojan.BloodHound
Win64.Worm.BloodHound