BloodHound maps Active Directory attack paths as a graph โ 'Helpdesk โ 3 hops โ Domain Admin' becomes visible. Red teams plan with it; blue teams use it to cut those paths.
Follow the steps โ click any step card to replay the terminal demo from that point. Everything runs in a lab you control.
SharpHound (C#) on Windows or bloodhound-python from Kali.
Neo4j database + GUI = the map.
One click shows who can become god-mode and how.
Simulate: 'if I phish THIS user, where do I end up?'
Delete the accidental path = delete the attack. Purple-team gold.
| SharpHound.ps1/.exe | Windows collector |
| bloodhound-python | Kali collector |
| -c All | collect everything |
| owned nodes | mark compromised |
| custom cypher | expert queries |
TryHackMe's 'Attacktive Directory' & 'Post-Exploitation Basics' rooms set this up gently.
In real AD labs (GOAD), your first action after creds: collect + map.
Defenders: audit for paths INTO Tier-0 (DA/Enterprise Admins) regularly.
Impacket + BloodHound + NetExec is the holy AD attack trinity.
Use BloodHound only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox โ plenty of legal targets, zero risk.