Nyx Learning AD attack paths
AD attack paths

Active Directory attack paths, thinking in graphs

Nodes, edges, choke points, and BloodHound from both sides

Generated Wednesday, October 7, 2026 · Depth: deep · BloodHound versions and features (v9.8.0 and SharpHound v2.17.0 released 2026-10-07; Privilege Zones with Tier Zero in CE and custom zones in Enterprise; OpenGraph since v8.0, July 2025; hybrid AD/Entra paths) checked against SpecterOps release notes and documentation. Session-enumeration restrictions checked against SpecterOps' collection docs and Compass Security's SharpHound write-up. Choke points and blast radius in Microsoft Security Exposure Management checked against Microsoft Learn. ATT&CK mappings checked against the ATT&CK entry for BloodHound (S0521). Edge names follow BloodHound CE documentation; edge sets change between releases, so check the current docs.

01

Start here

What this note covers

This is a standalone note that ties together topics from the Kerberos series: delegation, roasting and ticket theft all show up here as edges. It covers how to see an Active Directory (AD) environment as a graph, how tools like BloodHound build and search that graph, the common edge families, and how defenders use the same graph to measure and remove risk.

Highlight key
the term being defined
Key term: bold with a highlighter swash. A concept's defining phrase.
how something works
Mechanism: wavy underline. How a piece works or relates to another.
Risk: what makes an attack possible
Risk: warm highlight with a dashed edge. Attack prerequisites and dangerous conditions.
Fix: the mitigation to apply
Fix: solid green underline. A mitigation or configuration change.
Verify: how to confirm it worked
Verify: green underline with a check. How to prove a fix works.
only if, by default
Qualifier: bold italic. A word that changes the claim.
4769
Technical literal: monospace chip. Commands, settings, event IDs, exactly as typed.

Plain English first

Active Directory is a huge web of "who can do what to whom": this person is in that group, that group can manage those accounts, this server lets those people log in, an administrator is logged on over there. Each fact on its own is mundane. An attack path is a chain of those facts that leads from an ordinary account to control of the whole domain.

People and spreadsheets review those facts one at a time. Attackers follow them like routes on a map. Tools such as BloodHound draw the map automatically: every object becomes a dot (a node), every abusable relationship becomes an arrow (an edge), and the computer finds the routes.

The same map works for defenders. Instead of fixing thousands of individual permissions, you find the few Fix: shared links that most routes pass through and cut those.

The analogy: a subway map of trust

Think of AD as a city's subway map. Stations are users, groups and computers; the lines between them are permissions and logons. An attacker doesn't care that each station looks unimportant. They care whether Risk: a line connects their station to the central one. Defenders usually keep a list of stations; attackers read the map. And just like a subway, most routes pass through a few interchange stations. Close the interchange and dozens of routes break at once.

Why it matters now

Attacker

Graph tooling turned AD privilege escalation from craft into routine. A collector run as any domain user Risk: maps the directory in minutes, and pathfinding finds routes no human would spot. Many internal tests now reach Tier 0 without exploiting a single software flaw, just by walking configuration.

Defender

The defender's version of the same graph is now mainstream. BloodHound Community Edition (CE) ships a Tier Zero zone and OpenGraph for other platforms, and BloodHound Enterprise and Microsoft Security Exposure Management prioritise choke points. Attack paths can be measured as a number (how many accounts can reach Tier 0) and driven down like any other risk.

If you remember only 5 things

  1. Privilege is transitive. If A controls B and B controls C, A controls C. No single record says so, which is why list-based reviews miss paths.
  2. Edges point the way control flows. Membership, local admin, logged-on sessions, directory permissions, Group Policy Object (GPO) links, delegation and certificates all become arrows an attacker can follow.
  3. Tier 0 is defined by control, not by label. Anything that can control a Domain Controller (DC) or an admin group Risk: is Tier 0, whatever its name, including sync, backup and deployment servers.
  4. Fix choke points, not paths. Most paths share a few edges. Fix: Remove the shared edge with the biggest exposure first, then re-collect.
  5. The graph is a model. It is only as complete as the collection behind it. A clean graph from partial data is false comfort; validate paths and collect with privilege.
02

Core concepts

Thirteen ideas, from "what is a graph" to managing paths continuously. Open "Go deeper" for expert detail.

01Lists versus graphsAttackers see the network as a graph of relationships, not a list of assets.
In plain terms

A defender's spreadsheet lists servers, admins and groups one row at a time. An attacker asks a different question: from where I stand, what can I reach next, and from there, what next? Answering that means thinking in connections, not rows.

Example

The list says "helpdesk users are not admins." The graph shows helpdesk users are local admins on a server where a domain admin is logged on, so in practice they are one hop from domain admin.

TechnicalGo deeper

Microsoft's John Lambert put it in 2015: "Defenders think in lists. Attackers think in graphs. As long as this is true, attackers win." BloodHound (2016, by Andy Robbins, Rohan Vazarkar and Will Schroeder) made the idea concrete for Active Directory (AD). The insight is that Risk: privilege is transitive: if A controls B and B controls C, A controls C, even though no single row anywhere says so.

02NodesA node is a thing in the directory: a user, group, computer, Group Policy Object (GPO), Organizational Unit (OU), domain or certificate object.
In plain terms

Every object that can hold or grant access is a dot on the map. Users and computers are the obvious ones, but containers, policies and certificate templates are nodes too, because controlling them confers control over other things.

Example

In a typical domain graph: User jdoe, Group IT-Support, Computer FS01, GPO Workstation Baseline, OU Servers, Domain corp.example.

TechnicalGo deeper

BloodHound keys nodes on Security Identifiers (SIDs) or object Globally Unique Identifiers (GUIDs), so a renamed account stays the same node. Beyond the core Active Directory (AD) types it models CertTemplate, EnterpriseCA, RootCA, NTAuthStore and AIACA for Active Directory Certificate Services (AD CS), Entra and Azure objects via AzureHound, and, since v8, arbitrary node types through OpenGraph. Computers are both principals (their machine account) and places where credentials live, which is why they sit at the center of so many paths.

03EdgesAn edge is a directed "can control" relationship from one node to another.
In plain terms

An arrow from A to B means "A can do something to B that helps an attacker." Direction matters: the arrow points the way control flows, which is the way an attacker moves.

Example

jdoe MemberOf IT-Support; IT-Support AdminTo FS01; FS01 HasSession admin-ash. Read left to right: jdoe can reach admin-ash's credentials.

TechnicalGo deeper

Edges fall into families: membership (MemberOf), host access (AdminTo, CanRDP, CanPSRemote, ExecuteDCOM), credential exposure (HasSession), directory permissions (GenericAll, GenericWrite, WriteDacl, WriteOwner, Owns, ForceChangePassword, AddMember, AllExtendedRights), secrets (ReadLAPSPassword, ReadGMSAPassword), containment and policy (Contains, GPLink), delegation (AllowedToDelegate, AllowedToAct), replication (DCSync) and certificates (ADCSESC1 and friends). An edge says an abuse is possible, not that it is quiet or easy; each has its own tradecraft and evidence.

04Attack pathsAn attack path is a chain of edges from a node the attacker holds to a node they want.
In plain terms

Join edges end to end and you get a route. Each hop on its own may look harmless; Risk: the danger is the chain. Graph tools search millions of possible chains in seconds and show the short ones.

Example

Phished user → MemberOf Helpdesk → AdminTo APP07 → HasSession svc_backup → MemberOf Backup Operators → Tier 0.

TechnicalGo deeper

Pathfinding is classic graph search (shortest path by hop count). Hop count is a convenient proxy, not a cost model: a two-hop path through an EDR-protected host may be harder than a five-hop Access Control List (ACL) chain. BloodHound Enterprise and newer Community Edition (CE) features add exposure scoring and multi-destination pathfinding, but the analyst still judges which hops are realistic in this environment.

05Tier 0 and Privilege ZonesTier 0 is everything that controls the domain, plus anything that controls those things.
In plain terms

Some objects are the crown jewels: domain controllers, the admin groups, the account that signs Kerberos tickets. But Tier 0 is defined by control, not by label. If a server can push software to a Domain Controller (DC), that server is Tier 0 too, whatever its spreadsheet row says.

Example

DCs, Domain Admins, Enterprise Admins, krbtgt, enterprise Certificate Authoritys (CAs), the Entra Connect server, System Center Configuration Manager (SCCM) site servers, and backup servers that store DC images.

TechnicalGo deeper

BloodHound Community Edition (CE) ships a default Tier Zero Privilege Zone; legacy BloodHound called the same idea "high value." BloodHound Enterprise adds custom zones (a server tier, a payments zone) and certification of membership. The working rule: Risk: any inbound path into Tier 0 from outside it is a finding, because it means Tier 0 is bigger than you think. Tier 0 sprawl, where dozens of systems quietly qualify, is the most common root cause in mature environments.

06Group membership and nestingMembership edges mean a member inherits everything the group can do, through every level of nesting.
In plain terms

Put a group inside another group and every member of the inner one gets the outer one's rights. After a decade of reorganisations, Risk: nesting hides who is really privileged. The graph flattens it.

Example

jdoe is in Regional-IT, which is in Server-Ops-Global, which is in Administrators on the domain. Nobody ever added jdoe to an admin group directly.

TechnicalGo deeper

MemberOf is traversed for free in path queries. Watch the built-in operator groups (Account Operators, Server Operators, Backup Operators, Print Operators): Risk: they have Tier 0-equivalent abuse paths (logon to Domain Controllers (DCs), backup rights, control of non-protected groups) and are often forgotten. Domain Users, Authenticated Users and Everyone are also nodes, so Risk: an edge from one of them means every account in the domain has that path.

07Local admin rights and sessionsAdminTo plus HasSession is the credential-theft hop: admin on a box where a privileged user is logged on.
In plain terms

When someone logs on to a Windows machine, traces of their credentials stay in memory. Anyone who is local admin on that machine can usually extract them and become that person. So "who is admin where" and "who is logged on where" together form a path.

Example

The helpdesk group is local admin on every workstation (a common build default). A domain admin Remote Desktop Protocols (RDPs) to one workstation to fix a printer. Every helpdesk member now has a path to domain admin.

TechnicalGo deeper

This is "derivative local admin": admin on host A gives a session for user B, who is admin on host C, and so on. Defenses that cut it: Fix: unique local admin passwords (LAPS), tiered admin accounts so Tier 0 credentials never touch workstations, Protected Users and Credential Guard to reduce what is left in memory, and Restricted Admin or Remote Credential Guard for RDP. Session data is a snapshot; it decays within hours, so it is collected repeatedly.

08Access Control List (ACL) edgesACL edges are directory permissions that let one principal modify another.
In plain terms

Every Active Directory (AD) object carries a list of who can change it. If you can change a user's password, add members to a group, or rewrite an object's permissions, Risk: you effectively control that object. These grants pile up from tools, migrations and help-desk delegations nobody revisits.

Example

IT-Support has ForceChangePassword on all users in the Staff Organizational Unit (OU), which also contains a forgotten account that is a member of Domain Admins.

TechnicalGo deeper

The common abusable rights: GenericAll (full control), GenericWrite (write most attributes: set an Service Principal Name (SPN) to Kerberoast, set Resource-Based Constrained Delegation (RBCD), add shadow credentials), WriteDacl (grant yourself anything), WriteOwner and Owns (owners can rewrite the Discretionary Access Control List (DACL)), AddMember/AddSelf on groups, ForceChangePassword, AllExtendedRights, and AddKeyCredentialLink. Inheritance from OUs spreads them. AdminSDHolder and SDProp reset the ACLs of protected accounts hourly, which protects members of built-in admin groups but not custom privileged groups.

09Containers and Group PolicyControl of an Organizational Unit (OU) or a linked Group Policy Object (GPO) is control of everything beneath it.
In plain terms

OUs hold objects; GPOs push settings, including scripts and scheduled tasks, to the objects in the OUs they are linked to. Risk: Edit a GPO and you run code on every computer it applies to.

Example

A desktop team can edit the "Workstation Baseline" GPO, which is also linked to the Domain Controllers OU by mistake. That team now has a path to every Domain Controller (DC).

TechnicalGo deeper

Edges: Contains (OU or domain to child), GPLink (GPO to the container it applies to), and Access Control List (ACL) edges on the GPO object itself. Inheritance flags on an OU's Access Control Entrys (ACEs) decide whether rights flow to children. Block inheritance and enforced links change which GPOs actually apply, and collectors model this imperfectly, so verify GPO paths in the Group Policy Management Console before reporting them.

10CollectionCollection is reading the directory and hosts to build the graph, mostly with ordinary user rights.
In plain terms

By design, almost any domain user can read almost all of Active Directory (AD) over Lightweight Directory Access Protocol (LDAP): users, groups, memberships and most permissions. Risk: No exploit is needed to map the domain. Host data (who is logged on, who is local admin) needs extra queries to each computer.

Example

A collector runs as a phished user, makes LDAP queries to a Domain Controller (DC), then contacts each computer for sessions and local groups, and writes a zip of JavaScript Object Notation (JSON) files for upload.

TechnicalGo deeper

Collectors: SharpHound (Windows, C#), BloodHound.py's CE-compatible version and RustHound-CE (from non-Windows hosts), AzureHound for Entra and Azure, and OpenHound and OpenGraph collectors for other platforms. Since Windows 10 1607 and Server 2016, remote Security Account Manager Remote protocol (SAMR) is restricted to administrators by default, and session enumeration Application Programming Interfaces (APIs) increasingly need admin too, so a low-privilege collection is strong on directory data and weak on sessions. Defenders collecting with a privileged account get a far more complete graph than attackers usually do.

11Model versus realityThe graph is a model of possible abuse, not proof that a path works today.
In plain terms

Data goes stale, collection misses things, and some edges are hard to use in practice. A path on screen is a hypothesis to validate, and an absence of paths is only as good as the collection behind it.

Example

A path relies on a session that was there at 09:00 and gone by noon; another relies on a host the collector couldn't reach, so it doesn't appear at all.

TechnicalGo deeper

Sources of error: stale sessions, unreachable hosts, deny Access Control Entrys (ACEs) and edge-case inheritance, Group Policy Object (GPO) filtering, controls the graph doesn't know about (Endpoint Detection and Response (EDR), tiered logon restrictions, authentication silos), and edges whose abuse needs conditions outside the data. False negatives are the dangerous ones: a clean graph from a partial collection is false comfort. Good testers validate the chosen path; good defenders collect with full privilege and on a schedule.

12Choke points and blast radiusA choke point is an edge or node many paths pass through; removing it cuts them all.
In plain terms

Thousands of paths to Tier 0 often funnel through a handful of relationships. Fix the funnel, not the thousands. The flip side is blast radius: everything one compromised node can reach.

Example

1,800 users have a path to Domain Admins, and 1,750 of those paths cross one edge: Helpdesk AdminTo a jump server where admins leave sessions. Remove that one edge and exposure drops by 97%.

TechnicalGo deeper

Inbound analysis ("who can reach Tier 0?") drives remediation; outbound analysis ("what can this phished user reach?") drives incident scoping and findings narratives. BloodHound Enterprise ranks choke points by how many principals each one exposes, and Microsoft Security Exposure Management shows choke points and blast radius for its own attack paths. Fix: Fix the edge with the biggest exposure first, then re-collect, because removing one funnel often reveals the next.

13Attack path managementAttack path management is continuously measuring and shrinking paths to what matters.
In plain terms

One test gives a snapshot. Environments change daily: new hires, new groups, new servers. Attack Path Management (APM) treats paths like any other recurring risk, collect, measure, fix, verify, repeat, and reports a trend.

Example

A monthly report: "Principals with a path to Tier 0: 41% in January, 6% in June, after removing three choke points and enforcing admin tiering."

TechnicalGo deeper

Inputs: scheduled privileged collection, a maintained Tier 0 definition (Privilege Zones), and change detection on the directory. Outputs: exposure percentages, choke-point lists, and Verify: alerts when a new path to Tier 0 appears. Hybrid identity widens the graph: AzureHound data plus Active Directory (AD) data lets BloodHound render paths that cross from on-premises to Entra ID and back, and OpenGraph extensions add platforms such as GitHub and Okta. Commercial options exist (BloodHound Enterprise, Microsoft Security Exposure Management, and other exposure-management products); capabilities and licensing change often, so compare current versions.

03

Visual map

Step through how the graph gets built, two classic attack paths, and the defender's choke-point cut. Verify: Each attack step names the defense that breaks it.

The main edge families

FamilyExample edgesWhat it meansTypical root cause
MembershipMemberOfInherit the group's rightsDeep nesting, privileged groups inside managed groups
Host accessAdminTo, CanRDP, CanPSRemote, ExecuteDCOMLog on or run code on a computerHelpdesk admin everywhere, shared local passwords
Credential exposureHasSessionA user's credentials may be in memory on a hostRisk: Tier 0 admins logging on to lower tiers
Directory permissionsGenericAll, GenericWrite, WriteDacl, WriteOwner, Owns, ForceChangePassword, AddMember, AllExtendedRightsModify another objectOld delegations, migration leftovers, broad grants
SecretsReadLAPSPassword, ReadGMSAPassword, SyncLAPSPasswordRead a stored passwordLocal Administrator Password Solution (LAPS) read rights scoped too widely
Containers and policyContains, GPLinkControl flows to objects insideGroup Policy Object (GPO) edit rights delegated broadly
Delegation and replicationAllowedToDelegate, AllowedToAct, DCSyncImpersonate users or pull hashesDelegation flags, replication rights on non-DCs
CertificatesADCSESC1, ADCSESC3, GoldenCert, and moreObtain a certificate that authenticates as someone elseRisk: Weak templates with broad enrollment
Trust and hybridTrustedBy, HasSIDHistory, hybrid AD-to-Entra edgesCross a domain or cloud boundarySecurity Identifier (SID) history, synced cloud admins

Ways to see the graph

ApproachWho uses itStrengthsLimits
BloodHound Community Edition (CE)Testers, defendersFree, open source, Tier Zero zone, Cypher, OpenGraphYou run collection and analysis yourself
BloodHound EnterpriseDefendersContinuous collection, custom Privilege Zones, choke-point prioritisationCommercial; value depends on someone acting on it
Microsoft Security Exposure ManagementMicrosoft-centric defendersAttack paths, choke points and blast radius across Defender dataPaths depend on Microsoft's own models and licensing
PingCastle, Purple Knight and similarDefenders, auditorsFast health-check scores and known-bad settingsList-style checks; limited path chaining
Manual review (Active Directory Users and Computers (ADUC), PowerShell)AdminsNo new toolsRisk: Can't see chains; this is the list problem
04

Technical deep dive

Technical

Under the hood

The data model

BloodHound stores a directed property graph: nodes with types and properties (name, Security Identifier (SID), enabled, last logon, admincount, Tier Zero membership), and typed edges between them. Pathfinding is a graph search over edge types that are marked traversable. Some edges are collected directly (an Access Control Entry (ACE), a membership); others are post-processed, derived after ingest from combinations of data, such as Active Directory Certificate Services (AD CS) escalation edges built from template, Certificate Authority (CA) and enrollment data.

Nodes are keyed on SID or object Globally Unique Identifier (GUID), so renames don't break history, and data from several collections merges into one graph.

How collection works

  1. Directory (LDAP). Users, groups, computers, Organizational Units (OUs), Group Policy Objects (GPOs), containers, domains, trusts, AD CS objects, and each object's nTSecurityDescriptor. Readable by any authenticated user by default, apart from a few protected attributes (Local Administrator Password Solution (LAPS) passwords, for example).
  2. Hosts (Server Message Block (SMB)/Remote Procedure Call (RPC)). For each reachable computer: sessions (NetSessionEnum, NetWkstaUserEnum, Remote Registry) and local group membership over Security Account Manager Remote protocol (SAMR) or Local Security Authority (LSA) calls. Windows 10 1607 and Server 2016 onward Risk: restrict remote SAMR to administrators, and newer releases restrict session enumeration too, so a low-privilege collector sees far less here.
  3. Ingest and post-processing. The collector writes JavaScript Object Notation (JSON) files (usually zipped). BloodHound ingests them, then computes derived edges and zone membership.

Collection methods matter for noise and completeness:

Method (SharpHound)TouchesGivesNotes
DCOnlyDomain Controllers (DCs) only, over LDAPObjects, Access Control Lists (ACLs), memberships, GPOs, trusts, delegation, AD CSQuietest; no sessions or local groups
DefaultDCs plus every computerAdds sessions and local groupsFan-out to every host is noisy
AllEverythingAdds more host and certificate detailNoisiest, most complete
Session with --loopEvery computer, repeatedlyFresh session data over timeSessions are snapshots, so looping catches more

Edges in detail: the ones that come up most

  • MemberOf. Free to traverse. The built-in operator groups (Account, Server, Backup, Print Operators) are Risk: effectively Tier 0; check their membership first.
  • AdminTo and HasSession. The credential-theft pair. AdminTo comes from local Administrators membership (directly, by group, or by GPO-applied Restricted Groups). HasSession points from computer to user.
  • ForceChangePassword. Reset without knowing the old password. Effective but loud, and it locks the real user out, so testers often prefer quieter edges and many engagements forbid resets on live accounts.
  • GenericWrite. On a user: set an Service Principal Name (SPN) (targeted Kerberoasting) or add a key credential (shadow credentials). On a computer: set Resource-Based Constrained Delegation (RBCD). On a group: change membership.
  • WriteDacl, WriteOwner, Owns. Permission-on-permission. Risk: Any of these is full control one step later.
  • AllExtendedRights. Includes reset password and, on the domain object, the replication rights behind DCSync.
  • GPLink plus GPO write. Code execution on every computer in scope at next policy refresh.
  • CoerceToTGT and delegation edges. Hosts trusted for unconstrained delegation can capture a coerced Ticket Granting Ticket (TGT); AllowedToAct is RBCD (see Kerberos Part 3).
  • AD CS edges. Built in post-processing from templates, CAs, the NTAuth store and enrollment rights. Often Risk: the shortest path in the whole graph.

AdminSDHolder and what it does (and doesn't) protect

Every hour, the SDProp process copies the ACL of the AdminSDHolder object onto members of built-in protected groups (Domain Admins, Enterprise Admins, Administrators, the operator groups and a few more) and sets admincount=1. That wipes stray ACEs on those accounts. It does not cover custom privileged groups, and admincount=1 lingers on accounts removed from protected groups, leaving them with odd, non-inheriting ACLs. If AdminSDHolder's own ACL is modified, Risk: the change propagates to every protected account, a known persistence technique.

Querying the graph

The Graphical User Interface (GUI) covers the common questions (shortest paths, inbound to Tier Zero, outbound from an owned node), and BloodHound Community Edition (CE) ships a library of pre-built searches. For anything custom, use Cypher, the graph query language. Typical defensive questions:

// Every principal holding DCSync; anything that isn't a DC or an approved sync account is a finding
MATCH (n)-[:DCSync]->(d:Domain)
RETURN n.name, d.name

// Shortest paths from Domain Users (RID 513) to Domain Admins (RID 512)
MATCH p=shortestPath((g:Group)-[*1..]->(t:Group))
WHERE g.objectid ENDS WITH '-513' AND t.objectid ENDS WITH '-512'
RETURN p

Common misconceptions

MisconceptionReality
"BloodHound needs admin rights."Directory collection works with any domain account. Admin rights only improve host data.
"No paths in the graph means no paths."Only if collection was complete. Unprivileged collection under-reports sessions and local admin.
"Our admin groups are small, so we're fine."Effective Tier 0 includes nesting, ACLs, sessions, GPOs, CAs and sync servers. Risk: It's usually far larger than the groups.
"The shortest path is the most dangerous."Hop count ignores difficulty and detection. Rank by exposure and realism.
"Fix every path the tool lists."Fix: Fix the shared edges; thousands of paths usually collapse to a handful of causes.
"BloodHound is an attacker tool; blocking it solves the problem."Blocking one binary changes nothing about the paths. Fix: Detect unauthorised collection and run it yourself.
"Multi-Factor Authentication (MFA) removes these paths."Most edges are used after authentication with permissions, hashes or tickets. MFA doesn't gate them.

Troubleshooting a graph

  • Few or no sessions: the collector lacked admin rights, hosts were unreachable (firewall, offline laptops), or session enumeration is restricted. Re-run with a privileged account from a well-connected host, and loop session collection.
  • Paths that don't work when tested: stale session, a deny ACE, GPO security filtering, or a control the graph doesn't model (logon restrictions, authentication silos, Endpoint Detection and Response (EDR)). Verify: Record why, and treat it as a data-quality note rather than a mistake.
  • Huge, unreadable path counts: group by shared edge and look at choke points; filter out paths through Tier Zero nodes themselves.
  • Missing AD CS edges: confirm the collector version supports AD CS collection and that CA and template objects were readable.
  • Old queries failing: zone labels and some edge names changed between releases; use the current schema.
05

Attacker's view

Attacker

Attacker's view, for defenders

Each technique below is covered at the level needed to recognise it, test for it and explain it: prerequisites, what makes an environment vulnerable, the evidence it leaves, and how it reads as a finding. Tools are named so you can build detections and a lab. Exploit steps for each edge are deliberately left out; the BloodHound documentation's per-edge abuse notes and an authorised lab (for example, a deliberately vulnerable Active Directory (AD) range) are the place for hands-on practice.

Graph collection (domain reconnaissance)ATT&CKT1087.002 Account Discovery: Domain Account · T1069.002 Permission Groups Discovery: Domain Groups · T1482 Domain Trust Discovery · T1018 Remote System Discovery
How it works

The attacker runs a collector as any domain account. It reads objects, memberships and Access Control Lists (ACLs) over Lightweight Directory Access Protocol (LDAP), then contacts hosts for sessions and local group membership, and packages the result for BloodHound. Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK) catalogues BloodHound as software S0521.

Prerequisites

Risk: Any authenticated domain account and network reach to a Domain Controller (DC); host-level data needs reach to each computer and, on modern Windows, usually admin rights there.

What makes an environment vulnerable

Every Active Directory (AD) domain is readable by its users by design. Exposure grows with Risk: no detection on bulk LDAP and Security Account Manager Remote protocol (SAMR) enumeration, wide-open session enumeration on older or unhardened hosts, and collectors allowed to run unnoticed.

Tools

SharpHound, BloodHound.py (CE-compatible version), RustHound-CE, AzureHound for Entra and Azure, Sysinternals AD Explorer snapshots (which can be converted for BloodHound). Defenders run the same tools with privileged accounts.

# Recognise these in command lines and process telemetry
SharpHound.exe -c All            # all collection methods
SharpHound.exe -c DCOnly         # LDAP-only, no host contact (quieter)
SharpHound.exe -c Session --loop # repeated session collection
DefenderEvidence it leaves

Bursts of LDAP queries for every user, group, computer and security descriptor from one workstation; Verify: Server Message Block (SMB) connections to srvsvc, wkssvc and samr pipes across many hosts; Microsoft Defender for Identity (MDI) reconnaissance alerts (LDAP, SAMR, user and Internet Protocol (IP) enumeration); Endpoint Detection and Response (EDR) detection of the collector binary or its zip output.

ExecutiveAs a pentest finding

Rarely a finding on its own, since reading the directory is intended. Report it as a detection gap if a full collection ran unnoticed. Retest: a collection from a standard workstation raises an alert within the agreed time.

Directory permission (ACL) abuseATT&CKT1098 Account Manipulation · T1222 File and Directory Permissions Modification (closest fit; ATT&CK has no single "AD ACL abuse" technique)
How it works

The attacker walks ACL edges: reset a password they're allowed to reset, add themselves to a group they can write, grant themselves rights with WriteDacl, or take ownership with WriteOwner. GenericWrite on a user enables targeted Kerberoasting (set an Service Principal Name (SPN)) or shadow credentials (AddKeyCredentialLink).

Prerequisites

Control of a principal that holds Risk: an abusable right on a more privileged object, directly or through group membership.

What makes an environment vulnerable

Broad rights granted to large groups; Risk: delegations to Helpdesk or Information Technology (IT) groups that cover privileged accounts; leftover Access Control Entrys (ACEs) from migrations, Exchange installs and old tools; custom admin groups outside AdminSDHolder protection; owners left as former admins.

Tools

BloodHound to find the edge; PowerView, the ActiveDirectory module, Impacket's dacledit, bloodyAD and Whisker/pyWhisker (shadow credentials) are what testers use to exercise it.

DefenderEvidence it leaves

Event 4738 (user changed), 4724 (password reset by another account), 4728/4732/4756 (member added to a security group), and Verify: 5136 for Discretionary Access Control List (DACL), owner, servicePrincipalName or msDS-KeyCredentialLink changes, provided directory-service change auditing and System Access Control Lists (SACLs) are on.

ExecutiveAs a pentest finding

"Excessive Active Directory (AD) permissions create a path from ordinary users to Domain Admins." Severity follows the size of the starting population and the target: Domain Users to Tier 0 is critical. Retest: the edge is gone in a fresh privileged collection and the abuse attempt fails.

Session hunting and derivative local adminATT&CKT1033 System Owner/User Discovery · T1003.001 OS Credential Dumping: LSASS Memory · T1550.002 Use Alternate Authentication Material: Pass the Hash · T1021 Remote Services
How it works

The attacker finds a host where they are local admin (AdminTo) and a more privileged user has a session (HasSession), extracts that user's credential material from memory, and repeats until reaching Tier 0.

Prerequisites

Local admin on at least one host, and Risk: privileged credentials present on hosts that lower tiers administer.

What makes an environment vulnerable

Risk: Shared local administrator passwords (no Local Administrator Password Solution (LAPS)); a helpdesk group that is admin everywhere; Domain Admins logging on to workstations and member servers; no Credential Guard; Remote Desktop Protocol (RDP) without Restricted Admin or Remote Credential Guard.

Tools

BloodHound session data (often refreshed in a loop), Mimikatz, Impacket, NetExec (formerly CrackMapExec), and Rubeus for ticket-based variants.

DefenderEvidence it leaves

Remote logon (4624 logon type 3 or 10) by an unusual account to many hosts, Verify: Local Security Authority Subsystem Service (LSASS) access events from Endpoint Detection and Response (EDR), 4672 special privileges at odd hosts, and NT LAN Manager (NTLM) authentication patterns consistent with pass-the-hash.

ExecutiveAs a pentest finding

"Privileged credentials exposed on lower-tier hosts." High to critical depending on which accounts were exposed and who administers those hosts. Retest: Tier 0 accounts are denied logon to lower tiers (policy), LAPS is deployed, and session data shows no Tier 0 sessions outside Tier 0.

Group nesting escalationATT&CKT1098.007 Account Manipulation: Additional Local or Domain Groups
How it works

The attacker uses AddMember, AddSelf or GenericAll on a group that sits inside a privileged group, several levels down, and adds an account they control.

Prerequisites

Write access to the membership of Risk: any group nested into a privileged one.

What makes an environment vulnerable

Deep or circular nesting; Risk: privileged groups nested into project or regional groups managed by non-Tier-0 staff; built-in operator groups with members.

Tools

BloodHound to see the nesting; net, PowerShell, bloodyAD or similar to add the member.

DefenderEvidence it leaves

Verify: 4728, 4732 or 4756 on a group whose effective privilege is Tier 0, even though the group's own name looks harmless. Alerting on effective privilege, not group name, is the key.

ExecutiveAs a pentest finding

"Delegated group management reaches a privileged group through nesting." Critical when the outer group is Tier 0. Retest: nesting flattened, Tier 0 groups contain only named individuals or approved groups, and membership changes alert.

Group Policy and Organizational Unit (OU) controlATT&CKT1484.001 Domain or Tenant Policy Modification: Group Policy Modification
How it works

The attacker edits a Group Policy Object (GPO) they can write, or links a GPO they control to an OU they can write, to push a script or scheduled task to every computer or user in scope.

Prerequisites

Write access to a GPO linked above valuable objects, or Risk: write access to an OU's gPLink attribute.

What makes an environment vulnerable

GPO edit rights delegated broadly; Risk: GPOs linked to the Domain Controllers OU or domain root that non-Tier-0 teams can edit; GPO files on SYSVOL with weak file permissions.

Tools

BloodHound (GPLink, GenericWrite on GPO), Group Policy Management Console, SharpGPOAbuse, pyGPOAbuse.

DefenderEvidence it leaves

Verify: 5136 on the GPO object (versionNumber, gPCMachineExtensionNames) and on OU gPLink; SYSVOL file changes; new scheduled tasks (event 4698) appearing across many hosts at once.

ExecutiveAs a pentest finding

"Non-administrative group can modify Group Policy that applies to domain controllers." Critical when the scope includes Domain Controllers (DCs) or Tier 0 servers. Retest: GPO and link permissions limited to Tier 0 admins for Tier 0 scopes, verified by collection and by the console's delegation tab.

Certificate (AD CS) edgesATT&CKT1649 Steal or Forge Authentication Certificates
How it works

Misconfigured certificate templates or Certificate Authoritys (CAs) let a low-privilege user request a certificate that authenticates as someone else, or control the CA itself. BloodHound models the well-known escalation classes as edges such as ADCSESC1, ADCSESC3 and GoldenCert.

Prerequisites

An enterprise CA trusted for authentication and Risk: a template or CA permission matching an escalation class, reachable by a principal the attacker controls.

What makes an environment vulnerable

Templates that let the requester supply the subject and allow client authentication; Risk: broad enrollment rights (Domain Users); write rights on templates or the CA; unpatched CA settings.

Tools

Certipy and Certify to enumerate and test; BloodHound Community Edition (CE) for the path view; Locksmith and PSPKIAudit for defensive review.

DefenderEvidence it leaves

CA events 4886 and 4887 (certificate requested and issued) with Verify: a subject that doesn't match the requester, template changes (4899, 4900), and Kerberos certificate logons (4768 with certificate fields).

ExecutiveAs a pentest finding

Often the shortest path in the report. Critical when Domain Users can reach a domain admin certificate. Retest: template fixed, enrollment narrowed, and the edge absent after re-collection. AD CS deserves its own note.

Delegation, replication and secret-reading edgesATT&CKT1003.006 OS Credential Dumping: DCSync · T1558 Steal or Forge Kerberos Tickets
How it works

Some edges hand over credentials directly. DCSync (GetChanges plus GetChangesAll) lets a principal pull password hashes from a Domain Controller (DC); AllowedToDelegate and AllowedToAct allow impersonation; ReadLAPSPassword and ReadGMSAPassword reveal secrets.

Prerequisites

Control of a principal holding Risk: replication rights, delegation configuration or secret-read rights.

What makes an environment vulnerable

Replication rights granted to non-DC accounts (old sync tools, Exchange leftovers); Risk: Local Administrator Password Solution (LAPS) read rights granted to the whole helpdesk, including for Tier 0 servers; RBCD-writable computer objects.

Tools

BloodHound for discovery; Impacket secretsdump and Mimikatz for DCSync; Rubeus and Impacket for delegation; LAPS and group Managed Service Account (gMSA) readers.

DefenderEvidence it leaves

Verify: 4662 with the replication extended-right Globally Unique Identifiers (GUIDs) from a non-DC; Microsoft Defender for Identity (MDI) DCSync alerts; 4769 with Service for User (S4U) patterns; LAPS password read auditing.

ExecutiveAs a pentest finding

DCSync held by a non-Tier-0 principal is a direct domain-compromise finding. Retest: replication rights only on DCs and approved sync accounts; LAPS read scoped per tier.

Hybrid and cross-trust pathsATT&CKT1482 Domain Trust Discovery · T1078.004 Valid Accounts: Cloud Accounts
How it works

Paths cross boundaries the org chart treats as separate: from one domain to another over trusts, and between on-premises Active Directory (AD) and Entra ID through synchronisation servers, synced admin accounts and cloud-managed devices.

Prerequisites

A trust or sync relationship plus Risk: a privileged identity or server that spans both sides.

What makes an environment vulnerable

Synced on-premises accounts holding cloud admin roles; Risk: an Entra Connect server not treated as Tier 0; intra-forest trusts assumed to be boundaries; Security Identifier (SID) history left after migrations.

Tools

BloodHound Community Edition (CE) with SharpHound plus AzureHound data (hybrid paths render when both are loaded); ROADtools for Entra; defensive views in Microsoft Security Exposure Management.

DefenderEvidence it leaves

Sign-ins from the sync server's account outside sync patterns; Verify: role assignment changes in Entra audit logs; cross-domain Kerberos referrals for unusual principals.

ExecutiveAs a pentest finding

"On-premises compromise extends to the cloud tenant" (or the reverse). Severity follows the far-side target, often global administrator. Retest: cloud admins are cloud-only accounts, the sync server is protected as Tier 0, and the hybrid path is gone.

How a graph-driven engagement usually runs

  1. Foothold and collection: an assumed-breach or phished account collects the directory, often DCOnly first for low noise.
  2. Mark owned, ask questions: shortest paths from owned principals to Tier Zero, plus Risk: inbound edges from Domain Users and Authenticated Users.
  3. Choose a realistic path: prefer quiet, reliable hops (Access Control List (ACL) edges, Active Directory Certificate Services (AD CS)) over noisy ones (password resets, Local Security Authority Subsystem Service (LSASS) access on EDR-heavy hosts).
  4. Validate hop by hop, gathering evidence for the report and Verify: noting which alerts fired.
  5. Report by root cause: group the paths found by the choke points they share, and lead with the validated one.
06

Defender's playbook

Defender

The strategy: define Tier 0 honestly, collect with privilege on a schedule, Fix: cut the choke points with the most exposure, keep Tier 0 credentials off lower tiers, and alert when a new edge into Tier 0 appears.

Quick wins (days)

  1. Run your own privileged collection and look at inbound paths to Tier Zero. Verify: Start from Domain Users, Authenticated Users and Everyone, since edges from them affect everyone.
    SharpHound.exe -c All --domain corp.example
  2. Review the built-in operator groups (Account, Server, Backup, Print Operators) and Fix: empty them unless there's a documented need.
    'Account Operators','Server Operators','Backup Operators','Print Operators' |
      ForEach-Object { Get-ADGroupMember $_ -Recursive | Select @{n='Group';e={$_}},Name }
  3. Remove Access Control Entrys (ACEs) granted to broad groups on users, groups, Organizational Units (OUs), Group Policy Objects (GPOs) and the domain object. Fix: Domain Users should hold no write rights on anything privileged.
    # Example: list explicit ACEs on an OU for review
    (Get-Acl "AD:OU=Staff,DC=corp,DC=example").Access |
      Where-Object { -not $_.IsInherited } | Select IdentityReference,ActiveDirectoryRights,ObjectType
  4. Find non-DC principals with replication rights and remove any that aren't approved sync accounts. Risk: Any extra DCSync holder is a domain-compromise path.
  5. Deploy Windows Local Administrator Password Solution (LAPS) to Fix: break local-admin password reuse, and scope LAPS read rights by tier.
  6. Fix the top choke point the analysis shows, usually a jump server, a helpdesk local-admin grant or a nested group. Verify: Re-collect and record the before-and-after exposure.

Longer-term fixes (weeks to months)

  1. Define and enforce tiering. Separate admin accounts per tier; Fix: deny Tier 0 accounts logon to lower tiers by GPO (deny logon locally, through Remote Desktop Protocol (RDP), as a batch job or as a service); provide Privileged Access Workstations (PAWs).
  2. Shrink Tier 0. Move Tier 0 users, groups and computers into a dedicated OU with its own tightly controlled Access Control List (ACL) and GPOs. Fix: Treat sync, backup, deployment and Certificate Authority (CA) servers as Tier 0 or remove their control edges.
  3. Protect credentials in memory: Protected Users for admins, Credential Guard on endpoints and servers, Restricted Admin or Remote Credential Guard for RDP. These reduce what a session edge yields.
  4. Fix Active Directory Certificate Services (AD CS): audit templates and CA permissions, remove requester-supplied subjects from authentication templates, and narrow enrollment.
  5. Flatten group nesting and give privileged groups Fix: named, individual members only.
  6. Adopt attack path management: a weekly privileged collection, a maintained Tier Zero zone, an exposure Key Performance Indicator (KPI), and Verify: alerts when exposure or Tier 0 membership changes.
  7. Extend to hybrid: collect Entra with AzureHound, make cloud admins cloud-only accounts, and protect the Entra Connect server as Tier 0.

Detection signals

SignalSourceAlert on
5136: directory object modifiedDomain Controller (DC) Security log (directory service changes auditing, plus System Access Control Lists (SACLs))Discretionary Access Control List (DACL), owner, member, servicePrincipalName, msDS-KeyCredentialLink, msDS-AllowedToActOnBehalfOfOtherIdentity or gPLink changes on Verify: Tier 0 objects or OUs
4728 / 4732 / 4756: member added to a security groupDC Security logAdditions to any group whose Risk: effective privilege is Tier 0, not just groups with "admin" in the name
4724: password reset by another accountDC Security logResets of privileged or service accounts by anyone outside the identity team
4662 with replication extended-right Globally Unique Identifiers (GUIDs)DC Security log (needs auditing on the domain object)Verify: Replication requested by a non-DC, the DCSync signature
Lightweight Directory Access Protocol (LDAP) enumeration volume (1644 or sensor data)DC Directory Service log with expensive-query logging, Microsoft Defender for Identity (MDI)One host querying every object and security descriptor in minutes
Fan-out to srvsvc, wkssvc, samr pipesNetwork sensors, 5145 file share auditing, MDIA single source contacting hundreds of hosts for sessions and local groups
MDI reconnaissance and DCSync alertsMicrosoft Defender for IdentityLDAP, Security Account Manager Remote protocol (SAMR) and user/Internet Protocol (IP) reconnaissance; directory replication from non-DCs
4624 logon type 2, 10 or 3 by Tier 0 accounts on non-Tier-0 hostsEndpoint Security logsRisk: A new session edge into Tier 0; should be impossible with logon restrictions
New inbound path to Tier ZeroYour scheduled BloodHound analysisExposure rising, or a new principal reaching Tier Zero

Verify the fix worked

  1. Verify: Re-collect with a privileged account, from a host that can reach every subnet.
  2. Re-run the same inbound-path queries and confirm the removed edges and paths are gone; Verify: record the exposure number.
  3. Confirm Tier 0 accounts have no sessions on non-Tier-0 hosts across several looped collections.
  4. Have testers retry the original path from a standard account and Verify: confirm the alerts above fire.
  5. Check that SDProp and GPO refresh haven't reintroduced an edge a day later.

Why remediation stalls, and workable compromises

ObjectionWorkable compromise
"We don't know who uses these permissions."Log first: enable 5136 and access auditing on the object, watch for 30 days, then Fix: remove what wasn't used. Keep a rollback export of the ACL.
"Helpdesk needs admin everywhere."Keep it on Tier 1 and Tier 2; Fix: remove it only from Tier 0 and shared jump hosts, and give Tier 0 its own management path.
"Tiering is a huge project."Start with logon restrictions for Domain Admins alone. It removes most session edges into Tier 0 for little effort.
"The tool shows thousands of paths; we can't fix them all."You don't need to. Fix the top three choke points and re-measure; Verify: exposure usually drops sharply.
"Removing Exchange or migration ACEs might break something."Test in a lab or on one OU; most legacy grants are documented by the vendor as safe to remove after decommissioning.
"We can't run BloodHound; security tools are banned on servers."Collect from a dedicated admin workstation, or use a commercial product with a supported sensor. Risk: Attackers won't ask permission, so the graph exists either way.
07

Executive brief

Executive

The risk in plain language

Our computer network keeps a record of who can do what: which staff can manage which accounts, which servers they can log in to, who is an administrator where. Over years, thousands of small, reasonable permissions accumulate. The risk is that Risk: they line up into a route from any employee's account to full control of the network. Attackers use free tools that find those routes automatically, in minutes, without needing any software vulnerability.

Business impact

  • A single phished employee can become Risk: a full network compromise: the precondition for large-scale ransomware and data theft.
  • Our access reviews can pass while Risk: the real number of people who can reach full control is hundreds or thousands.
  • Routes often run through cloud links too, so on-premises compromise can Risk: reach email, files and cloud systems.

What drives likelihood

  • Risk: How many accounts have a route to the most sensitive systems, and how short those routes are.
  • Administrators logging on everywhere, leaving reusable credentials on everyday machines.
  • Old permissions nobody reviews: grants from past projects, migrations and departed staff.
  • No ongoing measurement, so new routes appear silently as the organisation changes.

Cost of inaction

The fixes are mostly staff time and configuration changes, not new products, and the biggest gains come from a few changes. Leaving the routes in place means any successful phishing email is Risk: one short, quiet step from a company-wide incident. Ransomware crews look for exactly this.

What good looks like

  • A Fix: small, known set of systems and people can control the network, and it's written down.
  • Administrators use Fix: separate accounts and dedicated machines for powerful work.
  • The share of accounts with a route to full control is Verify: measured monthly and close to zero.
  • New routes trigger an alert, and someone owns fixing them.

Questions executives ask

Are we exposed?

"Almost certainly to some degree; nearly every Active Directory (AD) environment we test has paths. The useful question is how many people can reach full control, and how short the routes are. We measured it: today 1,800 of 2,400 accounts have a route. Three changes would bring that under 100."

Isn't this just a list of permission problems? Why does the 'graph' matter?

"Each permission looks reasonable on its own. Risk: The risk is in how they chain together, and no one reviewing them one at a time can see that. The graph shows the chain, and it shows which single link to remove to cut hundreds of chains at once."

We passed our audit. How can this be possible?

"Audits usually check that controls exist: admin groups reviewed, passwords rotated. They don't test how access combines. Every individual control can pass while the combination still gives an ordinary user a route to the top."

Will Multi-Factor Authentication (MFA) fix this?

"Not on its own. These routes mostly use permissions and credentials already inside the network, after the login MFA protects. MFA is still essential at the front door; this is about what happens once someone is in."

What does it cost to fix?

"Mostly staff time, not products. The biggest wins are permission changes and separating admin accounts, which the existing team can do in weeks. Keeping it fixed needs a recurring measurement, which free tools can do and commercial ones make easier."

How do we know it stays fixed?

"We re-measure on a schedule and track one number: Verify: how many accounts can reach full control. If that number climbs, something changed and we find out before an attacker does."

Presenting this finding to leadership

  1. Headline: "Any employee's account had a three-step route to full control of the network; one change removes most of those routes."
  2. Show the picture: one path diagram and one number (how many accounts can reach full control).
  3. Explain the fix in business terms: remove one shared link this month, separate admin access this quarter.
  4. The ask: a named owner, staff time for the changes, and Verify: a monthly exposure number reported to leadership.
08

Talk the talk

Jargon decoder

Attack path

A chain of relationships leading from an attacker's foothold to a valuable target.

"We found 14 attack paths from Domain Users to Tier 0; the shortest is three hops."

Edge

One relationship in the graph that an attacker can use to move from one object to another.

"The GenericWrite edge from IT-Projects to the backup account is the one to remove."

Node

An object in the graph: a user, group, computer, Group Policy Object (GPO), Organizational Unit (OU), domain or certificate object.

"That service account is the most connected node in the domain."

Tier 0

The set of identities and systems that control the domain, and anything that controls them.

"If the backup server can restore a Domain Controller (DC), it's Tier 0."

Choke point

A relationship many attack paths share, so removing it cuts them all.

"Helpdesk local admin on the jump server is the choke point; 97% of paths cross it."

Blast radius

Everything a single compromised object can reach.

"The blast radius of that phished account is 300 servers and, through one session, the domain."

Owned

A principal the tester has compromised and marked as a starting point.

"Mark jdoe as owned and run shortest paths to Domain Admins."

Derivative local admin

Reaching admin on one machine by stealing the credentials of someone who is admin there, from another machine you already control.

"We weren't admin on the file server, but derivatively we were, through the session on APP07."

Session edge

A record that a user is logged on to a computer, so their credentials may be in memory there.

"The path depends on a session edge that's six hours old; let's re-collect before we report it."

Collector (ingestor)

The tool that gathers directory and host data for the graph.

"Run the collector with a Tier 0 service account so the session data is complete."

Cypher

The graph query language BloodHound uses to ask custom questions.

"I wrote a Cypher query for every non-Tier-0 principal with DCSync."

Privilege Zone

BloodHound's way of defining a protected set of assets (Tier 0 by default) to measure paths into.

"The Entra Connect server wasn't in the Tier Zero zone, so paths to it weren't flagged."

Exposure

The share of principals that have at least one path into a protected zone.

"Tier 0 exposure dropped from 41% to 6% this quarter."

Tier 0 sprawl

The quiet growth of systems and groups that effectively control the domain.

"Tier 0 sprawl: 38 servers qualify, and only 4 are managed as Tier 0."

Smart questions to ask

Sysadmins

  • What is your written definition of Tier 0, and does it include sync, backup, deployment and Certificate Authority (CA) servers?
  • When did someone last run a privileged BloodHound collection, and Verify: what was the exposure to Tier Zero?
  • Can Domain Admins log on to workstations or member servers, or Fix: is that denied by policy?
  • Who holds replication rights on the domain object besides the Domain Controllers (DCs)?
  • Do you audit 5136 changes on Tier 0 objects, and Verify: who gets the alert?
  • Is Local Administrator Password Solution (LAPS) deployed, and who can read LAPS passwords for Tier 0 servers?

Executives

  • How many of our accounts can reach full control of the network today, and what's the target?
  • Who owns keeping that number down?
  • When we add a system or a team, who checks whether it creates a new route?

Coworkers

  • Was collection privileged, or are session-based paths under-represented?
  • Which path are we leading with, and Verify: did we validate every hop?
  • What are the top choke points by exposure, so the report says "fix these three"?
  • Are Active Directory Certificate Services (AD CS) and hybrid edges in scope and in the data?

Say this, not that

Not this

"BloodHound found that you're vulnerable."

Say this

"The graph shows a three-hop path from all users to domain admin; we validated each hop."

Not this

"You have too many domain admins."

Say this

"Your effective Tier 0 is 600 principals once nesting, Access Control Lists (ACLs) and sessions are counted, against 9 named admins."

Not this

"There are no attack paths."

Say this

"From what we could collect with our access, we found no paths; session data was limited, so we can't rule out session-based ones."

Not this

"Remove all these permissions."

Say this

"Remove these three edges first; they carry 90% of the paths. Then we re-collect and look again."

Not this

"BloodHound is a hacking tool, block it."

Say this

"BloodHound is a mapping tool. Detect unauthorised collection, and run it yourselves on a schedule."

Not this

"The helpdesk group is dangerous."

Say this

"Helpdesk's local admin on the jump server is dangerous because Tier 0 admins log on there."

Not this

"Shortest path is the riskiest path."

Say this

"Shortest by hops isn't easiest; we rank paths by how many people they expose and how realistic each hop is."

Same point, two audiences

Paths come from combinations of ordinary settings.
Executive

"No single setting is the problem. It's how a few reasonable-looking settings line up to give an ordinary employee's account a route to full control."

Sysadmin

"Domain Users has GenericAll on IT-Projects, IT-Projects has ForceChangePassword over the Staff Organizational Unit (OU), and adm_backup lives in that OU and is in Backup Operators."

Fix the choke point first.
Executive

"One change removes 97% of the routes. We'd do that this month and handle the rest over the quarter."

Sysadmin

"Split JUMP01 by tier, remove Helpdesk from local Administrators on the Tier 0 jump host, and deny Tier 0 logon to Tier 1 servers by Group Policy Object (GPO)."

Measure continuously.
Executive

"We'll report one number each month: how many accounts can reach full control. It should go down and stay down."

Sysadmin

"Schedule a privileged SharpHound collection weekly, track the Tier Zero exposure trend, and alert on new inbound edges."

Tier 0 is bigger than the admin groups.
Executive

"The systems that can control everything include our backup and software-deployment servers, not just the admin accounts, so they need the same protection."

Sysadmin

"System Center Configuration Manager (SCCM) site servers, the backup server and Entra Connect all have control edges into Domain Controllers (DCs), so add them to the Tier Zero zone and apply Tier 0 logon restrictions."

09

Keep going

What to learn next, in order

  1. Active Directory Certificate Services (AD CS) abuse. The certificate escalation classes behind the ADCSESC edges are the largest single source of short paths, and deserve a note of their own.
  2. Tiering and the enterprise access model. How to actually build Tier 0 boundaries: admin account separation, logon restrictions, Privileged Access Workstations (PAWs), and authentication policies and silos (Kerberos Part 3).
  3. NT LAN Manager (NTLM) relay and coercion. The techniques that create edges at runtime (coerced authentication relayed into Lightweight Directory Access Protocol (LDAP) or AD CS), which the static graph models only partly.
  4. Hybrid identity paths. Entra ID roles, Entra Connect, device management and AzureHound data, where on-premises and cloud graphs join.
  5. Cypher for defenders. Enough of the query language to write your own exposure reports and change diffs.

Resources worth seeking out

  • BloodHound documentation (SpecterOps): the edge reference pages explain each edge's meaning, abuse and opsec notes, and are the authoritative list of current edge names.
  • The Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK) entry for BloodHound (S0521) and the discovery techniques it maps to, for findings language.
  • Microsoft's documentation on securing privileged access and the enterprise access model, for the tiering vocabulary clients' teams will recognise.
  • A practice lab: a deliberately vulnerable Active Directory (AD) range (several open-source projects build one), so you can collect, find and remediate paths Verify: in an environment you're authorised to break.
  • Conference talks by the BloodHound authors on attack path management and choke points, for the defender's framing.
My private notebook

Personal notes and bookmarks are private. Unsaved text is temporarily kept in this tab’s browser storage to recover supported sign-in redirects and reloads. Closing the tab may lose unsaved text.

Checking sign-in…

Sign in in another tab Sign in in this tab All my notes