Active Directory attack paths, thinking in graphs
Nodes, edges, choke points, and BloodHound from both sides
Start here
This is a standalone note that ties together topics from the Kerberos series: delegation, roasting and ticket theft all show up here as edges. It covers how to see an Active Directory (AD) environment as a graph, how tools like BloodHound build and search that graph, the common edge families, and how defenders use the same graph to measure and remove risk.
Highlight key
- the term being defined
- Key term: bold with a highlighter swash. A concept's defining phrase.
- how something works
- Mechanism: wavy underline. How a piece works or relates to another.
- Risk: what makes an attack possible
- Risk: warm highlight with a dashed edge. Attack prerequisites and dangerous conditions.
- Fix: the mitigation to apply
- Fix: solid green underline. A mitigation or configuration change.
- Verify: how to confirm it worked
- Verify: green underline with a check. How to prove a fix works.
- only if, by default
- Qualifier: bold italic. A word that changes the claim.
4769- Technical literal: monospace chip. Commands, settings, event IDs, exactly as typed.
Plain English first
Active Directory is a huge web of "who can do what to whom": this person is in that group, that group can manage those accounts, this server lets those people log in, an administrator is logged on over there. Each fact on its own is mundane. An attack path is a chain of those facts that leads from an ordinary account to control of the whole domain.
People and spreadsheets review those facts one at a time. Attackers follow them like routes on a map. Tools such as BloodHound draw the map automatically: every object becomes a dot (a node), every abusable relationship becomes an arrow (an edge), and the computer finds the routes.
The same map works for defenders. Instead of fixing thousands of individual permissions, you find the few Fix: shared links that most routes pass through and cut those.
The analogy: a subway map of trust
Think of AD as a city's subway map. Stations are users, groups and computers; the lines between them are permissions and logons. An attacker doesn't care that each station looks unimportant. They care whether Risk: a line connects their station to the central one. Defenders usually keep a list of stations; attackers read the map. And just like a subway, most routes pass through a few interchange stations. Close the interchange and dozens of routes break at once.
Why it matters now
Graph tooling turned AD privilege escalation from craft into routine. A collector run as any domain user Risk: maps the directory in minutes, and pathfinding finds routes no human would spot. Many internal tests now reach Tier 0 without exploiting a single software flaw, just by walking configuration.
The defender's version of the same graph is now mainstream. BloodHound Community Edition (CE) ships a Tier Zero zone and OpenGraph for other platforms, and BloodHound Enterprise and Microsoft Security Exposure Management prioritise choke points. Attack paths can be measured as a number (how many accounts can reach Tier 0) and driven down like any other risk.
If you remember only 5 things
- Privilege is transitive. If A controls B and B controls C, A controls C. No single record says so, which is why list-based reviews miss paths.
- Edges point the way control flows. Membership, local admin, logged-on sessions, directory permissions, Group Policy Object (GPO) links, delegation and certificates all become arrows an attacker can follow.
- Tier 0 is defined by control, not by label. Anything that can control a Domain Controller (DC) or an admin group Risk: is Tier 0, whatever its name, including sync, backup and deployment servers.
- Fix choke points, not paths. Most paths share a few edges. Fix: Remove the shared edge with the biggest exposure first, then re-collect.
- The graph is a model. It is only as complete as the collection behind it. A clean graph from partial data is false comfort; validate paths and collect with privilege.
Core concepts
Thirteen ideas, from "what is a graph" to managing paths continuously. Open "Go deeper" for expert detail.
01Lists versus graphsAttackers see the network as a graph of relationships, not a list of assets.
A defender's spreadsheet lists servers, admins and groups one row at a time. An attacker asks a different question: from where I stand, what can I reach next, and from there, what next? Answering that means thinking in connections, not rows.
The list says "helpdesk users are not admins." The graph shows helpdesk users are local admins on a server where a domain admin is logged on, so in practice they are one hop from domain admin.
TechnicalGo deeper
Microsoft's John Lambert put it in 2015: "Defenders think in lists. Attackers think in graphs. As long as this is true, attackers win." BloodHound (2016, by Andy Robbins, Rohan Vazarkar and Will Schroeder) made the idea concrete for Active Directory (AD). The insight is that Risk: privilege is transitive: if A controls B and B controls C, A controls C, even though no single row anywhere says so.
02NodesA node is a thing in the directory: a user, group, computer, Group Policy Object (GPO), Organizational Unit (OU), domain or certificate object.
Every object that can hold or grant access is a dot on the map. Users and computers are the obvious ones, but containers, policies and certificate templates are nodes too, because controlling them confers control over other things.
In a typical domain graph: User jdoe, Group IT-Support, Computer FS01, GPO Workstation Baseline, OU Servers, Domain corp.example.
TechnicalGo deeper
BloodHound keys nodes on Security Identifiers (SIDs) or object Globally Unique Identifiers (GUIDs), so a renamed account stays the same node. Beyond the core Active Directory (AD) types it models CertTemplate, EnterpriseCA, RootCA, NTAuthStore and AIACA for Active Directory Certificate Services (AD CS), Entra and Azure objects via AzureHound, and, since v8, arbitrary node types through OpenGraph. Computers are both principals (their machine account) and places where credentials live, which is why they sit at the center of so many paths.
03EdgesAn edge is a directed "can control" relationship from one node to another.
An arrow from A to B means "A can do something to B that helps an attacker." Direction matters: the arrow points the way control flows, which is the way an attacker moves.
jdoe MemberOf IT-Support; IT-Support AdminTo FS01; FS01 HasSession admin-ash. Read left to right: jdoe can reach admin-ash's credentials.
TechnicalGo deeper
Edges fall into families: membership (MemberOf), host access (AdminTo, CanRDP, CanPSRemote, ExecuteDCOM), credential exposure (HasSession), directory permissions (GenericAll, GenericWrite, WriteDacl, WriteOwner, Owns, ForceChangePassword, AddMember, AllExtendedRights), secrets (ReadLAPSPassword, ReadGMSAPassword), containment and policy (Contains, GPLink), delegation (AllowedToDelegate, AllowedToAct), replication (DCSync) and certificates (ADCSESC1 and friends). An edge says an abuse is possible, not that it is quiet or easy; each has its own tradecraft and evidence.
04Attack pathsAn attack path is a chain of edges from a node the attacker holds to a node they want.
Join edges end to end and you get a route. Each hop on its own may look harmless; Risk: the danger is the chain. Graph tools search millions of possible chains in seconds and show the short ones.
Phished user → MemberOf Helpdesk → AdminTo APP07 → HasSession svc_backup → MemberOf Backup Operators → Tier 0.
TechnicalGo deeper
Pathfinding is classic graph search (shortest path by hop count). Hop count is a convenient proxy, not a cost model: a two-hop path through an EDR-protected host may be harder than a five-hop Access Control List (ACL) chain. BloodHound Enterprise and newer Community Edition (CE) features add exposure scoring and multi-destination pathfinding, but the analyst still judges which hops are realistic in this environment.
05Tier 0 and Privilege ZonesTier 0 is everything that controls the domain, plus anything that controls those things.
Some objects are the crown jewels: domain controllers, the admin groups, the account that signs Kerberos tickets. But Tier 0 is defined by control, not by label. If a server can push software to a Domain Controller (DC), that server is Tier 0 too, whatever its spreadsheet row says.
DCs, Domain Admins, Enterprise Admins, krbtgt, enterprise Certificate Authoritys (CAs), the Entra Connect server, System Center Configuration Manager (SCCM) site servers, and backup servers that store DC images.
TechnicalGo deeper
BloodHound Community Edition (CE) ships a default Tier Zero Privilege Zone; legacy BloodHound called the same idea "high value." BloodHound Enterprise adds custom zones (a server tier, a payments zone) and certification of membership. The working rule: Risk: any inbound path into Tier 0 from outside it is a finding, because it means Tier 0 is bigger than you think. Tier 0 sprawl, where dozens of systems quietly qualify, is the most common root cause in mature environments.
06Group membership and nestingMembership edges mean a member inherits everything the group can do, through every level of nesting.
Put a group inside another group and every member of the inner one gets the outer one's rights. After a decade of reorganisations, Risk: nesting hides who is really privileged. The graph flattens it.
jdoe is in Regional-IT, which is in Server-Ops-Global, which is in Administrators on the domain. Nobody ever added jdoe to an admin group directly.
TechnicalGo deeper
MemberOf is traversed for free in path queries. Watch the built-in operator groups (Account Operators, Server Operators, Backup Operators, Print Operators): Risk: they have Tier 0-equivalent abuse paths (logon to Domain Controllers (DCs), backup rights, control of non-protected groups) and are often forgotten. Domain Users, Authenticated Users and Everyone are also nodes, so Risk: an edge from one of them means every account in the domain has that path.
07Local admin rights and sessionsAdminTo plus HasSession is the credential-theft hop: admin on a box where a privileged user is logged on.
When someone logs on to a Windows machine, traces of their credentials stay in memory. Anyone who is local admin on that machine can usually extract them and become that person. So "who is admin where" and "who is logged on where" together form a path.
The helpdesk group is local admin on every workstation (a common build default). A domain admin Remote Desktop Protocols (RDPs) to one workstation to fix a printer. Every helpdesk member now has a path to domain admin.
TechnicalGo deeper
This is "derivative local admin": admin on host A gives a session for user B, who is admin on host C, and so on. Defenses that cut it: Fix: unique local admin passwords (LAPS), tiered admin accounts so Tier 0 credentials never touch workstations, Protected Users and Credential Guard to reduce what is left in memory, and Restricted Admin or Remote Credential Guard for RDP. Session data is a snapshot; it decays within hours, so it is collected repeatedly.
08Access Control List (ACL) edgesACL edges are directory permissions that let one principal modify another.
Every Active Directory (AD) object carries a list of who can change it. If you can change a user's password, add members to a group, or rewrite an object's permissions, Risk: you effectively control that object. These grants pile up from tools, migrations and help-desk delegations nobody revisits.
IT-Support has ForceChangePassword on all users in the Staff Organizational Unit (OU), which also contains a forgotten account that is a member of Domain Admins.
TechnicalGo deeper
The common abusable rights: GenericAll (full control), GenericWrite (write most attributes: set an Service Principal Name (SPN) to Kerberoast, set Resource-Based Constrained Delegation (RBCD), add shadow credentials), WriteDacl (grant yourself anything), WriteOwner and Owns (owners can rewrite the Discretionary Access Control List (DACL)), AddMember/AddSelf on groups, ForceChangePassword, AllExtendedRights, and AddKeyCredentialLink. Inheritance from OUs spreads them. AdminSDHolder and SDProp reset the ACLs of protected accounts hourly, which protects members of built-in admin groups but not custom privileged groups.
09Containers and Group PolicyControl of an Organizational Unit (OU) or a linked Group Policy Object (GPO) is control of everything beneath it.
OUs hold objects; GPOs push settings, including scripts and scheduled tasks, to the objects in the OUs they are linked to. Risk: Edit a GPO and you run code on every computer it applies to.
A desktop team can edit the "Workstation Baseline" GPO, which is also linked to the Domain Controllers OU by mistake. That team now has a path to every Domain Controller (DC).
TechnicalGo deeper
Edges: Contains (OU or domain to child), GPLink (GPO to the container it applies to), and Access Control List (ACL) edges on the GPO object itself. Inheritance flags on an OU's Access Control Entrys (ACEs) decide whether rights flow to children. Block inheritance and enforced links change which GPOs actually apply, and collectors model this imperfectly, so verify GPO paths in the Group Policy Management Console before reporting them.
10CollectionCollection is reading the directory and hosts to build the graph, mostly with ordinary user rights.
By design, almost any domain user can read almost all of Active Directory (AD) over Lightweight Directory Access Protocol (LDAP): users, groups, memberships and most permissions. Risk: No exploit is needed to map the domain. Host data (who is logged on, who is local admin) needs extra queries to each computer.
A collector runs as a phished user, makes LDAP queries to a Domain Controller (DC), then contacts each computer for sessions and local groups, and writes a zip of JavaScript Object Notation (JSON) files for upload.
TechnicalGo deeper
Collectors: SharpHound (Windows, C#), BloodHound.py's CE-compatible version and RustHound-CE (from non-Windows hosts), AzureHound for Entra and Azure, and OpenHound and OpenGraph collectors for other platforms. Since Windows 10 1607 and Server 2016, remote Security Account Manager Remote protocol (SAMR) is restricted to administrators by default, and session enumeration Application Programming Interfaces (APIs) increasingly need admin too, so a low-privilege collection is strong on directory data and weak on sessions. Defenders collecting with a privileged account get a far more complete graph than attackers usually do.
11Model versus realityThe graph is a model of possible abuse, not proof that a path works today.
Data goes stale, collection misses things, and some edges are hard to use in practice. A path on screen is a hypothesis to validate, and an absence of paths is only as good as the collection behind it.
A path relies on a session that was there at 09:00 and gone by noon; another relies on a host the collector couldn't reach, so it doesn't appear at all.
TechnicalGo deeper
Sources of error: stale sessions, unreachable hosts, deny Access Control Entrys (ACEs) and edge-case inheritance, Group Policy Object (GPO) filtering, controls the graph doesn't know about (Endpoint Detection and Response (EDR), tiered logon restrictions, authentication silos), and edges whose abuse needs conditions outside the data. False negatives are the dangerous ones: a clean graph from a partial collection is false comfort. Good testers validate the chosen path; good defenders collect with full privilege and on a schedule.
12Choke points and blast radiusA choke point is an edge or node many paths pass through; removing it cuts them all.
Thousands of paths to Tier 0 often funnel through a handful of relationships. Fix the funnel, not the thousands. The flip side is blast radius: everything one compromised node can reach.
1,800 users have a path to Domain Admins, and 1,750 of those paths cross one edge: Helpdesk AdminTo a jump server where admins leave sessions. Remove that one edge and exposure drops by 97%.
TechnicalGo deeper
Inbound analysis ("who can reach Tier 0?") drives remediation; outbound analysis ("what can this phished user reach?") drives incident scoping and findings narratives. BloodHound Enterprise ranks choke points by how many principals each one exposes, and Microsoft Security Exposure Management shows choke points and blast radius for its own attack paths. Fix: Fix the edge with the biggest exposure first, then re-collect, because removing one funnel often reveals the next.
13Attack path managementAttack path management is continuously measuring and shrinking paths to what matters.
One test gives a snapshot. Environments change daily: new hires, new groups, new servers. Attack Path Management (APM) treats paths like any other recurring risk, collect, measure, fix, verify, repeat, and reports a trend.
A monthly report: "Principals with a path to Tier 0: 41% in January, 6% in June, after removing three choke points and enforcing admin tiering."
TechnicalGo deeper
Inputs: scheduled privileged collection, a maintained Tier 0 definition (Privilege Zones), and change detection on the directory. Outputs: exposure percentages, choke-point lists, and Verify: alerts when a new path to Tier 0 appears. Hybrid identity widens the graph: AzureHound data plus Active Directory (AD) data lets BloodHound render paths that cross from on-premises to Entra ID and back, and OpenGraph extensions add platforms such as GitHub and Okta. Commercial options exist (BloodHound Enterprise, Microsoft Security Exposure Management, and other exposure-management products); capabilities and licensing change often, so compare current versions.
Visual map
Step through how the graph gets built, two classic attack paths, and the defender's choke-point cut. Verify: Each attack step names the defense that breaks it.
The main edge families
| Family | Example edges | What it means | Typical root cause |
|---|---|---|---|
| Membership | MemberOf | Inherit the group's rights | Deep nesting, privileged groups inside managed groups |
| Host access | AdminTo, CanRDP, CanPSRemote, ExecuteDCOM | Log on or run code on a computer | Helpdesk admin everywhere, shared local passwords |
| Credential exposure | HasSession | A user's credentials may be in memory on a host | Risk: Tier 0 admins logging on to lower tiers |
| Directory permissions | GenericAll, GenericWrite, WriteDacl, WriteOwner, Owns, ForceChangePassword, AddMember, AllExtendedRights | Modify another object | Old delegations, migration leftovers, broad grants |
| Secrets | ReadLAPSPassword, ReadGMSAPassword, SyncLAPSPassword | Read a stored password | Local Administrator Password Solution (LAPS) read rights scoped too widely |
| Containers and policy | Contains, GPLink | Control flows to objects inside | Group Policy Object (GPO) edit rights delegated broadly |
| Delegation and replication | AllowedToDelegate, AllowedToAct, DCSync | Impersonate users or pull hashes | Delegation flags, replication rights on non-DCs |
| Certificates | ADCSESC1, ADCSESC3, GoldenCert, and more | Obtain a certificate that authenticates as someone else | Risk: Weak templates with broad enrollment |
| Trust and hybrid | TrustedBy, HasSIDHistory, hybrid AD-to-Entra edges | Cross a domain or cloud boundary | Security Identifier (SID) history, synced cloud admins |
Ways to see the graph
| Approach | Who uses it | Strengths | Limits |
|---|---|---|---|
| BloodHound Community Edition (CE) | Testers, defenders | Free, open source, Tier Zero zone, Cypher, OpenGraph | You run collection and analysis yourself |
| BloodHound Enterprise | Defenders | Continuous collection, custom Privilege Zones, choke-point prioritisation | Commercial; value depends on someone acting on it |
| Microsoft Security Exposure Management | Microsoft-centric defenders | Attack paths, choke points and blast radius across Defender data | Paths depend on Microsoft's own models and licensing |
| PingCastle, Purple Knight and similar | Defenders, auditors | Fast health-check scores and known-bad settings | List-style checks; limited path chaining |
| Manual review (Active Directory Users and Computers (ADUC), PowerShell) | Admins | No new tools | Risk: Can't see chains; this is the list problem |
Technical deep dive
TechnicalUnder the hood
The data model
BloodHound stores a directed property graph: nodes with types and properties (name, Security Identifier (SID), enabled, last logon, admincount, Tier Zero membership), and typed edges between them. Pathfinding is a graph search over edge types that are marked traversable. Some edges are collected directly (an Access Control Entry (ACE), a membership); others are post-processed, derived after ingest from combinations of data, such as Active Directory Certificate Services (AD CS) escalation edges built from template, Certificate Authority (CA) and enrollment data.
Nodes are keyed on SID or object Globally Unique Identifier (GUID), so renames don't break history, and data from several collections merges into one graph.
How collection works
- Directory (LDAP). Users, groups, computers, Organizational Units (OUs), Group Policy Objects (GPOs), containers, domains, trusts, AD CS objects, and each object's
nTSecurityDescriptor. Readable by any authenticated user by default, apart from a few protected attributes (Local Administrator Password Solution (LAPS) passwords, for example). - Hosts (Server Message Block (SMB)/Remote Procedure Call (RPC)). For each reachable computer: sessions (
NetSessionEnum,NetWkstaUserEnum, Remote Registry) and local group membership over Security Account Manager Remote protocol (SAMR) or Local Security Authority (LSA) calls. Windows 10 1607 and Server 2016 onward Risk: restrict remote SAMR to administrators, and newer releases restrict session enumeration too, so a low-privilege collector sees far less here. - Ingest and post-processing. The collector writes JavaScript Object Notation (JSON) files (usually zipped). BloodHound ingests them, then computes derived edges and zone membership.
Collection methods matter for noise and completeness:
| Method (SharpHound) | Touches | Gives | Notes |
|---|---|---|---|
DCOnly | Domain Controllers (DCs) only, over LDAP | Objects, Access Control Lists (ACLs), memberships, GPOs, trusts, delegation, AD CS | Quietest; no sessions or local groups |
Default | DCs plus every computer | Adds sessions and local groups | Fan-out to every host is noisy |
All | Everything | Adds more host and certificate detail | Noisiest, most complete |
Session with --loop | Every computer, repeatedly | Fresh session data over time | Sessions are snapshots, so looping catches more |
Edges in detail: the ones that come up most
MemberOf. Free to traverse. The built-in operator groups (Account, Server, Backup, Print Operators) are Risk: effectively Tier 0; check their membership first.AdminToandHasSession. The credential-theft pair.AdminTocomes from local Administrators membership (directly, by group, or by GPO-applied Restricted Groups).HasSessionpoints from computer to user.ForceChangePassword. Reset without knowing the old password. Effective but loud, and it locks the real user out, so testers often prefer quieter edges and many engagements forbid resets on live accounts.GenericWrite. On a user: set an Service Principal Name (SPN) (targeted Kerberoasting) or add a key credential (shadow credentials). On a computer: set Resource-Based Constrained Delegation (RBCD). On a group: change membership.WriteDacl,WriteOwner,Owns. Permission-on-permission. Risk: Any of these is full control one step later.AllExtendedRights. Includes reset password and, on the domain object, the replication rights behindDCSync.GPLinkplus GPO write. Code execution on every computer in scope at next policy refresh.CoerceToTGTand delegation edges. Hosts trusted for unconstrained delegation can capture a coerced Ticket Granting Ticket (TGT);AllowedToActis RBCD (see Kerberos Part 3).- AD CS edges. Built in post-processing from templates, CAs, the NTAuth store and enrollment rights. Often Risk: the shortest path in the whole graph.
AdminSDHolder and what it does (and doesn't) protect
Every hour, the SDProp process copies the ACL of the AdminSDHolder object onto members of built-in protected groups (Domain Admins, Enterprise Admins, Administrators, the operator groups and a few more) and sets admincount=1. That wipes stray ACEs on those accounts. It does not cover custom privileged groups, and admincount=1 lingers on accounts removed from protected groups, leaving them with odd, non-inheriting ACLs. If AdminSDHolder's own ACL is modified, Risk: the change propagates to every protected account, a known persistence technique.
Querying the graph
The Graphical User Interface (GUI) covers the common questions (shortest paths, inbound to Tier Zero, outbound from an owned node), and BloodHound Community Edition (CE) ships a library of pre-built searches. For anything custom, use Cypher, the graph query language. Typical defensive questions:
// Every principal holding DCSync; anything that isn't a DC or an approved sync account is a finding
MATCH (n)-[:DCSync]->(d:Domain)
RETURN n.name, d.name
// Shortest paths from Domain Users (RID 513) to Domain Admins (RID 512)
MATCH p=shortestPath((g:Group)-[*1..]->(t:Group))
WHERE g.objectid ENDS WITH '-513' AND t.objectid ENDS WITH '-512'
RETURN pCommon misconceptions
| Misconception | Reality |
|---|---|
| "BloodHound needs admin rights." | Directory collection works with any domain account. Admin rights only improve host data. |
| "No paths in the graph means no paths." | Only if collection was complete. Unprivileged collection under-reports sessions and local admin. |
| "Our admin groups are small, so we're fine." | Effective Tier 0 includes nesting, ACLs, sessions, GPOs, CAs and sync servers. Risk: It's usually far larger than the groups. |
| "The shortest path is the most dangerous." | Hop count ignores difficulty and detection. Rank by exposure and realism. |
| "Fix every path the tool lists." | Fix: Fix the shared edges; thousands of paths usually collapse to a handful of causes. |
| "BloodHound is an attacker tool; blocking it solves the problem." | Blocking one binary changes nothing about the paths. Fix: Detect unauthorised collection and run it yourself. |
| "Multi-Factor Authentication (MFA) removes these paths." | Most edges are used after authentication with permissions, hashes or tickets. MFA doesn't gate them. |
Troubleshooting a graph
- Few or no sessions: the collector lacked admin rights, hosts were unreachable (firewall, offline laptops), or session enumeration is restricted. Re-run with a privileged account from a well-connected host, and loop session collection.
- Paths that don't work when tested: stale session, a deny ACE, GPO security filtering, or a control the graph doesn't model (logon restrictions, authentication silos, Endpoint Detection and Response (EDR)). Verify: Record why, and treat it as a data-quality note rather than a mistake.
- Huge, unreadable path counts: group by shared edge and look at choke points; filter out paths through Tier Zero nodes themselves.
- Missing AD CS edges: confirm the collector version supports AD CS collection and that CA and template objects were readable.
- Old queries failing: zone labels and some edge names changed between releases; use the current schema.
Attacker's view
AttackerAttacker's view, for defenders
Each technique below is covered at the level needed to recognise it, test for it and explain it: prerequisites, what makes an environment vulnerable, the evidence it leaves, and how it reads as a finding. Tools are named so you can build detections and a lab. Exploit steps for each edge are deliberately left out; the BloodHound documentation's per-edge abuse notes and an authorised lab (for example, a deliberately vulnerable Active Directory (AD) range) are the place for hands-on practice.
Graph collection (domain reconnaissance)ATT&CKT1087.002 Account Discovery: Domain Account · T1069.002 Permission Groups Discovery: Domain Groups · T1482 Domain Trust Discovery · T1018 Remote System Discovery
The attacker runs a collector as any domain account. It reads objects, memberships and Access Control Lists (ACLs) over Lightweight Directory Access Protocol (LDAP), then contacts hosts for sessions and local group membership, and packages the result for BloodHound. Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK) catalogues BloodHound as software S0521.
Risk: Any authenticated domain account and network reach to a Domain Controller (DC); host-level data needs reach to each computer and, on modern Windows, usually admin rights there.
Every Active Directory (AD) domain is readable by its users by design. Exposure grows with Risk: no detection on bulk LDAP and Security Account Manager Remote protocol (SAMR) enumeration, wide-open session enumeration on older or unhardened hosts, and collectors allowed to run unnoticed.
SharpHound, BloodHound.py (CE-compatible version), RustHound-CE, AzureHound for Entra and Azure, Sysinternals AD Explorer snapshots (which can be converted for BloodHound). Defenders run the same tools with privileged accounts.
# Recognise these in command lines and process telemetry
SharpHound.exe -c All # all collection methods
SharpHound.exe -c DCOnly # LDAP-only, no host contact (quieter)
SharpHound.exe -c Session --loop # repeated session collection
Bursts of LDAP queries for every user, group, computer and security descriptor from one workstation; Verify: Server Message Block (SMB) connections to srvsvc, wkssvc and samr pipes across many hosts; Microsoft Defender for Identity (MDI) reconnaissance alerts (LDAP, SAMR, user and Internet Protocol (IP) enumeration); Endpoint Detection and Response (EDR) detection of the collector binary or its zip output.
Rarely a finding on its own, since reading the directory is intended. Report it as a detection gap if a full collection ran unnoticed. Retest: a collection from a standard workstation raises an alert within the agreed time.
Directory permission (ACL) abuseATT&CKT1098 Account Manipulation · T1222 File and Directory Permissions Modification (closest fit; ATT&CK has no single "AD ACL abuse" technique)
The attacker walks ACL edges: reset a password they're allowed to reset, add themselves to a group they can write, grant themselves rights with WriteDacl, or take ownership with WriteOwner. GenericWrite on a user enables targeted Kerberoasting (set an Service Principal Name (SPN)) or shadow credentials (AddKeyCredentialLink).
Control of a principal that holds Risk: an abusable right on a more privileged object, directly or through group membership.
Broad rights granted to large groups; Risk: delegations to Helpdesk or Information Technology (IT) groups that cover privileged accounts; leftover Access Control Entrys (ACEs) from migrations, Exchange installs and old tools; custom admin groups outside AdminSDHolder protection; owners left as former admins.
BloodHound to find the edge; PowerView, the ActiveDirectory module, Impacket's dacledit, bloodyAD and Whisker/pyWhisker (shadow credentials) are what testers use to exercise it.
Event 4738 (user changed), 4724 (password reset by another account), 4728/4732/4756 (member added to a security group), and Verify: 5136 for Discretionary Access Control List (DACL), owner, servicePrincipalName or msDS-KeyCredentialLink changes, provided directory-service change auditing and System Access Control Lists (SACLs) are on.
"Excessive Active Directory (AD) permissions create a path from ordinary users to Domain Admins." Severity follows the size of the starting population and the target: Domain Users to Tier 0 is critical. Retest: the edge is gone in a fresh privileged collection and the abuse attempt fails.
Session hunting and derivative local adminATT&CKT1033 System Owner/User Discovery · T1003.001 OS Credential Dumping: LSASS Memory · T1550.002 Use Alternate Authentication Material: Pass the Hash · T1021 Remote Services
The attacker finds a host where they are local admin (AdminTo) and a more privileged user has a session (HasSession), extracts that user's credential material from memory, and repeats until reaching Tier 0.
Local admin on at least one host, and Risk: privileged credentials present on hosts that lower tiers administer.
Risk: Shared local administrator passwords (no Local Administrator Password Solution (LAPS)); a helpdesk group that is admin everywhere; Domain Admins logging on to workstations and member servers; no Credential Guard; Remote Desktop Protocol (RDP) without Restricted Admin or Remote Credential Guard.
BloodHound session data (often refreshed in a loop), Mimikatz, Impacket, NetExec (formerly CrackMapExec), and Rubeus for ticket-based variants.
Remote logon (4624 logon type 3 or 10) by an unusual account to many hosts, Verify: Local Security Authority Subsystem Service (LSASS) access events from Endpoint Detection and Response (EDR), 4672 special privileges at odd hosts, and NT LAN Manager (NTLM) authentication patterns consistent with pass-the-hash.
"Privileged credentials exposed on lower-tier hosts." High to critical depending on which accounts were exposed and who administers those hosts. Retest: Tier 0 accounts are denied logon to lower tiers (policy), LAPS is deployed, and session data shows no Tier 0 sessions outside Tier 0.
Group nesting escalationATT&CKT1098.007 Account Manipulation: Additional Local or Domain Groups
The attacker uses AddMember, AddSelf or GenericAll on a group that sits inside a privileged group, several levels down, and adds an account they control.
Write access to the membership of Risk: any group nested into a privileged one.
Deep or circular nesting; Risk: privileged groups nested into project or regional groups managed by non-Tier-0 staff; built-in operator groups with members.
BloodHound to see the nesting; net, PowerShell, bloodyAD or similar to add the member.
Verify: 4728, 4732 or 4756 on a group whose effective privilege is Tier 0, even though the group's own name looks harmless. Alerting on effective privilege, not group name, is the key.
"Delegated group management reaches a privileged group through nesting." Critical when the outer group is Tier 0. Retest: nesting flattened, Tier 0 groups contain only named individuals or approved groups, and membership changes alert.
Group Policy and Organizational Unit (OU) controlATT&CKT1484.001 Domain or Tenant Policy Modification: Group Policy Modification
The attacker edits a Group Policy Object (GPO) they can write, or links a GPO they control to an OU they can write, to push a script or scheduled task to every computer or user in scope.
Write access to a GPO linked above valuable objects, or Risk: write access to an OU's gPLink attribute.
GPO edit rights delegated broadly; Risk: GPOs linked to the Domain Controllers OU or domain root that non-Tier-0 teams can edit; GPO files on SYSVOL with weak file permissions.
BloodHound (GPLink, GenericWrite on GPO), Group Policy Management Console, SharpGPOAbuse, pyGPOAbuse.
Verify: 5136 on the GPO object (versionNumber, gPCMachineExtensionNames) and on OU gPLink; SYSVOL file changes; new scheduled tasks (event 4698) appearing across many hosts at once.
"Non-administrative group can modify Group Policy that applies to domain controllers." Critical when the scope includes Domain Controllers (DCs) or Tier 0 servers. Retest: GPO and link permissions limited to Tier 0 admins for Tier 0 scopes, verified by collection and by the console's delegation tab.
Certificate (AD CS) edgesATT&CKT1649 Steal or Forge Authentication Certificates
Misconfigured certificate templates or Certificate Authoritys (CAs) let a low-privilege user request a certificate that authenticates as someone else, or control the CA itself. BloodHound models the well-known escalation classes as edges such as ADCSESC1, ADCSESC3 and GoldenCert.
An enterprise CA trusted for authentication and Risk: a template or CA permission matching an escalation class, reachable by a principal the attacker controls.
Templates that let the requester supply the subject and allow client authentication; Risk: broad enrollment rights (Domain Users); write rights on templates or the CA; unpatched CA settings.
Certipy and Certify to enumerate and test; BloodHound Community Edition (CE) for the path view; Locksmith and PSPKIAudit for defensive review.
CA events 4886 and 4887 (certificate requested and issued) with Verify: a subject that doesn't match the requester, template changes (4899, 4900), and Kerberos certificate logons (4768 with certificate fields).
Often the shortest path in the report. Critical when Domain Users can reach a domain admin certificate. Retest: template fixed, enrollment narrowed, and the edge absent after re-collection. AD CS deserves its own note.
Delegation, replication and secret-reading edgesATT&CKT1003.006 OS Credential Dumping: DCSync · T1558 Steal or Forge Kerberos Tickets
Some edges hand over credentials directly. DCSync (GetChanges plus GetChangesAll) lets a principal pull password hashes from a Domain Controller (DC); AllowedToDelegate and AllowedToAct allow impersonation; ReadLAPSPassword and ReadGMSAPassword reveal secrets.
Control of a principal holding Risk: replication rights, delegation configuration or secret-read rights.
Replication rights granted to non-DC accounts (old sync tools, Exchange leftovers); Risk: Local Administrator Password Solution (LAPS) read rights granted to the whole helpdesk, including for Tier 0 servers; RBCD-writable computer objects.
BloodHound for discovery; Impacket secretsdump and Mimikatz for DCSync; Rubeus and Impacket for delegation; LAPS and group Managed Service Account (gMSA) readers.
Verify: 4662 with the replication extended-right Globally Unique Identifiers (GUIDs) from a non-DC; Microsoft Defender for Identity (MDI) DCSync alerts; 4769 with Service for User (S4U) patterns; LAPS password read auditing.
DCSync held by a non-Tier-0 principal is a direct domain-compromise finding. Retest: replication rights only on DCs and approved sync accounts; LAPS read scoped per tier.
Hybrid and cross-trust pathsATT&CKT1482 Domain Trust Discovery · T1078.004 Valid Accounts: Cloud Accounts
Paths cross boundaries the org chart treats as separate: from one domain to another over trusts, and between on-premises Active Directory (AD) and Entra ID through synchronisation servers, synced admin accounts and cloud-managed devices.
A trust or sync relationship plus Risk: a privileged identity or server that spans both sides.
Synced on-premises accounts holding cloud admin roles; Risk: an Entra Connect server not treated as Tier 0; intra-forest trusts assumed to be boundaries; Security Identifier (SID) history left after migrations.
BloodHound Community Edition (CE) with SharpHound plus AzureHound data (hybrid paths render when both are loaded); ROADtools for Entra; defensive views in Microsoft Security Exposure Management.
Sign-ins from the sync server's account outside sync patterns; Verify: role assignment changes in Entra audit logs; cross-domain Kerberos referrals for unusual principals.
"On-premises compromise extends to the cloud tenant" (or the reverse). Severity follows the far-side target, often global administrator. Retest: cloud admins are cloud-only accounts, the sync server is protected as Tier 0, and the hybrid path is gone.
How a graph-driven engagement usually runs
- Foothold and collection: an assumed-breach or phished account collects the directory, often
DCOnlyfirst for low noise. - Mark owned, ask questions: shortest paths from owned principals to Tier Zero, plus Risk: inbound edges from Domain Users and Authenticated Users.
- Choose a realistic path: prefer quiet, reliable hops (Access Control List (ACL) edges, Active Directory Certificate Services (AD CS)) over noisy ones (password resets, Local Security Authority Subsystem Service (LSASS) access on EDR-heavy hosts).
- Validate hop by hop, gathering evidence for the report and Verify: noting which alerts fired.
- Report by root cause: group the paths found by the choke points they share, and lead with the validated one.
Defender's playbook
DefenderThe strategy: define Tier 0 honestly, collect with privilege on a schedule, Fix: cut the choke points with the most exposure, keep Tier 0 credentials off lower tiers, and alert when a new edge into Tier 0 appears.
Quick wins (days)
- Run your own privileged collection and look at inbound paths to Tier Zero. Verify: Start from Domain Users, Authenticated Users and Everyone, since edges from them affect everyone.
SharpHound.exe -c All --domain corp.example - Review the built-in operator groups (Account, Server, Backup, Print Operators) and Fix: empty them unless there's a documented need.
'Account Operators','Server Operators','Backup Operators','Print Operators' | ForEach-Object { Get-ADGroupMember $_ -Recursive | Select @{n='Group';e={$_}},Name } - Remove Access Control Entrys (ACEs) granted to broad groups on users, groups, Organizational Units (OUs), Group Policy Objects (GPOs) and the domain object. Fix: Domain Users should hold no write rights on anything privileged.
# Example: list explicit ACEs on an OU for review (Get-Acl "AD:OU=Staff,DC=corp,DC=example").Access | Where-Object { -not $_.IsInherited } | Select IdentityReference,ActiveDirectoryRights,ObjectType - Find non-DC principals with replication rights and remove any that aren't approved sync accounts. Risk: Any extra
DCSyncholder is a domain-compromise path. - Deploy Windows Local Administrator Password Solution (LAPS) to Fix: break local-admin password reuse, and scope LAPS read rights by tier.
- Fix the top choke point the analysis shows, usually a jump server, a helpdesk local-admin grant or a nested group. Verify: Re-collect and record the before-and-after exposure.
Longer-term fixes (weeks to months)
- Define and enforce tiering. Separate admin accounts per tier; Fix: deny Tier 0 accounts logon to lower tiers by GPO (deny logon locally, through Remote Desktop Protocol (RDP), as a batch job or as a service); provide Privileged Access Workstations (PAWs).
- Shrink Tier 0. Move Tier 0 users, groups and computers into a dedicated OU with its own tightly controlled Access Control List (ACL) and GPOs. Fix: Treat sync, backup, deployment and Certificate Authority (CA) servers as Tier 0 or remove their control edges.
- Protect credentials in memory: Protected Users for admins, Credential Guard on endpoints and servers, Restricted Admin or Remote Credential Guard for RDP. These reduce what a session edge yields.
- Fix Active Directory Certificate Services (AD CS): audit templates and CA permissions, remove requester-supplied subjects from authentication templates, and narrow enrollment.
- Flatten group nesting and give privileged groups Fix: named, individual members only.
- Adopt attack path management: a weekly privileged collection, a maintained Tier Zero zone, an exposure Key Performance Indicator (KPI), and Verify: alerts when exposure or Tier 0 membership changes.
- Extend to hybrid: collect Entra with AzureHound, make cloud admins cloud-only accounts, and protect the Entra Connect server as Tier 0.
Detection signals
| Signal | Source | Alert on |
|---|---|---|
| 5136: directory object modified | Domain Controller (DC) Security log (directory service changes auditing, plus System Access Control Lists (SACLs)) | Discretionary Access Control List (DACL), owner, member, servicePrincipalName, msDS-KeyCredentialLink, msDS-AllowedToActOnBehalfOfOtherIdentity or gPLink changes on Verify: Tier 0 objects or OUs |
| 4728 / 4732 / 4756: member added to a security group | DC Security log | Additions to any group whose Risk: effective privilege is Tier 0, not just groups with "admin" in the name |
| 4724: password reset by another account | DC Security log | Resets of privileged or service accounts by anyone outside the identity team |
| 4662 with replication extended-right Globally Unique Identifiers (GUIDs) | DC Security log (needs auditing on the domain object) | Verify: Replication requested by a non-DC, the DCSync signature |
| Lightweight Directory Access Protocol (LDAP) enumeration volume (1644 or sensor data) | DC Directory Service log with expensive-query logging, Microsoft Defender for Identity (MDI) | One host querying every object and security descriptor in minutes |
Fan-out to srvsvc, wkssvc, samr pipes | Network sensors, 5145 file share auditing, MDI | A single source contacting hundreds of hosts for sessions and local groups |
| MDI reconnaissance and DCSync alerts | Microsoft Defender for Identity | LDAP, Security Account Manager Remote protocol (SAMR) and user/Internet Protocol (IP) reconnaissance; directory replication from non-DCs |
| 4624 logon type 2, 10 or 3 by Tier 0 accounts on non-Tier-0 hosts | Endpoint Security logs | Risk: A new session edge into Tier 0; should be impossible with logon restrictions |
| New inbound path to Tier Zero | Your scheduled BloodHound analysis | Exposure rising, or a new principal reaching Tier Zero |
Verify the fix worked
- Verify: Re-collect with a privileged account, from a host that can reach every subnet.
- Re-run the same inbound-path queries and confirm the removed edges and paths are gone; Verify: record the exposure number.
- Confirm Tier 0 accounts have no sessions on non-Tier-0 hosts across several looped collections.
- Have testers retry the original path from a standard account and Verify: confirm the alerts above fire.
- Check that SDProp and GPO refresh haven't reintroduced an edge a day later.
Why remediation stalls, and workable compromises
| Objection | Workable compromise |
|---|---|
| "We don't know who uses these permissions." | Log first: enable 5136 and access auditing on the object, watch for 30 days, then Fix: remove what wasn't used. Keep a rollback export of the ACL. |
| "Helpdesk needs admin everywhere." | Keep it on Tier 1 and Tier 2; Fix: remove it only from Tier 0 and shared jump hosts, and give Tier 0 its own management path. |
| "Tiering is a huge project." | Start with logon restrictions for Domain Admins alone. It removes most session edges into Tier 0 for little effort. |
| "The tool shows thousands of paths; we can't fix them all." | You don't need to. Fix the top three choke points and re-measure; Verify: exposure usually drops sharply. |
| "Removing Exchange or migration ACEs might break something." | Test in a lab or on one OU; most legacy grants are documented by the vendor as safe to remove after decommissioning. |
| "We can't run BloodHound; security tools are banned on servers." | Collect from a dedicated admin workstation, or use a commercial product with a supported sensor. Risk: Attackers won't ask permission, so the graph exists either way. |
Executive brief
ExecutiveThe risk in plain language
Our computer network keeps a record of who can do what: which staff can manage which accounts, which servers they can log in to, who is an administrator where. Over years, thousands of small, reasonable permissions accumulate. The risk is that Risk: they line up into a route from any employee's account to full control of the network. Attackers use free tools that find those routes automatically, in minutes, without needing any software vulnerability.
Business impact
- A single phished employee can become Risk: a full network compromise: the precondition for large-scale ransomware and data theft.
- Our access reviews can pass while Risk: the real number of people who can reach full control is hundreds or thousands.
- Routes often run through cloud links too, so on-premises compromise can Risk: reach email, files and cloud systems.
What drives likelihood
- Risk: How many accounts have a route to the most sensitive systems, and how short those routes are.
- Administrators logging on everywhere, leaving reusable credentials on everyday machines.
- Old permissions nobody reviews: grants from past projects, migrations and departed staff.
- No ongoing measurement, so new routes appear silently as the organisation changes.
Cost of inaction
The fixes are mostly staff time and configuration changes, not new products, and the biggest gains come from a few changes. Leaving the routes in place means any successful phishing email is Risk: one short, quiet step from a company-wide incident. Ransomware crews look for exactly this.
What good looks like
- A Fix: small, known set of systems and people can control the network, and it's written down.
- Administrators use Fix: separate accounts and dedicated machines for powerful work.
- The share of accounts with a route to full control is Verify: measured monthly and close to zero.
- New routes trigger an alert, and someone owns fixing them.
Questions executives ask
Are we exposed?
"Almost certainly to some degree; nearly every Active Directory (AD) environment we test has paths. The useful question is how many people can reach full control, and how short the routes are. We measured it: today 1,800 of 2,400 accounts have a route. Three changes would bring that under 100."
Isn't this just a list of permission problems? Why does the 'graph' matter?
"Each permission looks reasonable on its own. Risk: The risk is in how they chain together, and no one reviewing them one at a time can see that. The graph shows the chain, and it shows which single link to remove to cut hundreds of chains at once."
We passed our audit. How can this be possible?
"Audits usually check that controls exist: admin groups reviewed, passwords rotated. They don't test how access combines. Every individual control can pass while the combination still gives an ordinary user a route to the top."
Will Multi-Factor Authentication (MFA) fix this?
"Not on its own. These routes mostly use permissions and credentials already inside the network, after the login MFA protects. MFA is still essential at the front door; this is about what happens once someone is in."
What does it cost to fix?
"Mostly staff time, not products. The biggest wins are permission changes and separating admin accounts, which the existing team can do in weeks. Keeping it fixed needs a recurring measurement, which free tools can do and commercial ones make easier."
How do we know it stays fixed?
"We re-measure on a schedule and track one number: Verify: how many accounts can reach full control. If that number climbs, something changed and we find out before an attacker does."
Presenting this finding to leadership
- Headline: "Any employee's account had a three-step route to full control of the network; one change removes most of those routes."
- Show the picture: one path diagram and one number (how many accounts can reach full control).
- Explain the fix in business terms: remove one shared link this month, separate admin access this quarter.
- The ask: a named owner, staff time for the changes, and Verify: a monthly exposure number reported to leadership.
Talk the talk
Jargon decoder
A chain of relationships leading from an attacker's foothold to a valuable target.
"We found 14 attack paths from Domain Users to Tier 0; the shortest is three hops."
One relationship in the graph that an attacker can use to move from one object to another.
"The GenericWrite edge from IT-Projects to the backup account is the one to remove."
An object in the graph: a user, group, computer, Group Policy Object (GPO), Organizational Unit (OU), domain or certificate object.
"That service account is the most connected node in the domain."
The set of identities and systems that control the domain, and anything that controls them.
"If the backup server can restore a Domain Controller (DC), it's Tier 0."
A relationship many attack paths share, so removing it cuts them all.
"Helpdesk local admin on the jump server is the choke point; 97% of paths cross it."
Everything a single compromised object can reach.
"The blast radius of that phished account is 300 servers and, through one session, the domain."
A principal the tester has compromised and marked as a starting point.
"Mark jdoe as owned and run shortest paths to Domain Admins."
Reaching admin on one machine by stealing the credentials of someone who is admin there, from another machine you already control.
"We weren't admin on the file server, but derivatively we were, through the session on APP07."
A record that a user is logged on to a computer, so their credentials may be in memory there.
"The path depends on a session edge that's six hours old; let's re-collect before we report it."
The tool that gathers directory and host data for the graph.
"Run the collector with a Tier 0 service account so the session data is complete."
The graph query language BloodHound uses to ask custom questions.
"I wrote a Cypher query for every non-Tier-0 principal with DCSync."
BloodHound's way of defining a protected set of assets (Tier 0 by default) to measure paths into.
"The Entra Connect server wasn't in the Tier Zero zone, so paths to it weren't flagged."
The share of principals that have at least one path into a protected zone.
"Tier 0 exposure dropped from 41% to 6% this quarter."
The quiet growth of systems and groups that effectively control the domain.
"Tier 0 sprawl: 38 servers qualify, and only 4 are managed as Tier 0."
Smart questions to ask
Sysadmins
- What is your written definition of Tier 0, and does it include sync, backup, deployment and Certificate Authority (CA) servers?
- When did someone last run a privileged BloodHound collection, and Verify: what was the exposure to Tier Zero?
- Can Domain Admins log on to workstations or member servers, or Fix: is that denied by policy?
- Who holds replication rights on the domain object besides the Domain Controllers (DCs)?
- Do you audit 5136 changes on Tier 0 objects, and Verify: who gets the alert?
- Is Local Administrator Password Solution (LAPS) deployed, and who can read LAPS passwords for Tier 0 servers?
Executives
- How many of our accounts can reach full control of the network today, and what's the target?
- Who owns keeping that number down?
- When we add a system or a team, who checks whether it creates a new route?
Coworkers
- Was collection privileged, or are session-based paths under-represented?
- Which path are we leading with, and Verify: did we validate every hop?
- What are the top choke points by exposure, so the report says "fix these three"?
- Are Active Directory Certificate Services (AD CS) and hybrid edges in scope and in the data?
Say this, not that
"BloodHound found that you're vulnerable."
"The graph shows a three-hop path from all users to domain admin; we validated each hop."
"You have too many domain admins."
"Your effective Tier 0 is 600 principals once nesting, Access Control Lists (ACLs) and sessions are counted, against 9 named admins."
"There are no attack paths."
"From what we could collect with our access, we found no paths; session data was limited, so we can't rule out session-based ones."
"Remove all these permissions."
"Remove these three edges first; they carry 90% of the paths. Then we re-collect and look again."
"BloodHound is a hacking tool, block it."
"BloodHound is a mapping tool. Detect unauthorised collection, and run it yourselves on a schedule."
"The helpdesk group is dangerous."
"Helpdesk's local admin on the jump server is dangerous because Tier 0 admins log on there."
"Shortest path is the riskiest path."
"Shortest by hops isn't easiest; we rank paths by how many people they expose and how realistic each hop is."
Same point, two audiences
"No single setting is the problem. It's how a few reasonable-looking settings line up to give an ordinary employee's account a route to full control."
"Domain Users has GenericAll on IT-Projects, IT-Projects has ForceChangePassword over the Staff Organizational Unit (OU), and adm_backup lives in that OU and is in Backup Operators."
"One change removes 97% of the routes. We'd do that this month and handle the rest over the quarter."
"Split JUMP01 by tier, remove Helpdesk from local Administrators on the Tier 0 jump host, and deny Tier 0 logon to Tier 1 servers by Group Policy Object (GPO)."
"We'll report one number each month: how many accounts can reach full control. It should go down and stay down."
"Schedule a privileged SharpHound collection weekly, track the Tier Zero exposure trend, and alert on new inbound edges."
"The systems that can control everything include our backup and software-deployment servers, not just the admin accounts, so they need the same protection."
"System Center Configuration Manager (SCCM) site servers, the backup server and Entra Connect all have control edges into Domain Controllers (DCs), so add them to the Tier Zero zone and apply Tier 0 logon restrictions."
Keep going
What to learn next, in order
- Active Directory Certificate Services (AD CS) abuse. The certificate escalation classes behind the
ADCSESCedges are the largest single source of short paths, and deserve a note of their own. - Tiering and the enterprise access model. How to actually build Tier 0 boundaries: admin account separation, logon restrictions, Privileged Access Workstations (PAWs), and authentication policies and silos (Kerberos Part 3).
- NT LAN Manager (NTLM) relay and coercion. The techniques that create edges at runtime (coerced authentication relayed into Lightweight Directory Access Protocol (LDAP) or AD CS), which the static graph models only partly.
- Hybrid identity paths. Entra ID roles, Entra Connect, device management and AzureHound data, where on-premises and cloud graphs join.
- Cypher for defenders. Enough of the query language to write your own exposure reports and change diffs.
Resources worth seeking out
- BloodHound documentation (SpecterOps): the edge reference pages explain each edge's meaning, abuse and opsec notes, and are the authoritative list of current edge names.
- The Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK) entry for BloodHound (S0521) and the discovery techniques it maps to, for findings language.
- Microsoft's documentation on securing privileged access and the enterprise access model, for the tiering vocabulary clients' teams will recognise.
- A practice lab: a deliberately vulnerable Active Directory (AD) range (several open-source projects build one), so you can collect, find and remediate paths Verify: in an environment you're authorised to break.
- Conference talks by the BloodHound authors on attack path management and choke points, for the defender's framing.
Active Directory attack paths, thinking in graphs
Acronyms
Every acronym used on this page. Four test modes are below the table.
| Acronym | Expansion | Plain English | Why it matters |
|---|---|---|---|
| ACE | Access Control Entry | One line in an Access Control List (ACL): a principal, a right, and whether it is allowed or denied. | Each abusable Access Control Entry (ACE) becomes one edge in the graph. |
| ACL | Access Control List | The list of permissions attached to an object, saying who can do what to it. | Most of the surprising edges in an Active Directory (AD) graph come from Access Control Lists (ACLs) nobody remembers granting. |
| AD | Active Directory | Microsoft's on-premises directory service: the database of users, groups, computers and the permissions between them. | Every node and most edges in this note are Active Directory (AD) objects and AD permissions. |
| AD CS | Active Directory Certificate Services | Microsoft's certificate authority role, integrated with Active Directory (AD). | Misconfigured certificate templates add some of the shortest paths to domain control, and BloodHound models them as edges. |
| ADUC | Active Directory Users and Computers | The classic Microsoft console for managing Active Directory (AD) objects. | The tool most admins review permissions in, one object at a time, which is the list problem in action. |
| API | Application Programming Interface | A defined way for programs to talk to each other. | BloodHound Community Edition (CE) exposes an Application Programming Interface (API) for uploads and queries, which is how teams automate attack-path reporting. |
| APM | Attack Path Management | The continuous practice of mapping, measuring and removing attack paths to critical assets. | The defender's discipline built on the same graph attackers use. |
| ATT&CK | Adversarial Tactics, Techniques, and Common Knowledge | MITRE's public catalogue of attacker techniques. | Gives findings a shared vocabulary; BloodHound itself is catalogued as software S0521. |
| CA | Certificate Authority | A server that issues digital certificates others trust. | An enterprise Certificate Authority (CA) trusted for logon is Tier 0; control of it lets an attacker mint credentials for anyone. |
| CE | Community Edition | The free, open-source edition of BloodHound. | What most testers and many defenders run; it includes the default Tier Zero zone and OpenGraph. |
| CFO | Chief Financial Officer | The executive responsible for finances. | Often in the room for readouts and asks the cost questions. |
| CIO | Chief Information Officer | The executive responsible for Information Technology (IT). | Usually owns the build-versus-buy decision for attack path tooling. |
| CISO | Chief Information Security Officer | The executive responsible for an organization's security program. | The usual audience for an attack-path readout. |
| DA | Domain Admins | The built-in Active Directory (AD) group with full administrative control of a domain. | The classic target node; "shortest path to Domain Admins (DA)" is the question BloodHound made famous. |
| DACL | Discretionary Access Control List | The part of an object's security descriptor that grants or denies access. | Write access to the Discretionary Access Control List (DACL) (WriteDACL) lets an attacker grant themselves any other right. |
| DC | Domain Controller | A server that holds a copy of the Active Directory (AD) database and authenticates logons. | The canonical Tier 0 asset; controlling one means controlling the domain. |
| EA | Enterprise Admins | The built-in group with administrative control over every domain in a forest. | A Tier 0 group above Domain Admins (DA); a path to it is a path to the whole forest. |
| EDR | Endpoint Detection and Response | Security software on each host that records activity and can block or respond to threats. | Often catches the collector binary or the credential theft that walks a session edge. |
| gMSA | group Managed Service Account | A service account whose long random password Active Directory (AD) rotates automatically. | Strong against cracking, but whoever can read its password (ReadGMSAPassword) controls it, which is an edge. |
| GPO | Group Policy Object | A bundle of settings that Active Directory (AD) pushes to the users and computers in the containers it is linked to. | Whoever can edit a Group Policy Object (GPO) can run code on everything it applies to, which makes GPO control an attack edge. |
| GUI | Graphical User Interface | The visual, point-and-click part of an application. | BloodHound's graph view is how most people first meet attack paths; Cypher is the power-user alternative. |
| GUID | Globally Unique Identifier | A 128-bit identifier guaranteed to be unique, used for objects, attributes and extended rights in Active Directory (AD). | Replication rights show up in event 4662 as Globally Unique Identifiers (GUIDs), which is how DCSync detections match them. |
| IP | Internet Protocol | The addressing system for devices on a network. | Reconnaissance detections often key on one source Internet Protocol (IP) enumerating many hosts. |
| IT | Information Technology | The function that runs an organization's computers and networks. | Information Technology (IT) support groups are among the most common choke points. |
| JSON | JavaScript Object Notation | A plain-text data format of keys and values. | Collectors write their output as JavaScript Object Notation (JSON) files, and OpenGraph extensions describe new nodes and edges in it. |
| KPI | Key Performance Indicator | A measurable value used to track progress toward a goal. | Attack-path exposure is one of the few Active Directory (AD) risks that can be reported as a trend number. |
| LAN | Local Area Network | A network within one site or building. | Appears inside NT LAN Manager (NTLM); listed so the expansion is complete. |
| LAPS | Local Administrator Password Solution | Microsoft's feature that sets a unique, rotating local administrator password on each machine and stores it in the directory. | Kills password-reuse edges between hosts, but adds a ReadLAPSPassword edge for whoever can read the stored password. |
| LDAP | Lightweight Directory Access Protocol | The protocol used to query and modify directory data in Active Directory (AD). | Most graph collection is ordinary Lightweight Directory Access Protocol (LDAP) reads that any domain user is allowed to make. |
| LSA | Local Security Authority | The Windows subsystem that enforces local security policy and handles authentication. | Collectors can query local group membership through Local Security Authority (LSA) calls; Local Security Authority Subsystem Service (LSASS) is its process. |
| LSASS | Local Security Authority Subsystem Service | The Windows process that handles logons and holds credential material in memory. | The session edge matters because an admin on the host can extract a logged-on user's credentials from it. |
| MDI | Microsoft Defender for Identity | Microsoft's sensor-based detection product for on-premises Active Directory (AD). | Ships detections for reconnaissance such as Lightweight Directory Access Protocol (LDAP), Security Account Manager Remote protocol (SAMR) and session enumeration, and feeds Microsoft's attack-path views. |
| MFA | Multi-Factor Authentication | Logging in with more than one kind of proof, such as a password plus a phone prompt. | Doesn't break most Active Directory (AD) graph edges, which use tickets, hashes and permissions rather than interactive logons. |
| NT | New Technology | The Windows New Technology (NT) family name, kept in names like NT LAN Manager (NTLM) and the NT hash. | Appears inside NT LAN Manager (NTLM); listed so the expansion is complete. |
| NTLM | NT LAN Manager | Microsoft's older challenge-response authentication protocol. | Stolen NT LAN Manager (NTLM) hashes are a common way to walk an AdminTo or HasSession edge. |
| OS | Operating System | The core software that runs a computer, such as Windows. | Appears in Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK) technique names like Operating System (OS) Credential Dumping. |
| OU | Organizational Unit | A folder-like container in Active Directory (AD) used to organise objects and delegate administration. | Control of an Organizational Unit (OU) usually means control of every object inside it, through inheritance and linked Group Policy Objects (GPOs). |
| PAW | Privileged Access Workstation | A hardened, dedicated machine used only for administrative work. | Keeps Tier 0 credentials off everyday hosts, which deletes session edges at the source. |
| RBCD | Resource-Based Constrained Delegation | Kerberos delegation configured on the target, naming which accounts may impersonate users to it. | Write access to a computer object becomes an impersonation edge through Resource-Based Constrained Delegation (RBCD). |
| RDP | Remote Desktop Protocol | Microsoft's protocol for interactive remote logon to a Windows host. | An Remote Desktop Protocol (RDP) logon by an admin leaves credentials in memory and creates a session edge. |
| RPC | Remote Procedure Call | A mechanism for one computer to call a function on another. | Session enumeration and local-group lookups are Remote Procedure Call (RPC) calls that collectors make against every host. |
| S4U | Service for User | Kerberos extensions that let a service obtain tickets on behalf of a user. | The machinery behind delegation edges; Service for User (S4U) patterns in 4769 events reveal their abuse. |
| SACL | System Access Control List | The part of a security descriptor that decides which access attempts get audited. | Directory-access detections (event 4662) only fire where a System Access Control List (SACL) asks for them. |
| SAMR | Security Account Manager Remote protocol | The Remote Procedure Call (RPC) interface for querying users and groups, including a host's local groups, remotely. | Collectors use it to learn who is a local administrator; modern Windows restricts it to admins by default. |
| SCCM | System Center Configuration Manager | Microsoft's endpoint management platform, now called Configuration Manager. | It can run code on every managed host, so its servers and admins belong in Tier 0. |
| SID | Security Identifier | The unique, permanent identifier Windows assigns to every user, group and computer. | BloodHound keys its nodes on Security Identifiers (SIDs), so renamed accounts stay the same node. |
| SIEM | Security Information and Event Management | The platform that collects logs centrally and runs correlation and alerting. | Where directory-change and reconnaissance detections live. |
| SMB | Server Message Block | Windows file-sharing protocol, also the transport for many remote management calls. | Session and local-group collection travel over Server Message Block (SMB) named pipes to each host. |
| SOC | Security Operations Center | The team that monitors alerts and responds to incidents. | Needs to know which graph-changing events (new Access Control Entrys (ACEs), new group members) deserve a page. |
| SPN | Service Principal Name | The name that ties a Kerberos service to the account that runs it. | Write access to an account's Service Principal Name (SPN) makes it Kerberoastable, which turns a write edge into a password-cracking opportunity. |
| SSO | Single Sign-On | Logging in once and being trusted by many applications. | Hybrid identity ties on-premises Active Directory (AD) to cloud apps, so an AD path can end in a cloud tenant. |
| TGT | Ticket Granting Ticket | The Kerberos ticket that proves a user's identity and is used to request access to services. | Several edges (unconstrained delegation, coercion) are really ways of obtaining someone else's Ticket Granting Ticket (TGT). |
Test yourself
Flashcards
Quiz
Fifteen questions, mostly scenarios. Feedback appears as soon as you choose.
Conversation drills
Say or type your answer first, then compare with the sample.
Export cards
Basic cards (Quizlet and Anki Basic)
Anki cloze cards
My private notebook
Personal notes and bookmarks are private. Unsaved text is temporarily kept in this tab’s browser storage to recover supported sign-in redirects and reloads. Closing the tab may lose unsaved text.
Checking sign-in…