BloodHound Analysis
Bloodhound is a powerful reconnaissance tool designed to model and analyze Active Directory (AD) environments using graph theory. By representing users, computers, groups, and permissions as nodes and edges in a graph, Bloodhound enables analysts to visualize complex relationships, identify potential attack paths, and pinpoint users or systems with elevated privileges. This section provides an overview of how Bloodhound models AD environments and leverages graph analysis for offensive reconnaissance.
Modeling AD with Graph Theory¶
Bloodhound abstracts AD into a graph where:
- Nodes represent entities such as users, computers, groups, and OUs.
- Edges represent relationships like memberOf, canRDP, trusts, or hasPermission.
For example:
- A user node might be connected to a group node via an edge labeled memberOf.
- A computer node might be linked to a user node via an edge labeled canRDP, indicating the user has remote access to the machine.
This graph structure allows Bloodhound to uncover indirect relationships that might not be apparent through traditional AD queries. For instance, a user with access to a machine that is a member of the Domain Admins group could be identified as a potential pivot point.
Identifying Privileged Users¶
Bloodhound's "Privileged Users" tab highlights users or computers with access to critical resources. It leverages graph algorithms to:
1. Detect users with direct access to privileged groups (e.g., Domain Admins, Enterprise Admins).
2. Identify indirect access paths, such as users who can reach privileged groups through chained permissions (e.g., User -> Server -> Domain Admins).
Example query:
Attack Path Discovery¶
Bloodhound's "Attack Paths" tab visualizes potential escalation routes by traversing the graph. For example:
- A low-privilege user might have access to a machine that is a member of the Domain Admins group.
- Bloodhound would map this as a path: User -> Machine -> Domain Admins, enabling the attacker to escalate privileges by compromising the machine.
To simulate this, analysts can use Bloodhound's Cypher query language to search for paths:
MATCH (u:User)-[:canRDP]->(m:Computer)-[:memberOf]->(g:Group)
WHERE g.name = "Domain Admins"
RETURN u.name, m.name
Domain Admins group.
Graph Algorithms for Reconnaissance¶
Bloodhound employs graph algorithms to automate analysis:
- Breadth-First Search (BFS): Finds the shortest attack paths from a starting node.
- Betweenness Centrality: Identifies nodes that are critical for connecting other nodes (e.g., a machine that bridges multiple subnets).
- Community Detection: Reveals tightly-knit groups of users or machines that might indicate misconfigurations or hidden privilege hierarchies.
These algorithms help Red Teams prioritize targets and understand the topology of the AD environment.
Key takeaways¶
- Bloodhound models AD as a graph to expose hidden relationships and attack surfaces.
- Privileged users and indirect access paths are identified through graph traversal and centrality metrics.
- Attack paths are visualized to guide exploitation planning, such as escalating from a low-privilege user to domain admins.
- Graph algorithms like BFS and betweenness centrality automate the analysis of complex AD structures.
- Bloodhound is a critical tool for Red Teams to map and exploit AD environments during authorized testing.