
Identity & Access ManagementVulnerability Management
BloodHound Enterprise
Maps and remediates identity attack paths across AD, Entra ID, AWS, Okta, GitHub, and Jamf.
BloodHound Enterprise Overview
What it does
BloodHound Enterprise is an Identity Attack Path Management (IAPM) platform that continuously maps the relationships, permissions, and trust dependencies linking every identity to an organization's most sensitive systems. Rather than scoring misconfigurations in isolation, it models the environment as a directed graph and traces the chained attack paths an adversary would follow to escalate privilege and reach Tier Zero assets across Active Directory, Entra ID, and hybrid estates.
How it works
The platform ingests directory data through the SharpHound and AzureHound collectors and, through its OpenGraph framework and OpenHound collector, extends the same graph model to AWS, Okta, GitHub, and Jamf-managed Mac environments. It runs choke point analysis to pinpoint the single remediations that sever the largest share of paths, then delivers step-by-step, impact-aware remediation guidance, with the BloodHound Hunter agent interface surfacing paths and remediation steps from the same graph intelligence. Privilege Zones let teams define custom security boundaries and enforce least privilege, while Risk Posture Trend Analysis baselines exposure and tracks reduction over time across business units.
Credentials and traction
BloodHound Enterprise is FedRAMP High Authorized and holds SOC 2 Type II, ISO 27001:2022, and ISO 27017 attestations, with TX-RAMP Level 2 certification and a government edition operating in AWS GovCloud. SpecterOps also carries CREST penetration testing accreditation. The platform is used by Microsoft and Woodside Energy, among enterprise and public-sector identity and security teams managing complex Active Directory and multi-cloud identity estates.
Key Capabilities
mapped to solution categoriesModels how exposures chain across assets and identities to reach critical systems, mapping attack paths and blast radius to separate reachable crown-jewel risks from dead ends.
Ranks exposures by their accessibility, visibility, and exploitability combined with asset criticality, business impact, and the security controls already in place, so a medium-severity issue on a critical, reachable, unprotected service outranks a high-severity issue on an isolated or compensated one.
Generates trend reports on exposure posture (new exposure, remediated exposure, outstanding exposure by severity), in business language suitable for security program reviews.
Creates and tracks remediation tasks across teams and ticketing systems, measuring exposure reduction over time rather than simply listing open findings.
Discovers assets and their exposures across the external, internal, cloud, and end-user attack surfaces, covering endpoints, network and on-premises infrastructure, identities and entitlements, hosts, containers, IoT and OT, and cloud platforms and applications, either through native discovery or by integrating third-party discovery sources, and reports vulnerabilities, misconfigurations, unmanaged assets, and compliance gaps in one inventory.
Tracks the life cycle of exposures through a centralized, aggregated view supported by automated workflows.
Groups assets into business processes, applications, or protection surfaces with named owners and criticality, so each exposure management cycle is scoped to what the business must protect and exposure is assessed and reported per scope rather than across the whole estate.
Compares granted permissions against observed usage to identify entitlements that exceed what an identity actually needs, candidates for right-sizing or revocation.
Scores each identity by aggregated risk signals (excessive permissions, stale credentials, anomalous access patterns, MFA gaps) to prioritize remediation effort.
Discovers service accounts, OAuth apps, API keys, JWT tokens, and Kubernetes service accounts alongside human accounts, mapping the complete identity population.
Identifies the small set of privileges or relationships whose removal severs the largest share of attack paths, then delivers impact-aware, step-by-step remediation guidance so teams make the few changes that eliminate the most identity exposure.
Models identities, permissions, and trust relationships as a directed graph and traces the chained attack paths an adversary could follow from any identity to the organization's most critical assets, instead of scoring identity misconfigurations in isolation.
Integrates identity data, activity, relationships, and configuration from directories, identity providers, IGA, PAM, cloud platforms, and SaaS applications, including applications not yet connected to any IAM tool, into one correlated inventory of every human and non-human actor with its accounts and entitlements, the single view on which posture assessment and analytics run.
Compliance
certificationsIntegrations
compatible toolsImplementation & support
Info last updated on September 23, 2026
Buyers
Start a shortlist with BloodHound Enterprise
Compare options, add your notes, and run informed evaluations.
Vendors
Is this your product?
Claim your profile to connect with the teams looking for your solutions.