
Identity & Access ManagementVulnerability Management
BloodHound Enterprise
Maps and remediates privilege escalation paths across AD, Entra ID, Okta, GitHub, and Jamf.
BloodHound Enterprise Overview
What it does
BloodHound Enterprise is an Identity Attack Path Management (IAPM) platform that continuously maps the relationships, permissions, and trust dependencies linking every identity to an organization's most sensitive systems. Rather than scoring misconfigurations in isolation, it models the environment as a directed graph and traces the chained attack paths an adversary would follow to escalate privilege and reach Tier Zero assets across Active Directory, Entra ID, and hybrid estates.
How it works
The platform ingests directory data through the SharpHound and AzureHound collectors and, through its OpenGraph framework and OpenHound collector, extends the same graph model to Okta, GitHub, and Jamf-managed Mac environments. It runs choke point analysis to pinpoint the single remediations that sever the largest share of paths, then delivers step-by-step, impact-aware remediation guidance. Privilege Zones let teams define custom security boundaries and enforce least privilege, while Risk Posture Trend Analysis baselines exposure and tracks reduction over time across business units.
Credentials and traction
BloodHound Enterprise is FedRAMP High Authorized and holds SOC 2 Type II, ISO 27001:2022, and ISO 27017 attestations, with TX-RAMP Level 2 certification and a government edition operating in AWS GovCloud. SpecterOps also carries CREST penetration testing accreditation. The platform is used by Microsoft and Woodside Energy, among enterprise and public-sector identity and security teams managing complex Active Directory and multi-cloud identity estates.
Key Capabilities
mapped to solution categoriesModels how exposures chain across assets and identities to reach critical systems, mapping attack paths and blast radius to separate reachable crown-jewel risks from dead ends.
Ranks exposures by combining exploitability signals with asset business criticality, so that a medium CVE on a critical customer-facing service ranks above a high CVE on an isolated dev instance.
Generates trend reports on exposure posture (new exposure, remediated exposure, outstanding exposure by severity), in business language suitable for security program reviews.
Creates and tracks remediation tasks across teams and ticketing systems, measuring exposure reduction over time rather than simply listing open findings.
Continuously inventories exposures across internet-facing assets, cloud, SaaS, and identity, including shadow IT, misconfigurations, and excessive permissions beyond CVE scanning.
Confirms whether a discovered vulnerability is exploitable in the specific environment through automated exploitation testing or manual validation, distinguishing confirmed risk from theoretical risk.
Tracks the life cycle of exposures through a centralized, aggregated view supported by automated workflows.
Compliance
certificationsIntegrations
compatible toolsImplementation & support
Info last updated on June 28, 2026
Vendors
Is this your product?
Claim your profile to connect with the teams looking for your solutions.