↳ Source GitHubConnecteur
BloodHound Enterprise Data Connector (using Azure Functions)
Description
**[BloodHound Enterprise](https://bloodhoundenterprise.io/)** from **[SpecterOps](https://specterops.io/)** is an **Identity Attack Path Management** platform: it maps how attackers can move through identity relationships to reach critical assets so teams can **prioritize and remediate** those paths not only detect them. It brings clarity to identity sprawl in **Active Directory**, **Azure**, and beyond, including **Privilege Zone** style protection around what matters most in your environment.
This **Microsoft Sentinel** connector adds **BloodHound Enterprise attack path context** into your workspace alongside logs and alerts so you can **enrich investigations**, focus on high-value findings, and track exposure, audit activity, and **Tier Zero** assets in one place.
**What this connector does**
- Connects to the **BloodHound Enterprise REST API** using your configured credentials (see [Working with the API](https://bloodhound.specterops.io/integrations/bloodhound-api/working-with-api)) and runs on a **schedule** you set when the Azure Function is deployed. The data is collected through Azure Functions and stored in custom Log Analytics tables with dedicated Data Collection Rules (DCR) and Data Collection Endpoints (DCE).
- Statut déclaré
- 1
- Auteur / éditeur déclaré
- SpecterOps
Sources déclarées
Métadonnées du fichier source. Aucune dépendance déduite du KQL.
Types de données
Permissions déclarées
read and write permissions on the workspace are required.
Workspace
Workspace
read permissions to shared keys for the workspace are required. [See the documentation to learn more about workspace keys](https://docs.microsoft.com/azure/azure-monitor/platform/agent-windows#obtain-workspace-id-and-key).
Keys
Workspace
Microsoft.Web/sites permissions
Read and write permissions to Azure Functions to create a Function App is required. [See the documentation to learn more about Azure Functions](https://docs.microsoft.com/azure/azure-functions/).
BloodHound Enterprise API access
**Token ID**, **Token key**, and your tenant **base URL** are required to authenticate to the BloodHound Enterprise REST API (requests are signed per the SpecterOps API model see [Working with the API](https://bloodhound.specterops.io/integrations/bloodhound-api/working-with-api)).
Instructions du connecteur
Contenu publié dans le dépôt. Consultez le fichier original pour l’ensemble des paramètres.
Step 1. Create BloodHound Enterprise API credentials
In your BloodHound Enterprise tenant, create API credentials (**Token ID** and **Token key**) used to sign requests to the REST API. Follow [Working with the API](https://bloodhound.specterops.io/integrations/bloodhound-api/working-with-api) to create API credentials then store the values securely.
Step 2. Create Microsoft Entra application
Create a Microsoft Entra ID (Azure AD) application used for ingestion to Log Analytics (for example DCE/DCR-related access). Follow [Create a Microsoft Entra application](https://learn.microsoft.com/azure/azure-monitor/logs/tutorial-logs-ingestion-portal#create-microsoft-entra-application) to create Microsoft Entra application & its credentials then save **Application (client) ID**, **Client secret** value, and any other IDs your administrator requires. Store the client secret securely.
Step 3. Deploy Function App
>**NOTE:** This connector uses Azure Functions to pull data from BloodHound Enterprise into Microsoft Sentinel. This might result in additional data ingestion costs. Check the [Azure Functions pricing page](https://azure.microsoft.com/pricing/details/functions/) for details.
>**IMPORTANT:** Before deploying the BloodHound Enterprise connector, have the **Workspace name** (see below), **BloodHound Enterprise tenant URL**, **Token ID** and **Token key**, **Microsoft Entra Application (client) ID** and **client secret**, and your desired **environment** and **finding type** filters (or use template defaults such as **All**) ready.
Workspace Name
Deploy all the resources related to the data connector
1. Click the **Deploy to Azure** button below.
[](https://aka.ms/sentinel-BloodhoundEnterprise-azuredeploy)
2. Select the preferred **Subscription**, **Resource Group**, and **Location**.
3. Enter **Function App name**, **Log Analytics workspace name** (Microsoft Sentinel workspace), **BloodHound Enterprise tenant domain** (URL), **BloodHound Token ID** and **Token key** (secure parameters), **Microsoft Entra Application (client) ID**, and **Microsoft Entra application client secret**.
4. Optional: set **Lookup days** (historical lookback), **Selected BloodHound environments** (comma-separated or **All**), and **Selected finding types** (or **All**) as described in the template.
5. Click **Review + create**, then **Create** to deploy.
Contenus associés
Liens établis à partir des identifiants déclarés et des manifests des solutions.
Traçabilité de la source
GitHubLes valeurs affichées proviennent des fichiers du dépôt Azure/Azure-Sentinel. Elles décrivent le modèle publié, pas la configuration de votre workspace.
- Commit
9800e51↗- Identifiant source
BloodHoundEnterprise
GSTEP / SUIVI DU CATALOGUE
Ajouté au catalogue : 16 sept. 2026 · 05:49 UTC
Dernier changement observé : 16 sept. 2026 · 05:49 UTC