Description
The BloodHound Enterprise Microsoft Sentinel solution ingests your BloodHound Enterprise posture and attack paths into Microsoft Sentinel. Use the dashboards to track the Active Directory and Azure attack paths of your environment. Create alerts to detect when new attack paths emerge or new the exposure increases.
- Version
- 3.2.2
- Declared author / publisher
- SpecterOps - support@specterops.io
- Support tier
- Partner
Related content
Links established from declared identifiers and solution manifests.
Analytics rules102
BloodHound Attack Path Finding - Add Key Credential Link Privileges on Tier Zero ObjectsMedium→BloodHound Attack Path Finding - Add Member Privileges on Tier Zero Security GroupsMedium→BloodHound Attack Path Finding - Add Members to Tier Zero GroupMedium→BloodHound Attack Path Finding - Add Owner to Tier Zero Object via MS Graph App RoleMedium→BloodHound Attack Path Finding - Add Resource-Based Constrained Delegation Privileges on Tier Zero ComputersMedium→BloodHound Attack Path Finding - Add Secret to Tier Zero PrincipalMedium→BloodHound Attack Path Finding - AddOwner Role on Tier Zero ResourceMedium→BloodHound Attack Path Finding - AddSelf Privilege on Tier Zero Security GroupsMedium→BloodHound Attack Path Finding - Admins on Tier Zero ComputersMedium→BloodHound Attack Path Finding - AKS Contributor Role on Tier Zero Managed ClusterMedium→BloodHound Attack Path Finding - AllExtended Privileges on Tier Zero ObjectsMedium→BloodHound Attack Path Finding - App Admin Control of Tier Zero PrincipalMedium→BloodHound Attack Path Finding - AS-REP Roastable User AccountsMedium→BloodHound Attack Path Finding - Avere Contributor Role on Tier Zero Virtual MachineMedium→BloodHound Attack Path Finding - Cloud App Admin Over Tier Zero PrincipalMedium→BloodHound Attack Path Finding - Command Execution on Tier Zero Virtual MachineMedium→BloodHound Attack Path Finding - Computers Vulnerable to Coercion-Based NTLM Relay to SMB AttackMedium→BloodHound Attack Path Finding - Constrained Delegation on Tier Zero ComputersMedium→BloodHound Attack Path Finding - Contributor Role on Tier Zero Automation AccountMedium→BloodHound Attack Path Finding - Contributor Role on Tier Zero ResourceMedium→BloodHound Attack Path Finding - DCOM Users on Tier Zero ComputersMedium→BloodHound Attack Path Finding - ForceChangePassword Privileges on Tier Zero ObjectsMedium→BloodHound Attack Path Finding - GenericAll Privileges on Tier Zero ObjectsMedium→BloodHound Attack Path Finding - GenericWrite Privileges on Tier Zero ObjectsMedium→BloodHound Attack Path Finding - Get Certifcates on Tier Zero Key VaultMedium→BloodHound Attack Path Finding - Get Keys on Tier Zero Key VaultMedium→BloodHound Attack Path Finding - Get Secrets on Tier Zero Key VaultMedium→BloodHound Attack Path Finding - Kerberoastable User AccountsMedium→BloodHound Attack Path Finding - Kerberos Delegation on Tier Zero ObjectsMedium→BloodHound Attack Path Finding - Key Vault Contributor Role on Tier Zero ResourceMedium→BloodHound Attack Path Finding - Large Default Group With SyncLapsPassword PrivilegesMedium→BloodHound Attack Path Finding - Large Default Groups in DCOM Users GroupsMedium→BloodHound Attack Path Finding - Large Default Groups in Local Administrator GroupsMedium→BloodHound Attack Path Finding - Large Default Groups in PS Remote Users GroupsMedium→BloodHound Attack Path Finding - Large Default Groups in SQL Admins GroupsMedium→BloodHound Attack Path Finding - Large Default Groups With Add Key Credential Link PrivilegesMedium→BloodHound Attack Path Finding - Large Default Groups With Add Member PrivilegesMedium→BloodHound Attack Path Finding - Large Default Groups With Add Self PrivilegesMedium→BloodHound Attack Path Finding - Large Default Groups With All Extended PrivilegesMedium→BloodHound Attack Path Finding - Large Default Groups With ForceChangePassword PrivilegesMedium→BloodHound Attack Path Finding - Large Default Groups With GenericAll PrivilegesMedium→BloodHound Attack Path Finding - Large Default Groups With GenericWrite PrivilegesMedium→BloodHound Attack Path Finding - Large Default Groups With Limited Ownership PrivilegesMedium→BloodHound Attack Path Finding - Large Default Groups With Ownership PrivilegesMedium→BloodHound Attack Path Finding - Large Default Groups With RDP AccessMedium→BloodHound Attack Path Finding - Large Default Groups With Read GMSA Password PrivilegesMedium→BloodHound Attack Path Finding - Large Default Groups With Read LAPS Password PrivilegesMedium→BloodHound Attack Path Finding - Large Default Groups With Resource-Based Constrained Delegation PrivilegesMedium→BloodHound Attack Path Finding - Large Default Groups With WriteAccountRestrictions PrivilegesMedium→BloodHound Attack Path Finding - Large Default Groups With WriteDacl PrivilegeMedium→BloodHound Attack Path Finding - Large Default Groups With WriteGpLink PrivilegeMedium→BloodHound Attack Path Finding - Large Default Groups With WriteOwner PrivilegesMedium→BloodHound Attack Path Finding - Large Default Groups With WriteOwnerLimitedRights PrivilegesMedium→BloodHound Attack Path Finding - Large Default Groups With WriteServicePrincipalName PrivilegesMedium→BloodHound Attack Path Finding - Legacy SID History on Tier Zero ObjectsMedium→BloodHound Attack Path Finding - Limited Ownership Privileges on Tier Zero ObjectsMedium→BloodHound Attack Path Finding - Logic App Contributor Role on Tier Zero Logic AppMedium→BloodHound Attack Path Finding - Logons From Tier Zero UsersMedium→BloodHound Attack Path Finding - Non Tier Zero Principals With ADCS ESC1 PrivilegesMedium→BloodHound Attack Path Finding - Non Tier Zero Principals With ADCS ESC10 Scenario A PrivilegesMedium→BloodHound Attack Path Finding - Non Tier Zero Principals With ADCS ESC13 Privileges Against Tier Zero GroupMedium→BloodHound Attack Path Finding - Non Tier Zero Resource Assigned to Tier Zero Service PrincipalMedium→BloodHound Attack Path Finding - Non-Tier Zero AD User Synced to Tier Zero Entra UserMedium→BloodHound Attack Path Finding - Non-Tier Zero Computer Hosting EnterpriseCA Trusted for NT AuthenticationMedium→BloodHound Attack Path Finding - Non-Tier Zero Entra User Synced to Tier Zero AD UserMedium→BloodHound Attack Path Finding - Non-Tier Zero Principal Can Grant Tier Zero App RolesMedium→BloodHound Attack Path Finding - Non-Tier Zero Principal Can Grant Tier Zero Entra ID RoleMedium→BloodHound Attack Path Finding - Non-Tier Zero Principal Trusted for Unconstrained DelegationMedium→BloodHound Attack Path Finding - Non-Tier Zero Principals With ADCS ESC10 Scenario B PrivilegesMedium→BloodHound Attack Path Finding - Non-Tier Zero Principals With ADCS ESC3 PrivilegesMedium→BloodHound Attack Path Finding - Non-Tier Zero Principals With ADCS ESC4 PrivilegesMedium→BloodHound Attack Path Finding - Non-Tier Zero Principals With ADCS ESC6 Scenario A PrivilegesMedium→BloodHound Attack Path Finding - Non-Tier Zero Principals With ADCS ESC6 Scenario B PrivilegesMedium→BloodHound Attack Path Finding - Non-Tier Zero Principals With ADCS ESC9 Scenario A PrivilegesMedium→BloodHound Attack Path Finding - Non-Tier Zero Principals With ADCS ESC9 Scenario B PrivilegesMedium→BloodHound Attack Path Finding - Non-Tier Zero Principals With DCSync PrivilegesMedium→BloodHound Attack Path Finding - Owner Role on Tier Zero ResourceMedium→BloodHound Attack Path Finding - Ownership of Tier Zero PrincipalMedium→BloodHound Attack Path Finding - Ownership Privileges on Tier Zero ObjectsMedium→BloodHound Attack Path Finding - PS Remote Users on Tier Zero ComputersMedium→BloodHound Attack Path Finding - RDP Users on Tier Zero ComputersMedium→BloodHound Attack Path Finding - Read GMSA Password Privileges on Tier Zero ObjectsMedium→BloodHound Attack Path Finding - ReadLapsPassword Privileges on Tier Zero ObjectsMedium→BloodHound Attack Path Finding - Reset a Tier Zero User's PasswordMedium→BloodHound Attack Path Finding - SQL Admin Users on Tier Zero ComputersMedium→BloodHound Attack Path Finding - SyncLapsPassword Privileges on Tier Zero ObjectsMedium→BloodHound Attack Path Finding - Tier Zero Computer Vulnerable to Coercion-Based NTLM Relay to ADCS (ESC8) AttackMedium→BloodHound Attack Path Finding - Tier Zero Computer Vulnerable to Coercion-Based NTLM Relay to LDAP AttackMedium→BloodHound Attack Path Finding - Tier Zero Computer Vulnerable to Coercion-Based NTLM Relay to LDAPS AttackMedium→BloodHound Attack Path Finding - Tier Zero Group Control via MS Graph App RoleMedium→BloodHound Attack Path Finding - Tier Zero Service Principal Control via MS Graph App RoleMedium→BloodHound Attack Path Finding - Tier Zero SMSA Installed on Non-Tier Zero ComputerMedium→BloodHound Attack Path Finding - User Access Admin Role on Tier Zero ResourceMedium→BloodHound Attack Path Finding - VM Admin Login Role on Tier Zero SystemMedium→BloodHound Attack Path Finding - VM Contributor Role on Tier Zero SystemMedium→BloodHound Attack Path Finding - Website Contributor Role on Tier Zero ResourceMedium→BloodHound Attack Path Finding - Write Account Restrictions Privileges on Tier Zero ObjectsMedium→BloodHound Attack Path Finding - WriteDacl Privileges on Tier Zero ObjectsMedium→BloodHound Attack Path Finding - WriteGpLink Privileges on Tier Zero ObjectsMedium→BloodHound Attack Path Finding - WriteOwner Privileges on Tier Zero ObjectsMedium→BloodHound Attack Path Finding - WriteOwnerLimitedRights Privileges on Tier Zero ObjectsMedium→BloodHound Attack Path Finding - WriteServicePrincipalName Privileges on Tier Zero ObjectsMedium→
Source provenance
GitHubDisplayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.
- Commit
9800e51↗- Source identifier
bloodhoundenterprise-mssentinel
GSTEP / CATALOG TRACKING
Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC