awesome-repositories.com
博客
MCP
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目MCP 服务器关于排名机制媒体报道
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
BloodHoundAD avatar

BloodHoundAD/BloodHound

0
View on GitHub↗
10,552 星标·1,795 分支·PowerShell·GPL-3.0·11 次浏览

BloodHound

BloodHound is a graph-based security analysis tool designed to map trust relationships and attack vectors within Active Directory environments. It functions as an attack path mapper and risk assessment system that uses graph theory to identify hidden relationships and paths leading to high-privilege accounts.

The tool specializes in network attack surface mapping and privilege escalation pathfinding. It quantifies security risks by measuring the reliability of attack paths to critical targets, allowing for the prioritization of vulnerability elimination.

The system provides capabilities for directed graph visualization and permission-based path analysis. It utilizes query-driven data extraction to pull permission sets and group memberships, storing them in a schema-mapped format to calculate the shortest routes to high-value targets.

Features

  • Active Directory Security Tools - Provides specialized utilities for identifying and mapping security vulnerabilities within Active Directory environments.
  • Attack Path Mappers - Visualizes the chains of trust and permissions leading to high-privileged accounts in Active Directory.
  • Heuristic Permission Analysis - Analyzes nested group memberships and delegated rights to identify privilege escalation vectors.
  • Attack Path Graphs - Models Active Directory objects and permissions as directed graphs to uncover hidden attack paths.
  • Attack Path Visualizations - Uses graph-based representations to visualize potential lateral movement routes and security vulnerabilities.
  • Privilege Escalation Analysis - Identifies the sequence of compromised accounts and permissions needed to reach domain administrator privileges.
  • Security Analysis Tools - Employs graph theory and automated inspection to identify hidden relationships and high-privilege paths.
  • Data Access and Querying - Uses LDAP and RPC queries to extract permission sets and group memberships from domain controllers.
  • Relationship Graph Visualizers - Provides a visual representation of trust relationships and access rights as directed node graphs.
  • Attack Path Risk Assessments - Quantifies security risks by measuring the reliability of attack paths to critical targets.
  • Vulnerability Prioritization - Measures the reliability of attack paths to prioritize the elimination of critical security vulnerabilities.
  • Active Directory Auditing - Visualizes attack paths in Active Directory environments.
  • Active Directory Exploitation - Graph-based tool for visualizing and analyzing AD attack paths.
  • Active Directory Tools - Graph-based tool for visualizing Active Directory attack paths.
  • Domain Exploitation - Graph-based analysis tool for Active Directory attack paths.
  • Domain Situational Awareness - Visualizes attack paths and domain admin relationships.
  • 安全与隐私 - Identifies complex attack paths in environments.
  • Security Auditing Tools - Analyzes and visualizes attack paths within Active Directory environments.
  • Security Tooling - Graph-based analysis of Active Directory attack paths.

Star 历史

bloodhoundad/bloodhound 的 Star 历史图表bloodhoundad/bloodhound 的 Star 历史图表

AI 搜索

探索更多 awesome 仓库

用简单的语言描述您的需求 —— AI 将根据相关性为您从数千个精选开源项目中进行排序。

Start searching with AI

BloodHound 的开源替代方案

相似的开源项目,按与 BloodHound 的功能重合度排序。
  • adaptivethreat/bloodhoundadaptivethreat 的头像

    adaptivethreat/Bloodhound

    10,552在 GitHub 上查看↗

    Bloodhound is an Active Directory attack path mapper and security auditor designed to visualize trust relationships and permission chains. It serves as an attack surface management tool that identifies paths to domain administrator and other high-privileged accounts. The project uses a graph database analyzer to map complex identity and access relationships. It quantifies the risk of privilege escalation by identifying misconfigured permissions and trust links within Windows domains. The system provides capabilities for Active Directory security analysis, identity and access auditing, and ne

    PowerShell
    在 GitHub 上查看↗10,552
  • byt3bl33d3r/crackmapexecbyt3bl33d3r 的头像

    byt3bl33d3r/CrackMapExec

    9,144在 GitHub 上查看↗

    CrackMapExec is a network penetration testing framework and automated security scanner designed to assess security postures across large IP ranges. It functions as a multi-protocol security scanner and network protocol auditor used to identify vulnerabilities and misconfigurations. The tool provides capabilities for Active Directory auditing to enumerate users and permissions, as well as post-exploitation enumeration to gather system metadata and discover lateral movement paths. It includes a framework for credential spraying and harvesting across various network services. The system utilize

    Python
    在 GitHub 上查看↗9,144
  • powershellmafia/powersploitPowerShellMafia 的头像

    PowerShellMafia/PowerSploit

    12,880在 GitHub 上查看↗

    PowerSploit is a collection of PowerShell modules designed for security assessment, penetration testing, and red team operations. It provides a framework for auditing Windows system configurations and evaluating the effectiveness of security defenses within an enterprise environment. The framework focuses on techniques that leverage native system administration tools and scripting environments to perform operations. It includes capabilities for executing arbitrary commands, escalating user privileges, and maintaining system persistence through event subscriptions. By utilizing in-memory execu

    PowerShell
    在 GitHub 上查看↗12,880
  • gentilkiwi/mimikatzgentilkiwi 的头像

    gentilkiwi/mimikatz

    21,630在 GitHub 上查看↗

    Mimikatz is a security research suite designed for auditing Windows authentication and managing system security configurations. It provides a comprehensive framework for extracting sensitive credentials, manipulating process privileges, and managing digital identity assets directly from system memory or offline memory dumps. The project distinguishes itself through advanced system-level exploitation techniques, including runtime process injection, API hooking, and the ability to bypass cryptographic export restrictions. It features a specialized toolkit for Kerberos protocol operations, allow

    C
    在 GitHub 上查看↗21,630
查看 BloodHound 的所有 30 个替代方案→

常见问题解答

bloodhoundad/bloodhound 是做什么的?

BloodHound is a graph-based security analysis tool designed to map trust relationships and attack vectors within Active Directory environments. It functions as an attack path mapper and risk assessment system that uses graph theory to identify hidden relationships and paths leading to high-privilege accounts.

bloodhoundad/bloodhound 的主要功能有哪些?

bloodhoundad/bloodhound 的主要功能包括:Active Directory Security Tools, Attack Path Mappers, Heuristic Permission Analysis, Attack Path Graphs, Attack Path Visualizations, Privilege Escalation Analysis, Security Analysis Tools, Data Access and Querying。

bloodhoundad/bloodhound 有哪些开源替代品?

bloodhoundad/bloodhound 的开源替代品包括: adaptivethreat/bloodhound — Bloodhound is an Active Directory attack path mapper and security auditor designed to visualize trust relationships… byt3bl33d3r/crackmapexec — CrackMapExec is a network penetration testing framework and automated security scanner designed to assess security… powershellmafia/powersploit — PowerSploit is a collection of PowerShell modules designed for security assessment, penetration testing, and red team… ghostpack/pspkiaudit — PowerShell toolkit for auditing Active Directory Certificate Services (AD CS). gentilkiwi/mimikatz — Mimikatz is a security research suite designed for auditing Windows authentication and managing system security… ghostpack/certify — Certify is a C# tool to enumerate and abuse misconfigurations in Active Directory Certificate Services (AD CS).