awesome-repositories.com
博客
MCP
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目MCP 服务器关于排名机制媒体报道
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
SpecterOps avatar

SpecterOps/BloodHound

0
View on GitHub↗
2,789 星标·292 分支·Go·apache-2.0·11 次浏览specterops.io/bloodhound-enterprise↗

BloodHound

BloodHound is an identity risk management platform and graph-based attack path analyzer used to map identity relationships and permissions in Active Directory. It functions as a security tool for auditing directory services, uncovering unintended privilege relationships, and visualizing sequences of permissions that can lead to domain compromise.

The project differentiates itself as a comprehensive adversary emulation framework that coordinates remote agents and executes post-exploitation commands. It includes a reverse proxy for bypassing multi-factor authentication via real-time session hijacking and a system for simulating phishing campaigns to track user interactions.

The platform covers a broad set of offensive security capabilities, including credential harvesting from memory and local stores, Kerberos and PKI manipulation, and infrastructure enumeration targeting system management tools. It also provides tools for remote command execution, lateral movement through authentication coercion, and the discovery of privilege escalation vectors across host configurations.

The system is deployed as a multi-tier container architecture and can be installed and configured via a command-line utility.

Features

  • Active Directory Security - Maps identity relationships and permissions in Active Directory to uncover hidden privilege escalation paths.
  • Graph Relationship Modeling - Models environments as a graph by ingesting data from identity and device management systems to identify attack paths.
  • Attack Path Graphs - Uses graph-based attack path modeling to visualize privilege escalation routes and hidden identity relationships.
  • Privilege Relationship Visualization - Visualizes hidden connections between users and assets across identity and access platforms using graph analysis.
  • Identity Risk Mitigation - Identifies and removes unintended privilege relationships to harden identity structures and block attack vectors.
  • Phishing Campaign Orchestrators - Orchestrates the delivery of simulated phishing emails and tracks target interactions for security auditing.
  • Remote Agent Payload Execution - Executes binary files and assemblies on remote agents to extend their operational capabilities.
  • Active Directory Enumeration - Performs domain reconnaissance and collects identity data to map network relationships in Active Directory.
  • Attack Path Visualizations - Uses graph databases to discover and visualize sequences of permissions that lead to domain compromise.
  • Attack Path Analysis - Visualizes privilege escalation routes and hidden identity relationships using graph-based analysis.
  • Permission Chain Discovery - Identifies sequences of permissions that can be exploited to escalate privileges or move laterally.
  • Identity Management - Audits directory services to uncover unintended privilege relationships and mitigate identity-based risks.
  • Identity Data Collection - Deploys specialized collectors to gather and upload access management data for analysis.
  • Identity Data Ingestion - Imports environment data into a graph database to analyze permissions and relationship mappings.
  • Post-Exploitation Plugins - Runs tasks such as process injection and credential harvesting across multiple operating systems.
  • Red Teaming Frameworks - Tracks assets and assessments to simplify report generation for offensive security engagements.
  • Relationship Pattern Analysis - Analyzes the structural topology of identity relationships to identify suspicious patterns and attack paths.
  • Adversary Emulation Frameworks - Coordinates remote agents and command control to simulate realistic cyber attacks and test security defenses.
  • Active Directory Security Tools - Provides a graph-based tool to map Active Directory permissions and identify security vulnerabilities.
  • Session Hijacking - Captures real-time session tokens via a reverse proxy to bypass multi-factor authentication.
  • MFA Bypass Proxies - Implements a reverse proxy to stream live browser sessions and bypass multi-factor authentication.
  • WMI-Based Command Execution - Executes system queries and commands on a remote Windows machine using management instrumentation.
  • Multi-User Agent Coordination - Coordinates multiple agents and communication profiles in real-time to conduct adversary emulation.
  • Remote Command Execution - Runs scripts or binaries across remote collections and targeted devices to move laterally.
  • Privilege Escalation - Scans for common privilege escalation paths such as insecure services and registry keys.
  • Custom Graph Schema Mapping - Ingests diverse data into a graph schema to visualize non-standard attack paths.
  • External Data Ingestion - Uses configurable extension definitions to ingest diverse external identity data into a structured graph database.
  • Infrastructure Data Imports - Imports access lists and permission data from external providers into a graph database to analyze attack paths.
  • Graph Schema Definition - Creates extension definitions to map custom nodes and edges into a structured graph.
  • OSINT Automation Frameworks - Discovers employees and enriches profiles using AI to generate personalized social engineering pretexts.
  • REST APIs - Provides a programmable REST API to connect external tools and custom workflows to the platform.
  • Phishing Target Directories - Maintains directories of email addresses and metadata to personalize simulated phishing attacks.
  • Credential Memory Dumping - Extracts credentials and sensitive data from active process memory using in-memory loaders.
  • Locked Data Extraction - Implements techniques for extracting files currently locked by the operating system to facilitate data exfiltration.
  • Captured File Enrichment - Processes files automatically to extract credentials and perform advanced data analysis.
  • Certificate Forgeries - Creates arbitrary user certificates using stolen private keys to establish persistent backdoors.
  • Certificate Services Exploitation - Uses misconfigurations in certificate services to achieve persistence and privilege escalation.
  • Configuration Manager Attacks - Profiles and attacks configuration manager environments to move laterally and gather credentials.
  • Credential Extraction - Provides capabilities to retrieve sensitive passwords from SCCM network accounts and task sequences using decryption.
  • Credential Harvesting Simulations - Extracts secrets from memory, local stores, and network protocols to enable lateral movement.
  • Embedded Content Harvesters - Captures authentication attempts and NTLM hashes using pixel images embedded in pages.
  • Host Enumeration - Provides capabilities for discovering and retrieving metadata about target hosts to identify security weaknesses.
  • Credential Extraction Utilities - Retrieves secrets from vaults, browser stores, certificates, and configuration files.
  • Phishing Capturers - Captures interaction data and credentials via deceptive web interfaces to generate audit metrics.
  • In-Memory Payload Execution - Executes specialized assemblies and binary modules directly in process memory to evade disk-based detection.
  • Infrastructure Enumeration - Identifies site servers, management points, and managed devices using LDAP and local configuration.
  • Collaboration Platform Reconnaissance - Enumerates spaces and searches for secrets within collaboration platforms.
  • Automated Kerberos Attacks - Automates the request, extraction, and forgery of Kerberos tickets to manipulate network identity.
  • Kerberos Ticket Cache Manipulators - Modifies Kerberos tickets in the local cache to perform roasting and delegation abuse.
  • Database Key Extractions - Retrieves encryption key material and master keys from KeePass databases and memory.
  • Misconfiguration Scanning - Evaluates environment configurations against security benchmarks to uncover potential attack paths.
  • Active 2FA Bypass Proxies - Uses a reverse proxy to capture real-time session data and hijack cookies to bypass multi-factor authentication.
  • Authentication Coercion - Forces servers or clients to authenticate via NTLM to facilitate credential relay attacks.
  • Infrastructure Auditing - Analyzes certificate services configurations to find vulnerabilities and compliance issues.
  • Module Execution Controllers - Runs assemblies across agents to extend functional capabilities using pre-configured armories.
  • Privilege Escalation Techniques - Scans services and registries for misconfigurations that permit the elevation of system privileges.
  • SCCM Infrastructure Attacks - Gains unauthorized access by exploiting SCCM enrollment abuses and relay attacks.
  • SCCM Infrastructure Manipulation - Modifies applications, collection memberships, and deployments within SCCM infrastructure.
  • Session Token Replays - Allows the injection of captured session data into a local browser to resume authenticated sessions.
  • Social Engineering Frameworks - Impersonates legitimate workflows by creating issues and comments to deliver payloads through social engineering.
  • Captured Session Managers - Extracts cookies, local storage, and keystrokes from authenticated users via a proxied session.
  • Browser Credential Extractions - Retrieves secrets from the Windows Data Protection API, including browser passwords and vaults.
  • Browser Session Token Reuse - Uses hijacked browser cookies to perform actions on behalf of a user.
  • Asynchronous Processing Pipelines - Implements an asynchronous pipeline to extract credentials and metadata from uploaded files in the background.
  • Phishing Session Monitors - Provides live browser thumbnails and keylogging for monitoring active phishing sessions.
  • Email Blueprint Management - Provides tools to create and organize email content used as blueprints for phishing simulation campaigns.
  • Active Directory Penetration - Tool for visualizing and analyzing Active Directory attack paths.
  • Post Exploitation - Tool for visualizing and analyzing Active Directory attack paths.

Star 历史

specterops/bloodhound 的 Star 历史图表specterops/bloodhound 的 Star 历史图表

AI 搜索

探索更多 awesome 仓库

用简单的语言描述您的需求 —— AI 将根据相关性为您从数千个精选开源项目中进行排序。

Start searching with AI

常见问题解答

specterops/bloodhound 是做什么的?

BloodHound is an identity risk management platform and graph-based attack path analyzer used to map identity relationships and permissions in Active Directory. It functions as a security tool for auditing directory services, uncovering unintended privilege relationships, and visualizing sequences of permissions that can lead to domain compromise.

specterops/bloodhound 的主要功能有哪些?

specterops/bloodhound 的主要功能包括:Active Directory Security, Graph Relationship Modeling, Attack Path Graphs, Privilege Relationship Visualization, Identity Risk Mitigation, Phishing Campaign Orchestrators, Remote Agent Payload Execution, Active Directory Enumeration。

specterops/bloodhound 有哪些开源替代品?

specterops/bloodhound 的开源替代品包括: adaptivethreat/bloodhound — Bloodhound is an Active Directory attack path mapper and security auditor designed to visualize trust relationships… mantvydasb/redteaming-tactics-and-techniques — This project is a red teaming knowledge base and offensive security playbook designed to simulate adversary behavior.… jaykali/maskphish — Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network… trustedsec/social-engineer-toolkit — The Social-Engineer Toolkit is a social engineering framework and penetration testing suite designed to simulate… falkordb/falkordb — FalkorDB is a high-performance graph database management system and vector graph database. It serves as a knowledge… bloodhoundad/bloodhound — BloodHound is a graph-based security analysis tool designed to map trust relationships and attack vectors within…

BloodHound 的开源替代方案

相似的开源项目,按与 BloodHound 的功能重合度排序。
  • adaptivethreat/bloodhoundadaptivethreat 的头像

    adaptivethreat/Bloodhound

    10,552在 GitHub 上查看↗

    Bloodhound is an Active Directory attack path mapper and security auditor designed to visualize trust relationships and permission chains. It serves as an attack surface management tool that identifies paths to domain administrator and other high-privileged accounts. The project uses a graph database analyzer to map complex identity and access relationships. It quantifies the risk of privilege escalation by identifying misconfigured permissions and trust links within Windows domains. The system provides capabilities for Active Directory security analysis, identity and access auditing, and ne

    PowerShell
    在 GitHub 上查看↗10,552
  • mantvydasb/redteaming-tactics-and-techniquesmantvydasb 的头像

    mantvydasb/RedTeaming-Tactics-and-Techniques

    4,620在 GitHub 上查看↗

    This project is a red teaming knowledge base and offensive security playbook designed to simulate adversary behavior. It serves as a comprehensive collection of technical guides and tactics for executing red team operations. The repository provides detailed instructions for Active Directory exploitation, including Kerberos abuse and domain privilege escalation. It covers defense evasion through API unhooking and payload obfuscation, as well as Windows internals research involving the manipulation of kernel objects and system memory. The capability surface extends to network penetration testi

    PowerShelloffensive-securityoscppentesting
    在 GitHub 上查看↗4,620
  • jaykali/maskphishjaykali 的头像

    jaykali/maskphish

    3,020在 GitHub 上查看↗

    Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network vulnerability scanning, open-source intelligence, penetration testing, and social engineering. It functions as a multi-purpose framework for automating reconnaissance and executing security audits across diverse network environments. The project features a specialized phishing and social engineering toolkit used for cloning websites, masking URLs, and deploying deceptive pages to capture user credentials. It also includes a remote access Trojan builder for generating platform-specific exe

    Shellhackhackinghacking-tool
    在 GitHub 上查看↗3,020
  • trustedsec/social-engineer-toolkittrustedsec 的头像

    trustedsec/social-engineer-toolkit

    14,984在 GitHub 上查看↗

    The Social-Engineer Toolkit is a social engineering framework and penetration testing suite designed to simulate human-centric security attacks. It serves as a phishing simulation tool and credential harvesting utility to evaluate personnel awareness and organizational resilience. The toolkit provides specialized tooling for phishing campaign testing and credential theft simulation. It enables the creation of deceptive emails and landing pages to identify vulnerabilities in how users handle sensitive account information. The system includes capabilities for security awareness training and br

    Python
    在 GitHub 上查看↗14,984
  • 查看 BloodHound 的所有 30 个替代方案→