1200KM / tool
BloodHound — Attack Tool
BloodHound is an Active Directory (AD) reconnaissance tool that can reveal hidden relationships and identify attack paths within an AD environment.
Tool identity and evidence
Included because the active pinned ATT&CK object has type tool. This is an upstream classification, not an assurance of benignness or a recommendation to run it.
Aliases: BloodHound
Existing author guides
No reviewed association in this snapshot.
Primary documentation
Connected ecosystem references
Linked tags
Documented actor use
Explicit actor-to-software uses relationships in the pinned ATT&CK source. These links are historical behavior context, not attribution of current events.
- APT29 · G0016 · Pinned relationship source (relationship--41760330-2558-4781-bc4e-1e4c7a1f5f92)
- TA505 · G0092 · Pinned relationship source (relationship--77d30a4e-d267-4416-85f2-edebc0a6af29)
- Wizard Spider · G0102 · Pinned relationship source (relationship--3b3c27ed-0129-48bf-8c79-e86d73e5b212)
- Chimera · G0114 · Pinned relationship source (relationship--5db02c00-0d28-4831-bad9-66737bb62eca)
- Ember Bear · G1003 · Pinned relationship source (relationship--d9ed5461-b123-4cb8-88e7-b24675858747)
- Play · G1040 · Pinned relationship source (relationship--c46ab316-6976-41ab-87ea-97f9d435b6cc)
Technique-specific simulations and detections
Detection links describe the associated behavior, not independently verified tool-specific signatures.
- T1018 · Remote System Discovery · Detection rules & anomalies
- T1033 · System Owner/User Discovery · Detection rules & anomalies
- T1059.001 · PowerShell · Detection rules & anomalies
- T1069.001 · Local Groups · Detection rules & anomalies
- T1069.002 · Domain Groups · Detection rules & anomalies
- T1087.001 · Local Account · Detection rules & anomalies
- T1087.002 · Domain Account · Detection rules & anomalies
- T1106 · Native API · Detection rules & anomalies
- T1482 · Domain Trust Discovery · Detection rules & anomalies
- T1560 · Archive Collected Data · Detection rules & anomalies
- T1615 · Group Policy Discovery · Detection rules & anomalies
Telemetry context
Derived from the explicitly linked TTPs; not proof of sensor coverage for this tool.
- Active Directory Object Access · DC0071
- Command Execution · DC0064
- File Access · DC0055
- File Creation · DC0039
- Module Load · DC0016
- Network Connection Creation · DC0082
- Network Traffic Content · DC0085
- OS API Execution · DC0021
- Process Access · DC0035
- Process Creation · DC0032
- Process Metadata · DC0034
- User Account Metadata · DC0013
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.