NOTES
BloodHound is most useful when you need to understand relationships rather than inspect directory objects one at a time. The graph model makes privilege paths, delegated rights, sessions, group membership, and trust relationships easier to reason about.
WORKFLOW
- Define scope before collection and keep collection methods appropriate to the engagement.
- Import only the data you intend to analyze and label owned or controlled principals deliberately.
- Use paths as leads to investigate, not as automatic proof that a finding is exploitable.
- Preserve screenshots, queries, and supporting directory evidence for reporting.
EVIDENCE
A useful BloodHound note should explain why a relationship matters, the preconditions required for abuse, what evidence confirmed it, and the remediation that actually breaks the path.