Glossary
BloodHound
BloodHound is a graph-based tool that maps Active Directory relationships to reveal attack paths from ordinary users to privileged control.
BloodHound collects data about Active Directory — group memberships, sessions, local admin rights, ACLs, delegation settings, trusts, GPO links and AD CS configuration — with collectors such as SharpHound, and loads it into a graph database. It then computes paths between principals: for example, how a helpdesk user can reach Domain Admins through a chain of group nesting, a writable ACL and an admin session on a server. The open-source Community Edition and the commercial Enterprise edition share this model; the latter adds continuous collection and prioritised findings.
It matters because attackers use the same tool, so defenders should see their graph first. Run it regularly with appropriate authorisation, tag everything that belongs in Tier 0, and focus on choke points — single edges that, once removed, cut many paths at once. Fixing a handful of over-broad ACLs or stale admin rights often eliminates most routes to domain dominance. Treat collected data as sensitive, since it is effectively a map of your weaknesses.
See Attack path management with BloodHound and Auditing Active Directory ACLs.