LiveActive security incident?Get immediate response
MITRE ATT&CK® Tool

S0521: BloodHound

BloodHound is an Active Directory (AD) reconnaissance tool that can reveal hidden relationships and identify attack paths within an AD environment.[1][2][3]

EnterpriseS0521ToolObject v1.7Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

BloodHound matters because it turns Active Directory relationships into a map of potential privilege and lateral-movement paths. For leaders, the business issue is not the tool name itself; it is whether hidden AD trust, group, account, and policy relationships could let an intruder quickly identify routes to high-value access during an incident.

Executive priority

Prioritize this as an identity and resilience question: can the organization prove that privileged access paths in Windows/AD are understood, monitored, and reduced? ATT&CK links BloodHound to multiple groups and one campaign, which makes it a useful control-validation scenario for SOC readiness, incident response playbooks, AD hardening, audit evidence, and ransomware/espionage preparedness without assuming current exposure.

Technical view

BloodHound is documented as a Windows Active Directory reconnaissance tool. ATT&CK relationships associate it with discovery of remote systems, users, local and domain groups, local and domain accounts, domain trusts, Group Policy, plus execution via PowerShell and Native API, and archiving collected data. SOC and IR teams should validate whether they can detect abnormal AD enumeration patterns, PowerShell-based collection activity, unusual access to domain policy or trust information, and creation of compressed collections after directory discovery.

Likely telemetry

  • Windows endpoint process creation with command line and parent process context
  • PowerShell execution and script block/module logging where enabled
  • Domain controller authentication and directory service query/audit events
  • Account, group, domain trust, and Group Policy access/change telemetry
  • Network connections from workstations or servers to domain controllers and SYSVOL paths

Detection direction

  • Do not rely on a BloodHound binary name alone; validate behavior-based coverage for AD account, group, trust, GPO, and remote system discovery.
  • Baseline legitimate administrative enumeration so detection logic can distinguish approved identity engineering or audit activity from unusual user, host, timing, or volume patterns.
  • Correlate PowerShell execution with bursts of domain discovery and subsequent archive creation rather than treating each event in isolation.
  • Review visibility from both endpoints and domain controllers; endpoint-only monitoring can miss directory-query context, while DC-only monitoring may miss collection tooling and archives.
  • Use the ATT&CK relationships to build test cases across Discovery, Execution, and Collection behaviors, since the official object does not provide a detection analytic.

Mitigation priorities

  • Reduce unnecessary privileged group membership and hidden administrative paths in Active Directory.
  • Review domain trusts, Group Policy permissions, and account delegation paths that could create unintended privilege routes.
  • Restrict and monitor administrative scripting, especially PowerShell, according to business need.
  • Ensure AD auditing, endpoint logging, and retention are sufficient for incident reconstruction.
  • Include AD attack-path review in identity governance, compliance evidence, and incident response exercises.
Additional notes and limits

The key defensive value is using BloodHound as a lens for AD attack-path exposure. ATT&CK records use of this tool by Operation Wocao and groups including APT29, TA505, Wizard Spider, Chimera, Ember Bear, and Play, but that relationship should inform prioritization and test planning rather than imply activity in a specific environment.

MITRE provides no official detection text for this object, and the supplied platform is Windows while several related techniques have broader platform coverage. Local logging configuration, AD architecture, administrative tooling, and approved assessment activity are required to determine actual detection coverage and risk.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

BloodHound

BloodHound is an Active Directory (AD) reconnaissance tool that can reveal hidden relationships and identify attack paths within an AD environment.[1][2][3]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

11 rows
DomainIDNameRelationship / procedure
EnterpriseT1069.002Domain GroupsSub-technique

BloodHound can collect information about domain groups and members.[2]

EnterpriseT1615Group Policy Discovery

BloodHound has the ability to collect local admin information via GPO.[1]

EnterpriseT1560Archive Collected Data

BloodHound can compress data collected by its SharpHound ingestor into a ZIP file to be written to disk.[1][4]

EnterpriseT1069.001Local GroupsSub-technique

BloodHound can collect information about local groups and members.[2]

EnterpriseT1087.002Domain AccountSub-technique

BloodHound can collect information about domain users, including identification of domain admin accounts.[2]

EnterpriseT1087.001Local AccountSub-technique

BloodHound can identify users with local administrator rights.[2]

EnterpriseT1033System Owner/User Discovery

BloodHound can collect information on user sessions.[2]

EnterpriseT1018Remote System Discovery

BloodHound can enumerate and collect the properties of domain computers, including domain controllers.[2]

EnterpriseT1106Native API

BloodHound can use .NET API calls in the SharpHound ingestor component to pull Active Directory data.[1]

EnterpriseT1059.001PowerShellSub-technique

BloodHound can use PowerShell to pull Active Directory information from the target environment.[2]

EnterpriseT1482Domain Trust Discovery

BloodHound has the ability to map domain trusts and identify misconfigurations for potential abuse.[2]

Associated objects

Groups, software, and campaigns

GroupEnterprise

G0102: Wizard Spider

Wizard Spider is a Russia-based financially motivated threat group originally known for the creation and deployment of TrickBot since at least 2016. Wizard Spider possesses a diverse arsenal of tools and has conducted ransomware campaigns against a variety of organizations, ranging from major corporations to hospitals.[1][2][3]

GroupEnterprise

G0016: APT29

APT29 is threat group that has been attributed to Russia's Foreign Intelligence Service (SVR).[1][2] They have operated since at least 2008, often targeting government networks in Europe and NATO member countries, research institutes, and think tanks. APT29 reportedly compromised the Democratic National Committee starting in the summer of 2015.[3][4][5][6]

In April 2021, the US and UK governments attributed the SolarWinds Compromise to the SVR; public statements included citations to APT29, Cozy Bear, and The Dukes.[7][8] Industry reporting also referred to the actors involved in this campaign as UNC2452, NOBELIUM, StellarParticle, Dark Halo, and SolarStorm.[9][10][11][12][13][14]

GroupEnterprise

G0114: Chimera

Chimera is a suspected China-based threat group that has been active since at least 2018 targeting the semiconductor industry in Taiwan as well as data from the airline industry.[1][2]

GroupEnterprise

G0092: TA505

TA505 is a cyber criminal group that has been active since at least 2014. TA505 is known for frequently changing malware, driving global trends in criminal malware distribution, and ransomware campaigns involving Clop.[1][2][3][4][5]

GroupEnterprise

G1040: Play

Play is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a double-extortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.[1][2]

GroupEnterprise

G1003: Ember Bear

Ember Bear is a Russian state-sponsored cyber espionage group that has been active since at least 2020, linked to Russia's General Staff Main Intelligence Directorate (GRU) 161st Specialist Training Center (Unit 29155).[1] Ember Bear has primarily focused operations against Ukrainian government and telecommunication entities, but has also operated against critical infrastructure entities in Europe and the Americas.[2] Ember Bear conducted the WhisperGate destructive wiper attacks against Ukraine in early 2022.[3][4][1] There is some confusion as to whether Ember Bear overlaps with another Russian-linked entity referred to as Saint Bear. At present available evidence strongly suggests these are distinct activities with different behavioral profiles.[2][5]

CampaignEnterprise

C0014: Operation Wocao

Operation Wocao was a cyber espionage campaign that targeted organizations around the world, including in Brazil, China, France, Germany, Italy, Mexico, Portugal, Spain, the United Kingdom, and the United States. The suspected China-based actors compromised government organizations and managed service providers, as well as aviation, construction, energy, finance, health care, insurance, offshore engineering, software development, and transportation companies.[1]

Security researchers assessed the Operation Wocao actors used similar TTPs and tools as APT20, suggesting a possible overlap. Operation Wocao was named after an observed command line entry by one of the threat actors, possibly out of frustration from losing webshell access.[1]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.7
Created
Modified
Raw hash
3520d0be31f1d3a3...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.7Current bundle3520d0be31f1…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    GitHub Bloodhound

    Robbins, A., Vazarkar, R., and Schroeder, W. (2016, April 17). Bloodhound: Six Degrees of Domain Admin. Retrieved March 5, 2019.

    Open source URL
  2. [2]
    CrowdStrike BloodHound April 2018

    Red Team Labs. (2018, April 24). Hidden Administrative Accounts: BloodHound to the Rescue. Retrieved October 28, 2020.

    Open source URL
  3. [3]
    FoxIT Wocao December 2019

    Dantzig, M. v., Schamper, E. (2019, December 19). Operation Wocao: Shining a light on one of China’s hidden hacking groups. Retrieved October 8, 2020.

    Open source URL
  4. [4]
    Trend Micro Black Basta October 2022

    Kenefick, I. et al. (2022, October 12). Black Basta Ransomware Gang Infiltrates Networks via QAKBOT, Brute Ratel, and Cobalt Strike. Retrieved February 6, 2023.

    Open source URL
  5. [5]
    DHS/CISA Ransomware Targeting Healthcare October 2020

    DHS/CISA. (2020, October 28). Ransomware Activity Targeting the Healthcare and Public Health Sector. Retrieved October 28, 2020.

    Open source URL
  6. [6]
    FireEye KEGTAP SINGLEMALT October 2020

    Kimberly Goody, Jeremy Kennelly, Joshua Shilko, Steve Elovitz, Douglas Bienstock. (2020, October 28). Unhappy Hour Special: KEGTAP and SINGLEMALT With a Ransomware Chaser. Retrieved October 28, 2020.

    Open source URL
  7. [7]
    Sophos New Ryuk Attack October 2020

    Sean Gallagher, Peter Mackenzie, Elida Leite, Syed Shahram, Bill Kearney, Anand Aijan, Sivagnanam Gn, Suraj Mundalik. (2020, October 14). They’re back: inside a new Ryuk ransomware attack. Retrieved October 14, 2020.

    Open source URL
  8. [8]
    Mandiant FIN12 Oct 2021

    Shilko, J., et al. (2021, October 7). FIN12: The Prolific Ransomware Intrusion Threat Actor That Has Aggressively Pursued Healthcare Targets. Retrieved June 15, 2023.

    Open source URL
  9. [9]
    ESET T3 Threat Report 2021

    ESET. (2022, February). THREAT REPORT T3 2021. Retrieved February 10, 2022.

    Open source URL
  10. [10]
    Cycraft Chimera April 2020

    Cycraft. (2020, April 15). APT Group Chimera - APT Operation Skeleton key Targets Taiwan Semiconductor Vendors. Retrieved August 24, 2020..

    Open source URL
  11. [11]
    NCC Group TA505

    Terefos, A. (2020, November 18). TA505: A Brief History of Their Time. Retrieved July 14, 2022.

    Open source URL
  12. [12]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  13. [13]
    CISA GRU29155 2024

    US Cybersecurity & Infrastructure Security Agency et al. (2024, September 5). Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure. Retrieved September 6, 2024.

    Open source URL
  14. [14]
    CrowdStrike BloodHound April 2018

    Red Team Labs. (2018, April 24). Hidden Administrative Accounts: BloodHound to the Rescue. Retrieved October 28, 2020.

    Open source URL
  15. [15]
    CrowdStrike BloodHound April 2018

    Red Team Labs. (2018, April 24). Hidden Administrative Accounts: BloodHound to the Rescue. Retrieved October 28, 2020.

    Open source URL
  16. [16]
    FoxIT Wocao December 2019

    Dantzig, M. v., Schamper, E. (2019, December 19). Operation Wocao: Shining a light on one of China’s hidden hacking groups. Retrieved October 8, 2020.

    Open source URL
  17. [17]
    FoxIT Wocao December 2019

    Dantzig, M. v., Schamper, E. (2019, December 19). Operation Wocao: Shining a light on one of China’s hidden hacking groups. Retrieved October 8, 2020.

    Open source URL
  18. [18]
    GitHub Bloodhound

    Robbins, A., Vazarkar, R., and Schroeder, W. (2016, April 17). Bloodhound: Six Degrees of Domain Admin. Retrieved March 5, 2019.

    Open source URL
  19. [19]
    GitHub Bloodhound

    Robbins, A., Vazarkar, R., and Schroeder, W. (2016, April 17). Bloodhound: Six Degrees of Domain Admin. Retrieved March 5, 2019.

    Open source URL
  20. [20]
    mitre-attackS0521
    Open source URL
  21. [21]
    mitre-attackS0521
    Open source URL
  22. [22]
    mitre-attackS0521
    Open source URL
  23. [23]
    FoxIT Wocao December 2019

    Dantzig, M. v., Schamper, E. (2019, December 19). Operation Wocao: Shining a light on one of China’s hidden hacking groups. Retrieved October 8, 2020.

    Open source URL
  24. [24]
    FoxIT Wocao December 2019

    Dantzig, M. v., Schamper, E. (2019, December 19). Operation Wocao: Shining a light on one of China’s hidden hacking groups. Retrieved October 8, 2020.

    Open source URL
  25. [25]
    CrowdStrike BloodHound April 2018

    Red Team Labs. (2018, April 24). Hidden Administrative Accounts: BloodHound to the Rescue. Retrieved October 28, 2020.

    Open source URL
  26. [26]
    CrowdStrike BloodHound April 2018

    Red Team Labs. (2018, April 24). Hidden Administrative Accounts: BloodHound to the Rescue. Retrieved October 28, 2020.

    Open source URL
  27. [27]
    GitHub Bloodhound

    Robbins, A., Vazarkar, R., and Schroeder, W. (2016, April 17). Bloodhound: Six Degrees of Domain Admin. Retrieved March 5, 2019.

    Open source URL
  28. [28]
    GitHub Bloodhound

    Robbins, A., Vazarkar, R., and Schroeder, W. (2016, April 17). Bloodhound: Six Degrees of Domain Admin. Retrieved March 5, 2019.

    Open source URL
  29. [29]
    GitHub Bloodhound

    Robbins, A., Vazarkar, R., and Schroeder, W. (2016, April 17). Bloodhound: Six Degrees of Domain Admin. Retrieved March 5, 2019.

    Open source URL
  30. [30]
    GitHub Bloodhound

    Robbins, A., Vazarkar, R., and Schroeder, W. (2016, April 17). Bloodhound: Six Degrees of Domain Admin. Retrieved March 5, 2019.

    Open source URL
  31. [31]
    Trend Micro Black Basta October 2022

    Kenefick, I. et al. (2022, October 12). Black Basta Ransomware Gang Infiltrates Networks via QAKBOT, Brute Ratel, and Cobalt Strike. Retrieved February 6, 2023.

    Open source URL
  32. [32]
    DHS/CISA Ransomware Targeting Healthcare October 2020

    DHS/CISA. (2020, October 28). Ransomware Activity Targeting the Healthcare and Public Health Sector. Retrieved October 28, 2020.

    Open source URL
  33. [33]
    FireEye KEGTAP SINGLEMALT October 2020

    Kimberly Goody, Jeremy Kennelly, Joshua Shilko, Steve Elovitz, Douglas Bienstock. (2020, October 28). Unhappy Hour Special: KEGTAP and SINGLEMALT With a Ransomware Chaser. Retrieved October 28, 2020.

    Open source URL
  34. [34]
    Mandiant FIN12 Oct 2021

    Shilko, J., et al. (2021, October 7). FIN12: The Prolific Ransomware Intrusion Threat Actor That Has Aggressively Pursued Healthcare Targets. Retrieved June 15, 2023.

    Open source URL
  35. [35]
    Sophos New Ryuk Attack October 2020

    Sean Gallagher, Peter Mackenzie, Elida Leite, Syed Shahram, Bill Kearney, Anand Aijan, Sivagnanam Gn, Suraj Mundalik. (2020, October 14). They’re back: inside a new Ryuk ransomware attack. Retrieved October 14, 2020.

    Open source URL
  36. [36]
    ESET T3 Threat Report 2021

    ESET. (2022, February). THREAT REPORT T3 2021. Retrieved February 10, 2022.

    Open source URL
  37. [37]
    CrowdStrike BloodHound April 2018

    Red Team Labs. (2018, April 24). Hidden Administrative Accounts: BloodHound to the Rescue. Retrieved October 28, 2020.

    Open source URL
  38. [38]
    CrowdStrike BloodHound April 2018

    Red Team Labs. (2018, April 24). Hidden Administrative Accounts: BloodHound to the Rescue. Retrieved October 28, 2020.

    Open source URL
  39. [39]
    CrowdStrike BloodHound April 2018

    Red Team Labs. (2018, April 24). Hidden Administrative Accounts: BloodHound to the Rescue. Retrieved October 28, 2020.

    Open source URL
  40. [40]
    CrowdStrike BloodHound April 2018

    Red Team Labs. (2018, April 24). Hidden Administrative Accounts: BloodHound to the Rescue. Retrieved October 28, 2020.

    Open source URL
  41. [41]
    Cycraft Chimera April 2020

    Cycraft. (2020, April 15). APT Group Chimera - APT Operation Skeleton key Targets Taiwan Semiconductor Vendors. Retrieved August 24, 2020..

    Open source URL
  42. [42]
    CrowdStrike BloodHound April 2018

    Red Team Labs. (2018, April 24). Hidden Administrative Accounts: BloodHound to the Rescue. Retrieved October 28, 2020.

    Open source URL
  43. [43]
    CrowdStrike BloodHound April 2018

    Red Team Labs. (2018, April 24). Hidden Administrative Accounts: BloodHound to the Rescue. Retrieved October 28, 2020.

    Open source URL
  44. [44]
    CrowdStrike BloodHound April 2018

    Red Team Labs. (2018, April 24). Hidden Administrative Accounts: BloodHound to the Rescue. Retrieved October 28, 2020.

    Open source URL
  45. [45]
    CrowdStrike BloodHound April 2018

    Red Team Labs. (2018, April 24). Hidden Administrative Accounts: BloodHound to the Rescue. Retrieved October 28, 2020.

    Open source URL
  46. [46]
    NCC Group TA505

    Terefos, A. (2020, November 18). TA505: A Brief History of Their Time. Retrieved July 14, 2022.

    Open source URL
  47. [47]
    CrowdStrike BloodHound April 2018

    Red Team Labs. (2018, April 24). Hidden Administrative Accounts: BloodHound to the Rescue. Retrieved October 28, 2020.

    Open source URL
  48. [48]
    CrowdStrike BloodHound April 2018

    Red Team Labs. (2018, April 24). Hidden Administrative Accounts: BloodHound to the Rescue. Retrieved October 28, 2020.

    Open source URL
  49. [49]
    GitHub Bloodhound

    Robbins, A., Vazarkar, R., and Schroeder, W. (2016, April 17). Bloodhound: Six Degrees of Domain Admin. Retrieved March 5, 2019.

    Open source URL
  50. [50]
    GitHub Bloodhound

    Robbins, A., Vazarkar, R., and Schroeder, W. (2016, April 17). Bloodhound: Six Degrees of Domain Admin. Retrieved March 5, 2019.

    Open source URL
  51. [51]
    CrowdStrike BloodHound April 2018

    Red Team Labs. (2018, April 24). Hidden Administrative Accounts: BloodHound to the Rescue. Retrieved October 28, 2020.

    Open source URL
  52. [52]
    CrowdStrike BloodHound April 2018

    Red Team Labs. (2018, April 24). Hidden Administrative Accounts: BloodHound to the Rescue. Retrieved October 28, 2020.

    Open source URL
  53. [53]
    CrowdStrike BloodHound April 2018

    Red Team Labs. (2018, April 24). Hidden Administrative Accounts: BloodHound to the Rescue. Retrieved October 28, 2020.

    Open source URL
  54. [54]
    CrowdStrike BloodHound April 2018

    Red Team Labs. (2018, April 24). Hidden Administrative Accounts: BloodHound to the Rescue. Retrieved October 28, 2020.

    Open source URL
  55. [55]
    Trend Micro Ransomware Spotlight Play July 2023

    Trend Micro Research. (2023, July 21). Ransomware Spotlight: Play. Retrieved September 24, 2024.

    Open source URL
  56. [56]
    CISA GRU29155 2024

    US Cybersecurity & Infrastructure Security Agency et al. (2024, September 5). Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure. Retrieved September 6, 2024.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.