logo

Mapping Deception with BloodHound OpenGraph

ID: 41fd585f-9ca1-53c4-a5f7-8319b94b82b6

STIX ID: report--41fd585f-9ca1-53c4-a5f7-8319b94b82b6

Feed Name: SpecterOps Blog

Date Published: 2025-12-23

Date Updated: 2026-04-30

Author: Ben Schroeder

...
...

This article presents a defender-focused methodology for building believable cyber deception by mapping attack paths with OpenGraph/BloodHound and augmenting them with decoys (e.g., canary accounts, honey credentials) using tools such as F4keH0und, GitHound, AnsibleHound, and deceptionClone; it applies Clean Source Principle reasoning, demonstrates placements in Active Directory (including shadow credentials and Certiception), GitHub artifacts, and Ansible Tower, and shows how to merge graphs across technologies to improve discoverability, context, and high-fidelity alerting while carefully managing operational risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.