logo

Adding MSSQL to BloodHound with OpenGraph

ID: 81e80618-6a4c-527f-a4a7-80efec798e81

STIX ID: report--81e80618-6a4c-527f-a4a7-80efec798e81

Feed Name: SpecterOps Blog

Date Published: 2025-08-04

Date Updated: 2026-04-30

Author: Chris Thompson

...
...

The post introduces MSSQLHound, a PowerShell collector that leverages BloodHound 8.0’s OpenGraph to model MSSQL attack paths by adding new nodes and edges, shifting to a composition model that separates non-traversable permission edges from traversable attack-action edges for clearer pathfinding and remediation. It details collection/processing logic, resource considerations, and unit-testing insights, and demonstrates practical research and operations with Cypher queries—including a default SCCM scenario where TRUSTWORTHY databases and EXECUTE AS OWNER can enable host-level code execution—enabling both offensive discovery and defensive analysis of MSSQL permissions and attack paths.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.