BloodHound MCP, One Year Later: What I Learned About MCPs, Models, and Context
ID: 931bb4c2-8509-5acb-9321-4f73f192209b
STIX ID: report--931bb4c2-8509-5acb-9321-4f73f192209b
Feed Name: SpecterOps Blog
TL;DR: The author describes rearchitecting the BloodHound MCP from a large, per-endpoint tool catalog to a smaller set of composite tools and domain resources to reduce token overhead, improve tool-selection reliability, and provide recoverable errors. Key changes include consolidating many endpoint-specific tools into composite tools (e.g., user_info with an info_type parameter), shared dispatcher-based error handling, offloading detailed Cypher and AD guidance into on-demand resources, file upload support for controlled agent-driven ingestion, and better prompt/resource design; these changes cut fixed-context token usage substantially and improve practical analyst workflows.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
