logo

BloodHound MCP, One Year Later: What I Learned About MCPs, Models, and Context

ID: 931bb4c2-8509-5acb-9321-4f73f192209b

STIX ID: report--931bb4c2-8509-5acb-9321-4f73f192209b

Feed Name: SpecterOps Blog

Date Published: 2026-06-18

Date Updated: 2026-07-16

...
...

TL;DR: The author describes rearchitecting the BloodHound MCP from a large, per-endpoint tool catalog to a smaller set of composite tools and domain resources to reduce token overhead, improve tool-selection reliability, and provide recoverable errors. Key changes include consolidating many endpoint-specific tools into composite tools (e.g., user_info with an info_type parameter), shared dispatcher-based error handling, offloading detailed Cypher and AD guidance into on-demand resources, file upload support for controlled agent-driven ingestion, and better prompt/resource design; these changes cut fixed-context token usage substantially and improve practical analyst workflows.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.