logo

Introducing TailscaleHound: Mapping Tailscale Attack Paths in BloodHound

ID: a2a89889-c1d0-53f4-9ab5-1db7569b1ce1

STIX ID: report--a2a89889-c1d0-53f4-9ab5-1db7569b1ce1

Feed Name: SpecterOps Blog

Date Published: 2026-05-21

Date Updated: 2026-05-22

...
...

**Executive Summary:** TailscaleHound is an OpenGraph collector for BloodHound that maps Tailscale users, devices, groups, tags, ACLs, grants, SSH rules, routes, app connectors, services, keys, invites, webhooks, and hybrid Azure identity relationships into a graph to help answer access and attack-path questions; the article details setup (OAuth/tailcontrol), remote and local collection modes, example queries for device/route/SSH/exit-node analysis, and how red and blue teams can use the output to identify or reduce risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.