logo

BloodHound versus Ransomware: A Defender’s Guide

ID: c48fac33-8c33-5c9e-b057-73beec7f1b44

STIX ID: report--c48fac33-8c33-5c9e-b057-73beec7f1b44

Feed Name: SpecterOps Blog

Date Published: 2021-06-08

Date Updated: 2026-04-30

Author: Andy Robbins

...
...

This blog post provides defensive guidance for using the free/open-source BloodHound and SharpHound to discover, assess, and reduce Active Directory attack paths frequently exploited by ransomware operators. It explains how to gauge environment exposure with targeted pathfinding, then details three proactive audits: reviewing object control over Tier 0 principals, analyzing privileged user interactive logons and sessions, and auditing local administrator rights and permissions on sensitive systems (e.g., domain controllers), enabling defenders to identify and remediate risky group nestings, excessive permissions, and unsafe administrative behaviors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.