logo

Updates to the MSSQLHound OpenGraph Collector for BloodHound

ID: d25727e1-d152-5e64-945a-b6ed996d9658

STIX ID: report--d25727e1-d152-5e64-945a-b6ed996d9658

Feed Name: SpecterOps Blog

Threat Score
70/100

Date Published: 2026-01-20

Date Updated: 2026-04-30

Author: Chris Thompson

...
...

This post describes updates to MSSQLHound that add NTLM relay/EPA scanning for MSSQL servers (to detect conditions that enable NTLM relay attacks and SCCM hierarchy takeover), detection for CVE-2025-49758 (an MSSQL ALTER ANY LOGIN elevation of privilege issue), and a set of BloodHound Cypher queries to visualize MSSQL-related attack paths and misconfigurations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.