Updates to the MSSQLHound OpenGraph Collector for BloodHound
ID: d25727e1-d152-5e64-945a-b6ed996d9658
STIX ID: report--d25727e1-d152-5e64-945a-b6ed996d9658
Feed Name: SpecterOps Blog
Threat Score
This post describes updates to MSSQLHound that add NTLM relay/EPA scanning for MSSQL servers (to detect conditions that enable NTLM relay attacks and SCCM hierarchy takeover), detection for CVE-2025-49758 (an MSSQL ALTER ANY LOGIN elevation of privilege issue), and a set of BloodHound Cypher queries to visualize MSSQL-related attack paths and misconfigurations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
