Skip to main content

BloodHound API

BloodHound Enterprise includes a REST API that allows you to programmatically interact with your BloodHound data and automate various tasks.

BloodHound JSON Formats

Work With the BloodHound API

BloodHound Python SDK

BloodHound Integrations

SpecterOps is built on community. Our strategic integrations enable BloodHound Enterprise customers to extend identity to proactively secure and manage their Active Directory, Entra ID, and hybrid environments and respond faster to threats. The sections below describe officially supported integrations, third-party integrations, and community-developed integrations.

Supported integrations

The following integrations are officially supported by SpecterOps.

Axonius

The Axonius integration enables Axonius users to fetch and catalog users and devices from BloodHound Enterprise, providing visibility into identity relationships and potential Attack Paths.

CrowdStrike Falcon for IT

The BloodHound Enterprise CrowdStrike Falcon Foundry Application is a native, serverless integration that automatically collects Sessions, Local Groups, User Rights Assignment (LSA), and Registry Keys data from CrowdStrike Falcon agents installed on endpoint hosts.The app then ingests that data into BloodHound Enterprise (BHE). This integration enables security teams to enrich their Active Directory and Azure Attack Path analysis with real-time endpoint telemetry gathered directly from their existing CrowdStrike Falcon deployment.

Palo Alto XSOAR

The BloodHound Enterprise integration for Cortex XSOAR lets you ingest and manage BloodHound Enterprise Attack Path findings in Cortex XSOAR as incidents.

Google SecOps

The BloodHound Enterprise Google Security Operations (SecOps) is an integration that automatically syncs Bloodhound Enterprise (BHE) Attack Path findings to SecOps cases for remediation tracking. This integration enables security teams to manage and track the remediation of Active Directory and Azure Attack Paths directly within their existing SecOps workflows.

Splunk SIEM

The BHE Splunk SIEM App enables customers to ingest Path, Posture, and Impacted Principals data into Splunk. The app also includes pre-built dashboards and alerts for Exposure, Path Details, and Impacted Principals.

Splunk SOAR

The BloodHound Enterprise Splunk SOAR integration includes the ability to pull findings into a SplunkSOAR environment, as well as to enrich alerts from other platforms via data from BloodHound Enterprise.

ServiceNow (SIR)

The BloodHound Enterprise ServiceNow integration provides the ability to generate tickets to track and monitor vulnerabilities within environments, as identified by BloodHound Enterprise.

ServiceNow (VR)

The Vulnerability Response (VR) integration for BloodHound Enterprise enables organizations to seamlessly connect their BloodHound Enterprise tenant with ServiceNow’s Vulnerability Response capabilities, providing automated vulnerable item creation and management based on Attack Path findings.

Third-party integrations

The following integrations are developed by third-party vendors and are not officially supported by SpecterOps.

Cisco Duo

Add two-factor authentication and flexible security policies to BloodHound Enterprise SAML 2.0 logins with Duo Single Sign-On. Our cloud-hosted SSO identity provider offers inline user enrollment, self-service device management, and support for a variety of authentication methods — such as passkeys and security keys, Duo Push, or Verified Duo Push — in the Universal Prompt.

Quest On Demand Audit

Integrating with SpecterOps BloodHound Enterprise helps you reduce the risk of attacks by enabling you to easily identify, prioritize, and eliminate the most vital avenues that attackers can exploit.

Community integrations

The following integrations are developed by the BloodHound community and are not officially supported by SpecterOps.

wineventhound

by @RantaSec

FalconHound

by @falconforceteam

ServiceHound

by @Eli4m
Please share your integrations with us in the BloodHound Gang community Slack.