Agent skill

Conducting Internal Reconnaissance With Bloodhound Ce

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Conduct internal Active Directory reconnaissance using BloodHound Community Edition's graph database with the SharpHound (AD) and AzureHound (Entra ID) collectors, mapping ACLs, sessions, and group…

Apache-2.0Auto-check passedSecurity

Install Conducting Internal Reconnaissance With Bloodhound Ce

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill conducting-internal-reconnaissance-with-bloodhound-ce -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills conducting-internal-reconnaissance-with-bloodhound-ce --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/conducting-internal-reconnaissance-with-bloodhound-ce .claude/skills/conducting-internal-reconnaissance-with-bloodhound-ce && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
conducting-internal-reconnaissance-with-bloodhound-ce
GitHub stars
34k
Token cost
~2k tokens
SKILL.md length
697 words
Files
8 (incl. scripts, references, assets)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Conduct internal Active Directory reconnaissance using BloodHound Community Edition's graph database with the SharpHound (AD) and AzureHound (Entra ID) collectors, mapping ACLs, sessions, and group…

  • Works in 5 steps: BloodHound CE Deployment → Data Collection with SharpHound v2 → Data Import and Initial Analysis → …
  • Tasks that involve Red teaming and adversary simulation
  • SKILL.md covers Overview, When to Use, Prerequisites and Objectives, plus 5 more sections
  • Runs Python scripts from its folder; calls docker and curl; reaches ghst.ly

What it does

Conducting Internal Reconnaissance With Bloodhound Ce is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Conduct internal Active Directory reconnaissance using BloodHound Community Edition's graph database with the SharpHound (AD) and AzureHound (Entra ID) collectors, mapping ACLs, sessions, and group memberships into attack paths from a low-privileged foothold to Domain Admin. Use after an initial AD foothold to identify privilege escalation chains, or to validate that AD hardening closed known attack paths.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/api-reference.md` and `references/standards.md`).

It sits in Security, covering Red teaming and adversary simulation. It works with Microsoft Entra ID. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Red teaming and adversary simulation

Example prompts

  • “/conducting-internal-reconnaissance-with-bloodhound-ce”

Requirements

  • Python 3
  • Docker

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. BloodHound CE Deployment
  2. Data Collection with SharpHound v2
  3. Data Import and Initial Analysis
  4. Custom Cypher Queries
  5. Attack Path Prioritization

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • docker
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • ghst.ly

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Conducting Internal Reconnaissance With Bloodhound Ce loads about 2k tokens when it runs, and up to ~3.2k if it reads all its reference files. Until then it costs about 116 tokens; SKILL.md has 697 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~116
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 697 words, ~2,037 tokens.

Download SKILL.mdSave it as .claude/skills/conducting-internal-reconnaissance-with-bloodhound-ce/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
conducting-internal-reconnaissance-with-bloodhound-ce
description
Conduct internal Active Directory reconnaissance using BloodHound Community Edition's graph database with the SharpHound (AD) and AzureHound (Entra ID) collectors, mapping ACLs, sessions, and group memberships into attack paths from a low-privileged foothold to Domain Admin. Use after an initial AD foothold to identify privilege escalation chains, or to validate that AD hardening closed known attack paths.
domain
cybersecurity
subdomain
red-teaming
tags
red-team, reconnaissance, bloodhound, active-directory, attack-paths, privilege-escalation, graph-analysis
version
1.0
author
mahipal
license
Apache-2.0
d3fend_techniques
Restore Access, Password Authentication, Biometric Authentication, Strong Password Policy, Restore User Account Access
nist_csf
ID.RA-01, GV.OV-02, DE.AE-07
mitre_attack
T1087.002, T1069.002, T1482, T1018

Conducting Internal Reconnaissance with BloodHound CE

Legal Notice: This skill is for authorized security testing and educational purposes only. Unauthorized use against systems you do not own or have written permission to test is illegal and may violate computer fraud laws.

Overview

BloodHound Community Edition (CE) is a modern, web-based Active Directory reconnaissance platform developed by SpecterOps that uses graph theory to reveal hidden relationships and attack paths within AD environments. Unlike the legacy BloodHound application, BloodHound CE uses a PostgreSQL backend with a dedicated graph database, providing improved performance, a modern web UI, and enhanced API capabilities. Red teams use BloodHound CE to collect AD objects, ACLs, sessions, group memberships, and trust relationships, then visualize attack paths from compromised low-privileged accounts to high-value targets like Domain Admins. The SharpHound collector (v2 for CE) gathers data from Active Directory, while AzureHound collects from Azure AD / Entra ID environments.

When to Use

  • When conducting security assessments that involve conducting internal reconnaissance with bloodhound ce
  • When following incident response procedures for related security events
  • When performing scheduled security testing or auditing activities
  • When validating security controls through hands-on testing

Prerequisites

  • Familiarity with red teaming concepts and tools
  • Access to a test or lab environment for safe execution
  • Python 3.8+ with required dependencies installed
  • Appropriate authorization for any testing activities

Objectives

  • Deploy BloodHound CE server using Docker Compose
  • Collect AD data using SharpHound v2 or BloodHound.py
  • Import collected data into BloodHound CE for graph analysis
  • Identify shortest attack paths from owned principals to Domain Admins
  • Discover ACL-based attack paths, Kerberoastable accounts, and delegation abuse
  • Execute custom Cypher queries for advanced attack path analysis
  • Generate attack path reports for engagement documentation

MITRE ATT&CK Mapping

  • T1087.002 - Account Discovery: Domain Account
  • T1069.002 - Permission Groups Discovery: Domain Groups
  • T1482 - Domain Trust Discovery
  • T1615 - Group Policy Discovery
  • T1018 - Remote System Discovery
  • T1033 - System Owner/User Discovery
  • T1016 - System Network Configuration Discovery

Workflow

Phase 1: BloodHound CE Deployment
  1. Deploy BloodHound CE using Docker Compose:
    bash
    curl -L https://ghst.ly/getbhce -o docker-compose.yml
    docker compose pull
    docker compose up -d
  2. Access the web interface at https://localhost:8080
  3. Log in with the default admin credentials (displayed in Docker logs):
    bash
    docker compose logs | grep "Initial Password"
  4. Change the default admin password immediately
Phase 2: Data Collection with SharpHound v2
  1. Transfer SharpHound v2 to the compromised Windows host:
    powershell
    # Execute full collection
    .\SharpHound.exe -c All --outputdirectory C:\Temp
    
    # DCOnly collection (LDAP only, stealthier)
    .\SharpHound.exe -c DCOnly
    
    # Session collection for logged-on user mapping
    .\SharpHound.exe -c Session --loop --loopduration 02:00:00
    
    # Collect from specific domain
    .\SharpHound.exe -c All -d child.domain.local
  2. Alternative: Use BloodHound.py from Linux:
    bash
    bloodhound-python -u user -p 'Password123' -d domain.local -ns 10.10.10.1 -c All
  3. Exfiltrate the generated ZIP file to the analysis workstation
Phase 3: Data Import and Initial Analysis
  1. Upload collected data via the BloodHound CE web interface (File Ingest)
  2. Mark compromised accounts as "Owned" in the interface
  3. Run built-in analysis queries:
    • Shortest Path to Domain Admin
    • Kerberoastable Users with Path to DA
    • AS-REP Roastable Users
    • Users with DCSync Rights
    • Computers with Unconstrained Delegation
Show full SKILL.md (345 more words)Show less
Phase 4: Custom Cypher Queries
  1. Execute custom Cypher queries in the BloodHound CE search bar:
    cypher
    // Find shortest path from owned principals to Domain Admins
    MATCH p=shortestPath((n {owned:true})-[*1..]->(m:Group {name:"DOMAIN ADMINS@DOMAIN.LOCAL"}))
    RETURN p
    
    // Find Kerberoastable users with path to DA
    MATCH (u:User {hasspn:true})
    MATCH p=shortestPath((u)-[*1..]->(g:Group {name:"DOMAIN ADMINS@DOMAIN.LOCAL"}))
    RETURN p
    
    // Find computers with sessions of DA members
    MATCH (c:Computer)-[:HasSession]->(u:User)-[:MemberOf*1..]->(g:Group {name:"DOMAIN ADMINS@DOMAIN.LOCAL"})
    RETURN c.name, u.name
    
    // Find ACL-based attack paths (GenericAll, WriteDACL, GenericWrite)
    MATCH p=(u:User)-[:GenericAll|GenericWrite|WriteDacl|WriteOwner|ForceChangePassword*1..]->(t)
    WHERE u.owned = true
    RETURN p
    
    // Find users who can DCSync
    MATCH (u)-[:MemberOf*0..]->()-[:DCSync|GetChanges|GetChangesAll*1..]->(d:Domain)
    RETURN u.name, d.name
    
    // Find computers with LAPS but readable by non-admins
    MATCH (c:Computer {haslaps:true})
    MATCH p=(u:User)-[:ReadLAPSPassword]->(c)
    RETURN p
Phase 5: Attack Path Prioritization
  1. Score identified attack paths by:
    • Number of hops (shorter = higher priority)
    • Stealth requirements (avoid noisy techniques)
    • Tool availability for each hop
    • Likelihood of detection at each step
  2. Create an execution plan for the highest-priority paths
  3. Identify required tools for each step in the chain
  4. Plan OPSEC considerations for each technique

Tools and Resources

ToolPurposePlatform
BloodHound CEWeb-based graph analysis platformDocker
SharpHound v2AD data collection (.NET, for CE)Windows
BloodHound.pyAD data collection (Python)Linux
AzureHoundAzure AD / Entra ID data collectionCross-platform
PlumHoundAutomated BloodHound reportingPython
BloodHound Query LibraryCommunity Cypher query repositoryWeb

Key Attack Path Types

Path TypeDescriptionExample
ACL AbuseExploit misconfigured ACLsGenericAll on DA group
KerberoastingCrack service account passwordsSPN account → DA
AS-REP RoastingAttack accounts without pre-authNo-preauth user → password crack
Delegation AbuseExploit unconstrained/constrained delegationComputer → impersonate DA
GPO AbuseModify GPOs applied to privileged OUsGPO write → code execution on DA
Session HijackLeverage DA sessions on compromised hostsAdmin session → token theft

Validation Criteria

  • BloodHound CE deployed and accessible
  • SharpHound v2 data collected from all domains in scope
  • Data successfully imported into BloodHound CE
  • Owned principals marked in the interface
  • Shortest paths to Domain Admin identified
  • ACL-based attack paths documented
  • Kerberoastable and AS-REP roastable accounts listed
  • Custom Cypher queries executed for advanced analysis
  • Attack paths prioritized by feasibility and stealth
  • Report generated with all identified paths and evidence

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in skills/conducting-internal-reconnaissance-with-bloodhound-ce of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • assets/template.md
  • references/api-reference.md
  • references/standards.md
  • references/workflows.md
  • scripts/agent.py
  • scripts/process.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Conducting Internal Reconnaissance With Bloodhound Ce next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Conducting Internal Reconnaissance With Bloodhound Ce compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Conducting Internal Reconnaissance With Bloodhound Ce this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2kAutomated safety check: PassApache-2.0
App Registration PostureSCStelz/security-investigator249—~21kAutomated safety check: PassMIT
Defender For Identityvinayaklatthe/microsoft-security-skills175—~2kAutomated safety check: PassMIT
Taint Instrumentation AssistantArabelaTso/Skills-4-SE253—~2.9kAutomated safety check: PassApache-2.0
Windows Serversickn33/agentic-awesome-skills47k2 repos~2.9kAutomated safety check: PassMIT
Azure Pimvinayaklatthe/microsoft-security-skills175—~1.9kAutomated safety check: PassMIT

Similar skills

  • App Registration Posture

    SCStelz/security-investigator

    Audit Entra ID app registration and service principal security posture.

    249 GitHub stars~21k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Defender For Identity

    vinayaklatthe/microsoft-security-skills

    Guidance for Microsoft Defender for Identity (MDI) — identity threat detection (ITDR) across on-premises Active Directory, AD CS, AD FS, and Entra Connect using sensors.

    175 GitHub stars~2k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Taint Instrumentation Assistant

    ArabelaTso/Skills-4-SE

    Instruments code to track the flow of untrusted or sensitive data at runtime, enabling detection of injection vulnerabilities, data leaks, and privilege violations.

    253 GitHub stars~2.9k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Windows Server

    sickn33/agentic-awesome-skills

    Administer Windows Server systems. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~2.9k tokens
    SecurityAuto-check passed
  • Azure Pim

    vinayaklatthe/microsoft-security-skills

    Guidance for Microsoft Entra Privileged Identity Management (PIM) — just-in-time, time-bound, approval-based, audited elevation for Entra roles, Azure resource roles, and privileged groups.

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Windows Av Evasion

    yaklang/hack-skills

    AV/EDR evasion playbook for Windows. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~2.9k tokensUpdated 28 days ago
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Conducting Internal Reconnaissance With Bloodhound Ce

What does Conducting Internal Reconnaissance With Bloodhound Ce do?

Conduct internal Active Directory reconnaissance using BloodHound Community Edition's graph database with the SharpHound (AD) and AzureHound (Entra ID) collectors, mapping ACLs, sessions, and group…. Conducting Internal Reconnaissance With Bloodhound Ce is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Conduct internal Active Directory reconnaissance using BloodHound Community Edition's graph database with the SharpHound (AD) and AzureHound (Entra ID) collectors, mapping ACLs, sessions, and group memberships into attack paths from a low-privileged foothold to Domain Admin.

When should I use Conducting Internal Reconnaissance With Bloodhound Ce?

Conducting Internal Reconnaissance With Bloodhound Ce fits situations like: tasks that involve Red teaming and adversary simulation.

How do I install Conducting Internal Reconnaissance With Bloodhound Ce in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill conducting-internal-reconnaissance-with-bloodhound-ce -a claude-code`. Or copy the skill folder (skills/conducting-internal-reconnaissance-with-bloodhound-ce in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/conducting-internal-reconnaissance-with-bloodhound-ce in your project. Claude Code loads it when a task matches its description.

How do I install Conducting Internal Reconnaissance With Bloodhound Ce in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill conducting-internal-reconnaissance-with-bloodhound-ce -a codex`. Or copy the skill folder (skills/conducting-internal-reconnaissance-with-bloodhound-ce in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/conducting-internal-reconnaissance-with-bloodhound-ce in your project. Codex loads it when a task matches its description.

Can I use Conducting Internal Reconnaissance With Bloodhound Ce in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill conducting-internal-reconnaissance-with-bloodhound-ce -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/conducting-internal-reconnaissance-with-bloodhound-ce, .gemini/skills/conducting-internal-reconnaissance-with-bloodhound-ce, .github/skills/conducting-internal-reconnaissance-with-bloodhound-ce and .opencode/skills/conducting-internal-reconnaissance-with-bloodhound-ce in your project.

What does Conducting Internal Reconnaissance With Bloodhound Ce need to run?

Going by SKILL.md and its folder, Conducting Internal Reconnaissance With Bloodhound Ce needs Python for the scripts in its folder and the command-line tools its instructions call (docker and curl). Our summary lists: Python 3; Docker.

Does Conducting Internal Reconnaissance With Bloodhound Ce access the network?

SKILL.md names 1 domain. In commands or code: ghst.ly; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Conducting Internal Reconnaissance With Bloodhound Ce safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Conducting Internal Reconnaissance With Bloodhound Ce use?

Conducting Internal Reconnaissance With Bloodhound Ce is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Conducting Internal Reconnaissance With Bloodhound Ce use?

About 2k tokens (SKILL.md is roughly 8.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.2k tokens, read only when the agent opens those files.

What are the alternatives to Conducting Internal Reconnaissance With Bloodhound Ce?

Skills that share tags, products or a category with Conducting Internal Reconnaissance With Bloodhound Ce: App Registration Posture (SCStelz/security-investigator, 249 stars), Defender For Identity (vinayaklatthe/microsoft-security-skills, 175 stars), Taint Instrumentation Assistant (ArabelaTso/Skills-4-SE, 253 stars) and Windows Server (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Conducting Internal Reconnaissance With Bloodhound Ce?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.