VYPR
advisoryPublished Jul 28, 2026· 1 source

SpecterOps BloodHound Enterprise Expands to AWS and Entra ID, Integrates AI Agent

SpecterOps enhances BloodHound Enterprise with AWS and Microsoft Entra ID support, enabling hybrid attack path management and integrating an AI agent for proactive threat elimination.

SpecterOps has significantly expanded the capabilities of its BloodHound Enterprise platform, introducing support for Amazon Web Services (AWS) and Microsoft Entra ID. This move extends the platform's attack path management features to hybrid environments, allowing security teams to visualize and neutralize threats that traverse across cloud, identity, and on-premises systems.

At the core of this update is the new BloodHound Hunter AI agent. This agent is designed to integrate adversary intelligence directly into security workflows, enabling organizations to proactively identify and eliminate potential attack paths before they can be exploited. "Attackers do not move through isolated systems. They move through the relationships between them, chaining trust, permissions, and misconfigurations across cloud, identity, and infrastructure until they achieve their objectives," stated Jared Atkinson, Chief Technology Officer at SpecterOps.

The enhanced BloodHound Enterprise now maps attack paths across a broader spectrum of services, including Okta, GitHub, Jamf, Active Directory, Entra ID, and now AWS. This unified view allows security teams to trace an attack from a foothold in one platform to critical assets in another, and then sever that path at the most effective chokepoint. The platform prioritizes identified attack paths and provides remediation guidance to shut them down.

With native support for AWS, BloodHound Enterprise can now surface traversable paths and pinpoint critical chokepoints that prevent a minor compromise from escalating into a full-scale breach. The platform also allows for the implementation of "Privilege Zones" around vital data stores or roles, offering granular protection for an organization's most sensitive assets.

Furthermore, the integration with Microsoft Entra Agent ID extends attack path management to Microsoft Copilot agents and other AI identities. This capability, built on SpecterOps' research into abusable Copilot configurations, allows security teams to investigate how AI agents, delegated identities, and service principals can inadvertently create indirect paths to privileged access.

The BloodHound Hunter AI agent, leveraging the Model Context Protocol (MCP), connects approved AI agents and knowledge sources directly to BloodHound Enterprise findings. This enables teams to prioritize remediation based on their specific environment, translate technical findings into actionable business language, and identify key assets or enclaves to protect. Customers can bring their own trusted AI agents and knowledge sources to evaluate findings against their unique controls and priorities.

These new features also enhance the value of BloodHound Scentry, SpecterOps' offering that combines tradecraft expertise with BloodHound Enterprise to accelerate maturity in identity attack path management. The overall goal is to provide defenders with a dynamic understanding of adversary movement and the tools to proactively disrupt it across increasingly complex hybrid infrastructures.

Synthesized by Vypr AI