Skip to content
Navigation Menu
Sign in
Appearance settings
Platform
AI CODE CREATION
GitHub Copilot
Write better code with AI
GitHub Copilot app
Direct agents from issue to merge
MCP Registry
Integrate external tools
DEVELOPER WORKFLOWS
Actions
Automate any workflow
Codespaces
Instant dev environments
Issues
Plan and track work
Code Review
Manage code changes
Code Quality
Enforce quality at merge
APPLICATION SECURITY
GitHub Advanced Security
Find and fix vulnerabilities
Code security
Secure your code as you build
Secret protection
Stop leaks before they start
EXPLORE
Why GitHub
Documentation
Blog
Changelog
Marketplace
View all features
Solutions
BY COMPANY SIZE
Enterprises
Small and medium teams
Startups
Nonprofits
BY USE CASE
App Modernization
DevSecOps
DevOps
CI/CD
View all use cases
BY INDUSTRY
Healthcare
Financial services
Manufacturing
Government
View all industries
View all solutions
Resources
EXPLORE BY TOPIC
AI
Software Development
DevOps
Security
View all topics
EXPLORE BY TYPE
Customer stories
Events & webinars
Ebooks & reports
Business insights
GitHub Skills
SUPPORT & SERVICES
Documentation
Customer support
Community forum
Trust center
Partners
View all resources
Open Source
COMMUNITY
GitHub Sponsors
Fund open source developers
PROGRAMS
Security Lab
Maintainer Community
Accelerator
GitHub Stars
Archive Program
REPOSITORIES
Topics
Trending
Collections
Enterprise
ENTERPRISE SOLUTIONS
Enterprise platform
AI-powered developer platform
AVAILABLE ADD-ONS
GitHub Advanced Security
Enterprise-grade security features
Copilot for Business
Enterprise-grade AI features
Premium Support
Enterprise-grade 24/7 support
Pricing
Type
/
to search
Sign in
Sign up
Appearance settings
You signed in with another tab or window.
Reload
to refresh your session.
You signed out in another tab or window.
Reload
to refresh your session.
You switched accounts on another tab or window.
Reload
to refresh your session.
Dismiss alert
{{ message }}
Uh oh!
There was an error while loading.
Please reload this page
.
SpecterOps
/
BloodHoundQueryLibrary
Public
Notifications
You must be signed in to change notification settings
Fork
25
Star
202
Code
Issues
1
Pull requests
3
Actions
Security and quality
0
Insights
Additional navigation options
Code
Issues
Pull requests
Actions
Security and quality
Insights
Files
Expand file tree
main
Breadcrumbs
BloodHoundQueryLibrary
/
queries
/
Copy path
Directory actions
More options
More options
Directory actions
More options
More options
Latest commit
History
History
History
main
Breadcrumbs
BloodHoundQueryLibrary
/
queries
/
Copy path
Top
Folders and files
Name
Name
Last commit message
Last commit date
parent directory
..
ACEs across trusts.yml
ACEs across trusts.yml
AD Groups nested more than 3 levels.yml
AD Groups nested more than 3 levels.yml
AS-REP Roastable Tier Zero users (DontReqPreAuth).yml
AS-REP Roastable Tier Zero users (DontReqPreAuth).yml
AS-REP Roastable users (DontReqPreAuth).yml
AS-REP Roastable users (DontReqPreAuth).yml
Accounts related to AAD Entra Connect.yml
Accounts related to AAD Entra Connect.yml
Accounts with SID History to a non-existent domain.yml
Accounts with SID History to a non-existent domain.yml
Accounts with SID History to a same-domain account.yml
Accounts with SID History to a same-domain account.yml
Accounts with SID History.yml
Accounts with SID History.yml
Accounts with clear-text password attributes.yml
Accounts with clear-text password attributes.yml
Accounts with smart card required in domains where smart account passwords do not expire.yml
Accounts with smart card required in domains where smart account passwords do not expire.yml
Accounts with weak password storage encryption.yml
Accounts with weak password storage encryption.yml
AdminSDHolder protected Accounts and Groups.yml
AdminSDHolder protected Accounts and Groups.yml
AdminSDHolder protected objects without 'Admin Count' flag.yml
AdminSDHolder protected objects without 'Admin Count' flag.yml
AdminSDHolder to protected objects relationship.yml
AdminSDHolder to protected objects relationship.yml
AdminSDHolder with ACL inheritance enabled.yml
AdminSDHolder with ACL inheritance enabled.yml
All ADCS ESC privilege escalation edges.yml
All ADCS ESC privilege escalation edges.yml
All Azure VMs with a tied Managed Identity.yml
All Azure VMs with a tied Managed Identity.yml
All DNSAdmins.yml
All DNSAdmins.yml
All Domain Admins.yml
All Domain Admins.yml
All GPOs applied to a specific computer.yml
All GPOs applied to a specific computer.yml
All Global Administrators.yml
All Global Administrators.yml
All Kerberoastable users.yml
All Kerberoastable users.yml
All Schema Admins.yml
All Schema Admins.yml
All coerce and NTLM relay edges.yml
All coerce and NTLM relay edges.yml
All direct Controllers of MS Graph.yml
All direct Controllers of MS Graph.yml
All enabled Group Managed Service Accounts (gMSAs).yml
All enabled Group Managed Service Accounts (gMSAs).yml
All incoming and local paths for a specific computer.yml
All incoming and local paths for a specific computer.yml
All members of Operator groups.yml
All members of Operator groups.yml
All members of Protected Users.yml
All members of Protected Users.yml
All members of high privileged roles.yml
All members of high privileged roles.yml
All paths crossing a specific trust.yml
All paths crossing a specific trust.yml
All privileged Azure Service Principals.yml
All privileged Azure Service Principals.yml
All service principals with Microsoft Graph App Role assignments.yml
All service principals with Microsoft Graph App Role assignments.yml
All service principals with Microsoft Graph privilege to grant arbitrary App Roles.yml
All service principals with Microsoft Graph privilege to grant arbitrary App Roles.yml
Azure groups nested more than 3 levels.yml
Azure groups nested more than 3 levels.yml
Azure tenants with fewer than 2 Global Administrators.yml
Azure tenants with fewer than 2 Global Administrators.yml
Azure tenants with more than 5 Global Administrators.yml
Azure tenants with more than 5 Global Administrators.yml
CA Administrators and CA Managers (ESC7).yml
CA Administrators and CA Managers (ESC7).yml
Circular AD group memberships.yml
Circular AD group memberships.yml
Circular AZ group memberships.yml
Circular AZ group memberships.yml
Collection health of CA Registry Data.yml
Collection health of CA Registry Data.yml
Collection health of DC Registry Data.yml
Collection health of DC Registry Data.yml
Compromising permissions on ADCS nodes (ESC5).yml
Compromising permissions on ADCS nodes (ESC5).yml
Computer owners who can obtain LAPS passwords.yml
Computer owners who can obtain LAPS passwords.yml
Computers not requiring inbound SMB signing.yml
Computers not requiring inbound SMB signing.yml
Computers where Domain Users are local administrators.yml
Computers where Domain Users are local administrators.yml
Computers where Domain Users can read LAPS passwords.yml
Computers where Domain Users can read LAPS passwords.yml
Computers with local administrator permissions over other computers.yml
Computers with local administrator permissions over other computers.yml
Computers with membership in default privileged groups.yml
Computers with membership in default privileged groups.yml
Computers with non-default Primary Group membership.yml
Computers with non-default Primary Group membership.yml
Computers with passwords older than the default maximum password age.yml
Computers with passwords older than the default maximum password age.yml
Computers with the WebClient running.yml
Computers with the WebClient running.yml
Computers with the outgoing NTLM setting set to Deny all.yml
Computers with the outgoing NTLM setting set to Deny all.yml
Computers with unsupported operating systems.yml
Computers with unsupported operating systems.yml
Computers without Windows LAPS.yml
Computers without Windows LAPS.yml
Cross-forest trusts with abusable configuration.yml
Cross-forest trusts with abusable configuration.yml
DCs vulnerable to NTLM relay to LDAP attacks.yml
DCs vulnerable to NTLM relay to LDAP attacks.yml
Dangerous privileges for Domain Users groups.yml
Dangerous privileges for Domain Users groups.yml
Devices with unsupported operating systems.yml
Devices with unsupported operating systems.yml
Disabled Tier Zero High Value principals - AD.yml
Disabled Tier Zero High Value principals - AD.yml
Disabled Tier Zero High Value principals - AZ.yml
Disabled Tier Zero High Value principals - AZ.yml
Domain Admins logons to non-Domain Controllers.yml
Domain Admins logons to non-Domain Controllers.yml
Domain Controllers allowing NTLMv1 or LM authentication.yml
Domain Controllers allowing NTLMv1 or LM authentication.yml
Domain controllers with UPN certificate mapping enabled.yml
Domain controllers with UPN certificate mapping enabled.yml
Domain controllers with weak certificate binding enabled.yml
Domain controllers with weak certificate binding enabled.yml
Domain migration groups.yml
Domain migration groups.yml
Domains affected by AdPrep privilege escalation risk.yml
Domains affected by AdPrep privilege escalation risk.yml
Domains affected by Exchange privilege escalation risk.yml
Domains affected by Exchange privilege escalation risk.yml
Domains allowing authenticated domain enumeration.yml
Domains allowing authenticated domain enumeration.yml
Domains allowing unauthenticated NSPI RPC binds.yml
Domains allowing unauthenticated NSPI RPC binds.yml
Domains allowing unauthenticated domain enumeration.yml
Domains allowing unauthenticated domain enumeration.yml
Domains allowing unauthenticated rootDSE searches and binds.yml
Domains allowing unauthenticated rootDSE searches and binds.yml
Domains exempting privileged groups from AdminSDHolder protections.yml
Domains exempting privileged groups from AdminSDHolder protections.yml
Domains not mitigating CVE-2021-42291.yml
Domains not mitigating CVE-2021-42291.yml
Domains not verifying UPN and SPN uniqueness.yml
Domains not verifying UPN and SPN uniqueness.yml
Domains where any user can join a computer to the domain.yml
Domains where any user can join a computer to the domain.yml
Domains with List Object mode enabled.yml
Domains with List Object mode enabled.yml
Domains with a minimum default password policy length less than 15 characters.yml
Domains with a minimum default password policy length less than 15 characters.yml
Domains with a single-point-of-failure Domain Controller.yml
Domains with a single-point-of-failure Domain Controller.yml
Domains with functional level not the latest version.yml
Domains with functional level not the latest version.yml
Domains with more than 50 Tier Zero accounts.yml
Domains with more than 50 Tier Zero accounts.yml
Domains with smart card accounts where smart account passwords do not expire.yml
Domains with smart card accounts where smart account passwords do not expire.yml
Domains without Group Managed Service Accounts.yml
Domains without Group Managed Service Accounts.yml
Domains without Microsoft LAPS computers.yml
Domains without Microsoft LAPS computers.yml
Domains without Protected Users group.yml
Domains without Protected Users group.yml
ESC8-vulnerable Enterprise CAs.yml
ESC8-vulnerable Enterprise CAs.yml
Enabled Entra ID guest users inactive for 30 days.yml
Enabled Entra ID guest users inactive for 30 days.yml
Enabled Entra ID users inactive for 90 days.yml
Enabled Entra ID users inactive for 90 days.yml
Enabled Entra Tier Zero principals inactive for 60 days.yml
Enabled Entra Tier Zero principals inactive for 60 days.yml
Enabled Tier Zero High Value principals inactive for 60 days.yml
Enabled Tier Zero High Value principals inactive for 60 days.yml
Enabled built-in guest user accounts.yml
Enabled built-in guest user accounts.yml
Enabled computers inactive for 180 days - MSSQL Failover Cluster.yml
Enabled computers inactive for 180 days - MSSQL Failover Cluster.yml
Enabled computers inactive for 180 days.yml
Enabled computers inactive for 180 days.yml
Enabled users inactive for 180 days.yml
Enabled users inactive for 180 days.yml
Enrollment rights on CertTemplates with OIDGroupLink.yml
Enrollment rights on CertTemplates with OIDGroupLink.yml
Enrollment rights on certificate templates published to Enterprise CA with User Specified SAN enabled.yml
Enrollment rights on certificate templates published to Enterprise CA with User Specified SAN enabled.yml
Enrollment rights on certificate templates published to Enterprise CA with vulnerable HTTP(S) endpoint (ESC8).yml
Enrollment rights on certificate templates published to Enterprise CA with vulnerable HTTP(S) endpoint (ESC8).yml
Enrollment rights on published ESC1 certificate templates.yml
Enrollment rights on published ESC1 certificate templates.yml
Enrollment rights on published ESC15 certificate templates.yml
Enrollment rights on published ESC15 certificate templates.yml
Enrollment rights on published ESC2 certificate templates.yml
Enrollment rights on published ESC2 certificate templates.yml
View all files
You can’t perform that action at this time.