Skip to main content
AD Academy
Tools
Advanced20 minLast updated: Topic 4 of 4

Reading the BloodHound graph — from user to Domain Admin

Walking an attack path step by step — and using the same tool for defense.

Not read

What you will learn here

  • What an Edge is and which relationship types matter
  • How to collect the graph with SharpHound / bloodhound-python
  • How to read an attack path step by step

Worth reading first:GOAD — Game of Active Directory

Theory

collects data from (who is in a group, who is logged into which computer, which ACL they have access to) and builds a relationship graph. The attack is no longer "where is a weak account" — but finding a path in the graph from the node you control to the Admins group.

Edges you must know

  • MemberOf — group membership.
  • AdminTo — a user/group is admin on a computer.
  • HasSession — a user is currently logged into a computer (an opportunity to steal credentials from memory).
  • CanRDP / CanPSRemote — remote access to a computer.
  • — replication right on the domain — the prize.
  • WriteDacl / AddMember / AddKeyCredentialLink — rights for "self-upgrade" in the chain.

Chain: bob, HasSession, WORKSTATION1, AdminTo, svc_helpdesk, CanRDP, SRV-APP1, MemberOf, G-Deploy, DCSync, CORP.LOCAL. Each arrow is an Edge (relationship). Defense: run the same query and break every path before the attacker.

Short and clear

  • Each arrow in the graph is an Edge — a relationship between two AD objects.
  • HasSession = credentials in memory; AdminTo = hash extraction; DCSync = domain takeover.
  • Defense: run the same query before the attacker and break every path.
  • After fixing — run again and confirm the path is gone.

Real-life examplebob is connected to WORKSTATION1 via HasSession. The attacker steals svc_helpdesk credentials from memory, escalates to SRV-APP1 via RDP, and reaches DCSync through G-Deploy.

Practice — collecting the graph

# SharpHound from Windows
SharpHound.exe -c All --zipfilename corp_collection
powershell
# bloodhound-python from Linux
bloodhound-python -u attacker -p 'Password123' \
  -d corp.local -dc dc01.corp.local -c All
bash

Import the zip into and check: Pre-built Analytics → "Find Shortest Paths to Admins".

Reading the path step by step

Example path: bob → HasSession → WORKSTATION1 → AdminTo → svc_helpdesk → CanRDP → SRV-APP1 → MemberOf → G-Deploy → → CORP.LOCAL.

  • 1. bob is logged onto WORKSTATION1 (HasSession) — if we control bob, there are additional credentials in the computer's memory to steal.
  • 2. svc_helpdesk is admin on WORKSTATION1 (AdminTo) — with rights on the computer, we extract svc_helpdesk's hash from SAM/.
  • 3. svc_helpdesk can RDP to SRV-APP1 (CanRDP) and is logged on there — additional credentials in memory.
  • 4. Whoever is logged onto SRV-APP1 belongs to G-Deploy, which holds on the domain.
  • 5. = domain takeover — we pull all hashes via replication.

Useful Cypher queries

// Shortest path from user to Domain Admins
MATCH p=shortestPath(
  (u:User {name:'BOB@CORP.LOCAL'})-[*1..]->
  (g:Group {name:'DOMAIN ADMINS@CORP.LOCAL'})
) RETURN p

// Who holds DCSync on the domain
MATCH (n)-[:DCSync]->(d:Domain {name:'CORP.LOCAL'}) RETURN n

// Targets for AS-REP Roasting
MATCH (u:User {dontreqpreauth: true}) RETURN u

// Computers with Unconstrained Delegation
MATCH (c:Computer {unconstraineddelegation: true}) RETURN c

// Admins on a computer where a Domain Admin has a session
MATCH (da:Group {name:'DOMAIN ADMINS@CORP.LOCAL'})<-[:MemberOf*1..]-(u1:User)
      -[:HasSession]->(c:Computer)<-[:AdminTo]-(u2:User)
RETURN DISTINCT u2.name, c.name
cypher

Detection and defense — BloodHound is also a defensive tool

  • Run "Shortest Paths to Admins" before the attacker — breaking every path (removing AdminTo, rotating a password, killing a stale session) is real mitigation.
  • Find exactly these edges in the logs: which svc_helpdesk logs in via RDP to servers (4624 Type 10), who runs without a reason.

Mitigation

  • Fix edges: remove unnecessary AdminTo, disable unneeded delegation, keep a small number of holders.
  • For every service account with high privileges — least privilege, PAW for management, and monitoring of every use.
  • Return to the graph after the fix and verify the path is gone — proof the mitigation worked.

Check yourself

What is an Edge in BloodHound?

Which edge marks the main "prize" in the graph?

In the path u1 → HasSession → WS1 → AdminTo → svc1, what is the attack logic?

Why is running "Shortest Paths to Domain Admins" also a defensive action?

Was this page helpful?