Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
cypherhound — Your template-based BloodHound terminal companion tool | Kitploit
Tools/GitHubGitHub/fin3ss3g0d/cypherhound
ReconnaissanceInformation GatheringPenetration TestingUtilities & Frameworks
GitHubfin3ss3g0d/cypherhound

cypherhound

Your template-based BloodHound terminal companion tool

View Repository
45436418 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CypherHound

logo

A Python3 terminal application that contains Neo4j cyphers for BloodHound data sets with a script to automate importing them into BloodHound CE.

Output Samples

Terminal

demo

HTML Report

report summary

HTML Report (continued)

details sample

Why?

BloodHound is a staple tool for every penetration tester. However, there are some negative side effects based on its design. I will cover the biggest pain points I've experienced and what this tool aims to address:

  1. My tools think in lists - until my tools parse exported JSON graphs, I need graph results in a line-by-line format .txt file to actually attack things from other tools
  2. Copy/pasting graph results - this plays into the first but do we need to really explain this one?
  3. Graphs can be too large to draw - Large AD environments, multiple shortest paths being drawn on the same graph, etc. The information contained in any graph can aid our goals as the attacker and we need to be able to view all data efficiently.
  4. Manually running custom cyphers is time-consuming - let's automate it :)

This tool can provide significant value for both red and blue teams.

Features

Take back control of your BloodHound data with CypherHound!

  • Read cypher templates from a YAML file
    • Set cyphers to search based on user input (user, group, and computer-specific)
    • User-defined regex cyphers
  • User-defined exporting of all results
    • Examples provided in grep/cut/awk-friendly format
    • Export any combination of cyphers to a modern, sleek HTML report
  • Run the same queries from the BloodHound CE GUI
    • YAML -> JSON converter and automated BloodHound CE query importer
    • BloodHound Legacy customqueries.json importer script into BloodHound CE included

Installation

Make sure to have python3 installed and run:

python3 -m pip install -r requirements.txt

Usage

Start the program with: python3 cypherhound.py -c config.json -y queries.yaml

config.json

The program will read a configuration file in json format. An example of this file is shown below:

{
    "user": "neo4j",
    "pwd": "password",
    "database": "neo4j"
}

where:

  • user is your Neo4j username
  • pwd is your Neo4j password
  • database is your Neo4j database

YAML Format

The program reads queries from a YAML file in the format below. ad-queries.yaml has been provided as an example containing queries related to Active Directory. msg_template is not required for shortest paths queries but they must return the variable containing the path

queries:
- group: general
  desc: List all AddKeyCredentialLink privileges for owned principals
  cypher: |-
    MATCH (n {owned: true})-[r:AddKeyCredentialLink]->(m)
    RETURN n.name AS n_name, m.name AS m_name, labels(m) AS labels_m, labels(n) AS labels_n
    ORDER BY n.name
  msg_template: |-
    {{ n_name }} ({{ labels_n[0] }}/{{ labels_n[1] }}) has AddKeyCredentialLink over {{ m_name }} ({{
    labels_m[0] }}/{{ labels_m[1] }})

A table breakdown of the keys/value pairs can be seen below:

KeyDescription
groupThe group this query belongs to, groups are user-defined e.g. "general"
descThe description of the query
cypherThe query itself in Neo4j format
msg_templateJinja2 template for the terminal output based on cypher variables, use aliases for Neo4j variables to avoid Jinja attempting to render as nested variables

Dynamic Parameters in Cypher (Jinja2 params.*)

The program uses Jinja2 to render Cypher. Define runtime parameters with the set command and reference them in YAML as {{ params.<key> }}.

CLI

set <key> <value...> # e.g., set user [email protected]
unset <key> # optional
show # optional

YAML Example

- group: user
  desc: List all privileges for this user
  cypher: |-
    MATCH (n:User)-[r]->(m)
    WHERE n.name =~ '((?i){{ params.user }})'
    RETURN n.name AS n_name, TYPE(r) AS rel_type, labels(m) AS labels_m, m.name AS m_name
    ORDER BY TYPE(r)
  msg_template: |-
    User {{ n_name }} has {{ rel_type }} over {{ m_name }} ({{ labels_m[0] }}/{{ labels_m[1] }})

Common Param Patterns

Param keyExample valueUse in Cypher
params.user[email protected]= {{ params.user }}
params.user_regex(?i)john\.doe(@example\.com)?=~ '{{ params.user_regex }}'
params.groupDomain [email protected]= {{ params.group }}
params.prefixACME-STARTS WITH {{ params.prefix }}

JSON Format

This repository provides a query-importer.py script to automate importing queries into the BloodHound CE UI from a JSON file. bh_query_converter.py has also been provided to convert a YAML file intended for the terminal application to the JSON format expected by query-importer.py & BloodHound CE. An example of the required JSON format can be seen below:

{
  "queries": [
    {
      "name": "List all AddKeyCredentialLink privileges for owned principals",
      "description": "List all AddKeyCredentialLink privileges for owned principals - General",
      "query": "MATCH p=(n {owned: true})-[r:AddKeyCredentialLink]->(m)\nRETURN p\nORDER BY n.name"
    },
    {
      "name": "List all AddKeyCredentialLink privileges for Users, Domain Users, Authenticated Users, and Everyone groups",
      "description": "List all AddKeyCredentialLink privileges for Users, Domain Users, Authenticated Users, and Everyone groups - General",
      "query": "MATCH p=(n:Group)-[r:AddKeyCredentialLink]->(m)\nWHERE (n.objectid =~ \"(?i)S-1-5-21-.*-513\" OR n.objectid =~ \"(?i).*-S-1-5-11\" OR n.objectid =~ \"(?i).*-S-1-1-0\" OR n.objectid =~ \"(?i).*-S-1-5-32-545\")\nRETURN p\nORDER BY n.name"
    }
  ]
}

Commands

The full command menu is shown below:

Download Tool