Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Dop2Mop — OpenGraph collector for BloodHound that maps attack paths from DevOps to MLOps infrastructure, collecting CI/CD pipeline, service principal, and ML platform resources for lateral movement analysis. | Kitploit
Tools/GitHubGitHub/h4wkst3r/dop2mop
Cloud Infrastructure SecurityReconnaissanceContainer SecurityVulnerability AnalysisInformation GatheringPenetration TestingCloud SecurityDevSecOpsIdentity & Access Management (IAM)Supply Chain SecurityRed Teaming
41215 months agoNot yet reviewed
GitHubh4wkst3r/dop2mop

Dop2Mop

OpenGraph collector for BloodHound that maps attack paths from DevOps to MLOps infrastructure, collecting CI/CD pipeline, service principal, and ML platform resources for lateral movement analysis.

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Dop2Mop

A proof-of-concept OpenGraph collector for BloodHound that maps attack paths from DevOps to MLOps infrastructure.

Based on Pipelines of Privilege: Attack Paths from DevOps to MLOps Infrastructure by Brett Hawkins (@h4wkst3r).

Table of Contents

  • Acknowledgments
  • Overview
    • Supported Platforms
    • Trust Boundaries Mapped
  • Installation
    • Optional Dependencies
  • Quick Start
    • Generate Demo Data
    • Ingest into BloodHound
  • Configuration
    • Config File
    • Credential Validation
  • CLI Reference
    • Commands Overview
    • Global Options
    • dop2mop collect
    • dop2mop demo
  • CLI Usage Examples
    • Basic Collection
    • Single Platform Collection
    • Multiple Platform Collection
    • GitHub Collection Examples
    • Azure DevOps Collection Examples
    • Azure ML Collection Examples
    • AWS SageMaker Collection Examples
    • Full Environment Collection
  • Environment Variables
  • Node Types
    • DevOps Nodes
    • MLOps Nodes
    • Identity Nodes
    • Artifact Nodes
  • Edge Types
    • Attack Path Edges
    • Structural Edges
  • Example Queries
  • Custom Icons
    • Uploading Icons to BloodHound
  • Python API
    • Using Individual Collectors
    • Building Custom Graphs
  • Troubleshooting
    • Common Issues
  • License

Acknowledgments

  • SpecterOps for BloodHound and OpenGraph

Overview

Dop2Mop collects data from DevOps and MLOps platforms to identify attack paths that enable lateral movement from CI/CD pipelines to machine learning training infrastructure. It outputs BloodHound-compatible OpenGraph JSON for visualization and analysis.

Supported Platforms

DevOps PlatformsMLOps PlatformsIdentity Providers
GitHub (Actions, Repos, Secrets)Azure Machine LearningAzure AD Service Principals
Azure DevOps (Pipelines, Service Connections)Amazon SageMakerAWS IAM Roles
OIDC/Federated Identity

Trust Boundaries Mapped

Dop2Mop models the five critical trust boundaries identified in the research:

  1. TB1: Code Repository to CI/CD Pipeline - Automatic triggering of pipelines from code commits
  2. TB2: Service Principal Authentication - NHI credentials used by pipelines to access ML platforms
  3. TB3: Container Artifact Trust - Implicit trust in container images from internal registries
  4. TB4: Job Definition Execution - ML platforms executing job definitions without validation
  5. TB5: Code Deserialization - Unsafe deserialization of datasets (pickle, joblib)

Installation

git clone https://github.com/h4wkst3r/dop2mop.git
cd dop2mop
pip install -r requirements.txt
pip install -e .

What's Collected

Each collector gathers platform-specific resources and maps the trust boundaries between them:

CollectorResources Collected
GitHubOrganizations, repositories, workflows, secrets, branch protection rules, OIDC configurations, container image references, S3 bucket references
Azure DevOpsOrganizations, projects, pipelines (YAML), service connections (with scope details), variable groups, agent pools, repositories
Azure MLWorkspaces, compute clusters/instances, datastores, ML environments, registered models, jobs/experiments, online & batch endpoints
SageMakerTraining jobs, models, endpoints, domains, notebook instances, IAM execution roles (with policy analysis), ECR repositories/images, S3 buckets (filtered to ML-relevant)

Quick Start

Generate Demo Data

The fastest way to see Dop2Mop in action is to generate demo data showing the attack scenarios from the research:

dop2mop demo -o demo.json

Ingest into BloodHound

  1. Open BloodHound CE (v8.0+)
  2. Navigate to Administration → File Ingest
  3. Upload the generated JSON file
  4. Query with Cypher:
// Azure DevOps to Azure ML Lateral Movement
MATCH p=(repo)-[:TriggersPipeline]->(pipeline)-[:UsesServiceConnection]->(svcconn)-[:AuthenticatesAs]->(workspace)-[:CodeExecution]->(compute)
RETURN p

// Container Image Poisoning (Supply Chain Attack)
MATCH p=(workflow)-[:CanPoisonImage]->(image)<-[:PullsImage]-(job)
RETURN p

// OIDC/Federated Identity Abuse (confirmed edges)
MATCH p=(workflow)-[:OIDCTrust]->(oidc)-[:CanAssumeRole]->(role)-[:SubmitsJob]->(job)
RETURN p

// OIDC abuse including inferred paths
MATCH p=(workflow)-[:OIDCTrust]->(oidc)-[:InferredCanAssumeRole]->(role)
RETURN p

// Dataset Poisoning via Pickle Deserialization
MATCH p=(workflow)-[:CanPoisonDataset]->(dataset)<-[:LoadsDataset]-(job)
RETURN p

// Find repos with weak/no branch protection (TB1 exploitable)
MATCH (repo)-[:BypassesProtection]->(repo)
RETURN repo.name, repo.default_branch

// Find overprivileged SageMaker IAM roles
MATCH (role:IAMRole) WHERE role.is_admin = true OR role.has_s3_full_access = true
RETURN role.name, role.attached_policies

// Find SageMaker notebooks with root + internet access
MATCH (nb:SMNotebook) WHERE nb.root_access = 'Enabled' AND nb.direct_internet_access = 'Enabled'
RETURN nb.name, nb.status

// Find self-hosted ADO agent pools
MATCH (agent:ADOAgent) WHERE agent.is_hosted = false
RETURN agent.name, agent.pool_type

Configuration

Config File

Instead of passing credentials on every run, you can save them in a config file. Copy the included example and fill in your values:

cp dop2mop.yaml.example dop2mop.yaml
# Edit dop2mop.yaml with your credentials

Dop2Mop checks these locations in order:

  1. Path specified by --config
  2. dop2mop.yaml / dop2mop.yml / .dop2mop.yaml in the current directory
  3. ~/.dop2mop.yaml

Note: dop2mop.yaml is in .gitignore to prevent accidentally committing credentials. The example file (dop2mop.yaml.example) is safe to commit.

See dop2mop.yaml.example for all available options with comments.

Priority order: CLI arguments > config file > environment variables.

Credential Validation

Test credentials before running a full collection:

# Validate all configured collectors
dop2mop collect --validate -v

# Validate specific collectors
dop2mop collect --validate --collectors github,sagemaker -v

This makes a lightweight API call per platform to verify tokens are valid before starting collection.

Collector Aliases

You can use short names instead of full class names with --collectors:

AliasCollector
github, ghGitHubCollector
ado, azuredevops, azure-devopsAzureDevOpsCollector
azureml, azure-mlAzureMLCollector
sagemaker, smSageMakerCollector
Download Tool