
Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration findings without BloodHound or Neo4j.
A SquidSec Open Source Project
SquidOffense.com ·
GitHub
BloodBash is an open source offline SharpHound and AzureHound JSON analyzer, created and managed by SquidSec. It builds a graph, surfaces AD/Entra attack paths and misconfigs, and prints prioritized findings. No Neo4j or BloodHound UI required.
| Organization | SquidSec |
| Website | https://squidoffense.com/ |
| App version | v1.4.2 |
| Latest binary | |
| License | MIT |
| Runtime (source) | Python 3.9+ |
Merges to main automatically build Linux and Windows binaries and publish a GitHub Release (tag v1.4.2-build.N).
BloodBash is built and maintained by SquidSec for the security community - red teamers, pentesters, and defenders who need fast offline AD/Entra analysis without standing up BloodHound infrastructure.
Standalone SquidSec BloodBash executables - no Python, pip, or venv needed:
| Platform | Latest download |
|---|---|
| Linux x64 | bloodbash-linux-x64 |
| Windows x64 | bloodbash-windows-x64.exe |
# Linux
curl -sL -o bloodbash \
https://github.com/DotNetRussell/BloodBash/releases/latest/download/bloodbash-linux-x64
chmod +x bloodbash
./bloodbash /path/to/json --all
# Windows (PowerShell)
Invoke-WebRequest -Uri "https://github.com/DotNetRussell/BloodBash/releases/latest/download/bloodbash-windows-x64.exe" `
-OutFile bloodbash.exe
.\bloodbash.exe C:\path\to\json --all
pipx install git+https://github.com/DotNetRussell/BloodBash
Or from a clone:
git clone https://github.com/DotNetRussell/BloodBash.git
cd BloodBash
python3 -m venv venv && source venv/bin/activate
pip install -r requirements.txt
Dependencies: networkx, rich, tqdm, pyyaml.
Start with these 3 (point at a SharpHound/AzureHound directory or .zip):
# 1) Day-0 triage - default when you pass only the data path
bloodbash /path/to/json
# same as:
bloodbash /path/to/json --quick-wins
# 2) Just owned a user - outbound compromise dossier
bloodbash ./sharpout --from-user alice --from-user-export
# 3) Full attack analysis (large env: --fast auto on big graphs)
bloodbash /path/to/json --all --fast
# inventory ladders still opt-in:
bloodbash /path/to/json --all --inventory
From a source checkout, python3 BloodBash.py is equivalent to bloodbash.
# Binary / pipx
./bloodbash /path/to/json
bloodbash /path/to/json --from-user alice --from-user-export
# Multi-collection merge (low-priv + DA zip, multi-domain forest)
bloodbash ./lowpriv.zip --merge ./da.zip ./child-domain.zip --all --fast
Bare directory (no check flags) runs quick-wins triage. Use --all for full attack-path analysis (not inventory), or --wizard for an interactive picker.
Under --all and --quick-wins, empty detector sections are suppressed so the console stays readable. Selective flags still print green "none found" lines for the checks you asked for.
Sample data: SampleSharphoundADData/ and SampleAzurehoundData/.
bloodbash --help # start-here + cheat sheet
bloodbash --help-advanced # full flag tables + all examples
More recipes: docs/cookbook.md.