Skip to content
KitploitKITPLOIT
उपकरणएक्सप्लॉइटब्लॉग
Log in
जमा करें
उपकरणएक्सप्लॉइटब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

फ़ीडसंपर्कगोपनीयता© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
BloodBash — Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration findings without BloodHound or Neo4j. | Kitploit
उपकरण/GitHubGitHub/squidsec/bloodbash
Privilege EscalationVulnerability AnalysisLateral MovementConfiguration AuditingInformation GatheringPenetration TestingCloud SecurityIdentity & Access Management (IAM)Red Teaming
GitHubsquidsec/bloodbash

BloodBash

Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration findings without BloodHound or Neo4j.

492551201 महीना पहलेKitploit द्वारा समीक्षित

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें
रिपॉजिटरी देखें
अनुरोधित भाषा में सामग्री उपलब्ध नहीं है। अंग्रेज़ी संस्करण दिखाया जा रहा है।

BloodBash

SquidSec logo

A SquidSec Open Source Project
SquidOffense.com · GitHub

Run Unit Tests Build and Release Binaries Latest release License: MIT

BloodBash is an open source offline SharpHound and AzureHound JSON analyzer, created and managed by SquidSec. It builds a graph, surfaces AD/Entra attack paths and misconfigs, and prints prioritized findings. No Neo4j or BloodHound UI required.

OrganizationSquidSec
Websitehttps://squidoffense.com/
App versionv1.4.2
Latest binaryGitHub release
LicenseMIT
Runtime (source)Python 3.9+

Merges to main automatically build Linux and Windows binaries and publish a GitHub Release (tag v1.4.2-build.N).


About SquidSec

BloodBash is built and maintained by SquidSec for the security community - red teamers, pentesters, and defenders who need fast offline AD/Entra analysis without standing up BloodHound infrastructure.

  • Website: https://squidoffense.com/
  • Project: https://github.com/DotNetRussell/BloodBash

Download (no Python required)

Standalone SquidSec BloodBash executables - no Python, pip, or venv needed:

PlatformLatest download
Linux x64bloodbash-linux-x64
Windows x64bloodbash-windows-x64.exe
  • All releases & version tags: https://github.com/DotNetRussell/BloodBash/releases
  • Latest release page: https://github.com/DotNetRussell/BloodBash/releases/latest
# Linux
curl -sL -o bloodbash \
  https://github.com/DotNetRussell/BloodBash/releases/latest/download/bloodbash-linux-x64
chmod +x bloodbash
./bloodbash /path/to/json --all
# Windows (PowerShell)
Invoke-WebRequest -Uri "https://github.com/DotNetRussell/BloodBash/releases/latest/download/bloodbash-windows-x64.exe" `
  -OutFile bloodbash.exe
.\bloodbash.exe C:\path\to\json --all

Install (Python / source)

pipx install git+https://github.com/DotNetRussell/BloodBash

Or from a clone:

git clone https://github.com/DotNetRussell/BloodBash.git
cd BloodBash
python3 -m venv venv && source venv/bin/activate
pip install -r requirements.txt

Dependencies: networkx, rich, tqdm, pyyaml.

Quick start

Start with these 3 (point at a SharpHound/AzureHound directory or .zip):

# 1) Day-0 triage - default when you pass only the data path
bloodbash /path/to/json
# same as:
bloodbash /path/to/json --quick-wins

# 2) Just owned a user - outbound compromise dossier
bloodbash ./sharpout --from-user alice --from-user-export

# 3) Full attack analysis (large env: --fast auto on big graphs)
bloodbash /path/to/json --all --fast
# inventory ladders still opt-in:
bloodbash /path/to/json --all --inventory

From a source checkout, python3 BloodBash.py is equivalent to bloodbash.

# Binary / pipx
./bloodbash /path/to/json
bloodbash /path/to/json --from-user alice --from-user-export

# Multi-collection merge (low-priv + DA zip, multi-domain forest)
bloodbash ./lowpriv.zip --merge ./da.zip ./child-domain.zip --all --fast

Bare directory (no check flags) runs quick-wins triage. Use --all for full attack-path analysis (not inventory), or --wizard for an interactive picker.

Under --all and --quick-wins, empty detector sections are suppressed so the console stays readable. Selective flags still print green "none found" lines for the checks you asked for.

Sample data: SampleSharphoundADData/ and SampleAzurehoundData/.

bloodbash --help            # start-here + cheat sheet
bloodbash --help-advanced   # full flag tables + all examples

More recipes: docs/cookbook.md.

What it finds

टूल डाउनलोड करें