> ## Documentation Index
> Fetch the complete documentation index at: https://specterops-feat-poc-api-playground.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# OpenGraph Library

> List of the OpenGraph models available to the community

export const SO_Icon_Inline = ({size = 20}) => {
  return <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 171.1 186.1" width={size} height={size} style={{
    display: 'inline-block',
    verticalAlign: 'middle',
    margin: '0 4px'
  }}>
            <polygon fill="var(--brand-green)" points="58.4 77.3 58.4 83.9 63.1 89.6 78.3 90.3 78.3 77.3 68.2 71.6 58.4 77.3" />
            <polygon fill="var(--brand-green)" points="92.3 77.3 92.3 90.5 107.2 89.6 112.3 83.9 112.3 77.3 102.2 71.6 92.3 77.3" />
            <path fill="var(--brand-light)" d="M141.4 125.2l.1-.1V60.9l-17.3-9.7-13-7.3-25.6-14.3-25.2 14.3-13 7.4-3.2 1.8-12.1-7.1 4-2.3 19-10.9 30.2-17.2 30.8 17.3 19 10.7 18.4 10.3 13.7-7.9v-.1l-25.4-14.2-19-10.7L85.3 0 48.4 21.1l-19 10.9-24.4 13.9v.3l25.8 14.8v63.7l55.4 31.9 41.7-23.6 12 7.1-53.6 30.3-67.4-38.8-13.7 7.9 81 46.6 67.3-38.1 13.9-7.9v-.1l-13.8-7.8-12.2-7Zm-13.5-7.8l-41.7 23.6-41.8-24.2v-48l9.8-5.6 13-7.4 18.4-10.5 18.9 10.6 13 7.3 10.4 5.8v48.4Z" />
            <polygon fill="var(--brand-light)" points="156.6 118 171.1 125.4 171.1 60.2 156.6 68.4 156.6 118" />
            <polygon fill="var(--brand-light)" points="14.6 68.4 0 60.2 0 125.4 14.6 118 14.6 68.4" />
        </svg>;
};

export const SO_Icon = ({size = 20}) => {
  return <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 171.1 186.1" width={size} height={size}>
            <polygon fill="var(--brand-green)" points="58.4 77.3 58.4 83.9 63.1 89.6 78.3 90.3 78.3 77.3 68.2 71.6 58.4 77.3" />
            <polygon fill="var(--brand-green)" points="92.3 77.3 92.3 90.5 107.2 89.6 112.3 83.9 112.3 77.3 102.2 71.6 92.3 77.3" />
            <path fill="var(--brand-light)" d="M141.4 125.2l.1-.1V60.9l-17.3-9.7-13-7.3-25.6-14.3-25.2 14.3-13 7.4-3.2 1.8-12.1-7.1 4-2.3 19-10.9 30.2-17.2 30.8 17.3 19 10.7 18.4 10.3 13.7-7.9v-.1l-25.4-14.2-19-10.7L85.3 0 48.4 21.1l-19 10.9-24.4 13.9v.3l25.8 14.8v63.7l55.4 31.9 41.7-23.6 12 7.1-53.6 30.3-67.4-38.8-13.7 7.9 81 46.6 67.3-38.1 13.9-7.9v-.1l-13.8-7.8-12.2-7Zm-13.5-7.8l-41.7 23.6-41.8-24.2v-48l9.8-5.6 13-7.4 18.4-10.5 18.9 10.6 13 7.3 10.4 5.8v48.4Z" />
            <polygon fill="var(--brand-light)" points="156.6 118 171.1 125.4 171.1 60.2 156.6 68.4 156.6 118" />
            <polygon fill="var(--brand-light)" points="14.6 68.4 0 60.2 0 125.4 14.6 118 14.6 68.4" />
        </svg>;
};

<img noZoom src="https://mintcdn.com/specterops-feat-poc-api-playground/5XJ7p5p7xL9ZwxE2/assets/enterprise-AND-community-edition-pill-tag.svg?fit=max&auto=format&n=5XJ7p5p7xL9ZwxE2&q=85&s=79b8dea14cb2266671c0a2f64f4b9caa" alt="Applies to BloodHound Enterprise and CE" width="482" height="45" data-path="assets/enterprise-AND-community-edition-pill-tag.svg" />

The OpenGraph library provides a list of projects created by BloodHound community members that extend the coverage of BloodHound utilizing OpenGraph.

Have you built a cool project using OpenGraph and want it featured here? Already got your project in the list and need to update something? Open a ["Library Change" issue](https://github.com/SpecterOps/bloodhound-docs/issues) on the BloodHound Docs repo and we'll get it added for you!

Submissions from the community will have a <Icon icon="people-group" color="#ffffff" size={18} /> icon next to them while those by SpecterOps employees will have a <SO_Icon_Inline size={18} /> SpecterOps icon.

## OpenGraph Library

<Warning>
  All code linked via this library is provided “as is,” without review, approval, or endorsement by SpecterOps, regardless of authorship. It has not been audited for accuracy, security, or fitness for any purpose. Use at your own risk. You are solely responsible for testing, validating, and ensuring the code meets your requirements before use in any environment. SpecterOps is not responsible for any damages, losses, or security issues arising from the use of any linked code.
</Warning>

<AccordionGroup>
  <Accordion title="1Password" icon={<SO_Icon />}>
    #### <SO_Icon_Inline size={22} /> 1PassHound

    **Description**

    The 1Password for Business OpenGraph extension lets you bring your [1Password](https://1password.com/) ACL data into BloodHound’s graph‑analysis framework.

    Whether you’re auditing permissions, responding to incidents, or simply exploring your 1Password configuration, this extension brings clarity, control and rich visualization to your vaults and items.

    **Authors/Maintainers**

    * [Jared Atkinson](https://x.com/jaredcatkinson) @[SpecterOps](https://specterops.io)

    **Repo**

    * [https://github.com/SpecterOps/1PassHound](https://github.com/SpecterOps/1PassHound)
  </Accordion>

  <Accordion title="Ansible" icon="people-group">
    #### <Icon icon="people-group" size={22} /> AnsibleHound

    **Description**

    AnsibleHound is a BloodHound OpenGraph collector for [Ansible AWX](https://github.com/ansible/awx) and [Ansible Tower](https://docs.ansible.com/ansible-tower/). The collector is designed to map the structure and permissions of your organization into a navigable attack-path graph.

    **Authors/Maintainers**

    * [Ramoreik](https://github.com/Ramoreik)
    * [s-lck](https://github.com/s-lck)

    **Repo**

    * [https://github.com/TheSleekBoyCompany/AnsibleHound](https://github.com/TheSleekBoyCompany/AnsibleHound)
  </Accordion>

  <Accordion title="Amazon Web Service (AWS)" icon="people-group">
    #### <Icon icon="people-group" size={22} /> IAMhounddog

    **Description**

    A tool to help pentesters quickly identify privileged principals and second-order privilege escalation opportunities in unfamiliar AWS environments. Creates OpenGraph-compatible IAM to resource models that can be ingested and used in BloodHound CE along with pre-written queries to identify common misconfigurations.

    **Authors/Maintainers**

    * [Nathan Tucker](https://github.com/vntucker) @[Virtue Security](https://www.virtuesecurity.com/)

    **Repo**

    * [https://github.com/VirtueSecurity/IAMhounddog](https://github.com/VirtueSecurity/IAMhounddog)
  </Accordion>

  <Accordion title="Entra ID" icon={<SO_Icon />}>
    #### <SO_Icon_Inline size={22} /> EntraAuthPolicyHound

    **Description**

    This PoC community project provides a sample `PowerShell` script that collects Microsoft Entra ID permissions related to [Temporary Access Passes (TAPs)](https://learn.microsoft.com/en-us/entra/identity/authentication/howto-authentication-temporary-access-pass) and [Passkeys (FIDO2 security keys or mobile devices)](https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-enable-passkey-fido2) and exports the data in [BloodHound OpenGraph](https://specterops.io/opengraph/) format.

    **Authors/Maintainers**

    * [Michael Grafnetter](https://x.com/mgrafnetter) @[SpecterOps](https://specterops.io)

    **Repo**

    * [https://github.com/MichaelGrafnetter/EntraAuthPolicyHound](https://github.com/MichaelGrafnetter/EntraAuthPolicyHound)

    #### <SO_Icon_Inline size={22} /> EntraSSSOHound

    **Description**

    Entra ID Seamless Single Sign-On (Seamless SSO) is a feature that non-interactively signs users into cloud applications whenever they are connected to Active Directory. EntraSSSOHound extends BloodHound CE with OpenGraph-format coverage, modeling how Active Directory computers can compromise synced Entra ID users through the trust established between the trusted on-premises computer and Entra ID.

    **Authors/Maintainers**

    * [Daniel Heinsen](https://x.com/hotnops) @[SpecterOps](https://specterops.io)

    **Repo**

    * [https://github.com/SpecterOps/EntraSSSOHound](https://github.com/SpecterOps/EntraSSSOHound)
  </Accordion>

  <Accordion title="GitHub" icon={<SO_Icon />}>
    #### <SO_Icon_Inline size={22} /> GitHound

    **Description**

    GitHound is a BloodHound OpenGraph collector for [GitHub](https://github.com), designed to map your organization’s structure and permissions into a navigable attack‑path graph.

    With GitHound, you get a clear, interactive graph of your GitHub permissions landscape—perfect for security reviews, compliance audits, and rapid incident investigations.

    **Authors/Maintainers**

    * [Jared Atkinson](https://x.com/jaredcatkinson) @[SpecterOps](https://specterops.io)

    **Repo**

    * [https://github.com/SpecterOps/GitHound](https://github.com/SpecterOps/GitHound)

    #### <Icon icon="people-group" size={22} /> GitHoundPy

    **Description**

    A python implementation of the GitHound collector for BloodHound OpenGraph. This project aims to stay in sync with the main PowerShell version.

    Credit and tons of props to the SpecterOps team for the main implementation, for a detailed breakdown on the features check the main [repo](https://github.com/SpecterOps/GitHound)

    **Authors/Maintainers**

    * [Derrick Polakoff](https://www.linkedin.com/in/derrick-polakoff-54a34a237) @[CorvraLabs](https://github.com/CorvraLabs)

    **Repo**

    * [https://github.com/CorvraLabs/GitHoundPy](https://github.com/CorvraLabs/GitHoundPy)
  </Accordion>

  <Accordion title="Google Cloud Platform (GCP)" icon="people-group">
    #### <Icon icon="people-group" size={22} /> GCP-Hound

    **Description**

    GCP-Hound is an open-source security enumeration and privilege escalation discovery tool designed specifically for Google Cloud Platform environments. Built to integrate seamlessly with BloodHound's OpenGraph framework, it transforms complex GCP IAM relationships into interactive attack graphs.

    **Authors/Maintainers**

    * [Faiz Karim](https://in.linkedin.com/in/faiz-karim-8421bb195)

    **Repo**

    * [https://github.com/F41zK4r1m/GCP-Hound](https://github.com/F41zK4r1m/GCP-Hound)
  </Accordion>

  <Accordion title="Jamf" icon={<SO_Icon />}>
    #### <SO_Icon_Inline size={22} /> JamfHound

    **Description**

    JamfHound is a python3 project designed to collect and identify attack-paths in [Jamf Pro](https://www.jamf.com/products/jamf-pro/) tenants for privilege escalation and lateral movement based on existing object permissions. The collector saves data as JSON for ingestion into BloodHound to easily visualize and evaluate the risks of compromise within the Jamf Pro tenant.

    **Authors/Maintainers**

    * [Lance Cain](https://www.linkedin.com/in/lance-cain-3ab262184) @[SpecterOps](https://specterops.io)

    **Repo**

    * [https://github.com/SpecterOps/jamfhound](https://github.com/SpecterOps/jamfhound)
  </Accordion>

  <Accordion title="Kubernetes" icon={<SO_Icon />}>
    #### <SO_Icon_Inline size={22} /> OpenGraph DLT

    **Description**

    A lightweight CLI for collecting service-specific resources and turning it into OpenGraph/BloodHound datasets. The long–term goal is to plug in multiple collectors; Kubernetes is the first source and serves as the reference implementation for future integrations. The kubernetes collector makes use of an (embedded) DuckDB database, which may not be needed for your usecase.

    **Authors/Maintainers**

    * [Joey Dreijer](https://github.com/d3vzer0) @[SpecterOps](https://specterops.io)

    **Repo**

    * [https://github.com/d3vzer0/OpenGraph-dlt](https://github.com/d3vzer0/OpenGraph-dlt)
  </Accordion>

  <Accordion title="MSSQL" icon={<SO_Icon />}>
    #### <SO_Icon_Inline size={22} /> MSSQLHound

    **Description**

    Collects BloodHound OpenGraph compatible data from one or more [MSSQL](https://www.microsoft.com/en-us/sql-server) servers into individual temporary files, then zips them in the current directory.

    **Authors/Maintainers**

    * [Chris Thompson](https://x.com/_Mayyhem) @[SpecterOps](https://specterops.io)

    **Repo**

    * [https://github.com/SpecterOps/MSSQLHound](https://github.com/SpecterOps/MSSQLHound)
  </Accordion>

  <Accordion title="Network" icon="people-group">
    #### <Icon icon="people-group" size={22} /> NetworkHound

    **Description**

    NetworkHound connects to Active Directory Domain Controllers, discovers computer objects, resolves hostnames to IP addresses using multiple DNS methods, performs comprehensive network scanning (port scanning, HTTP/HTTPS validation), and discovers shadow-IT devices. It then builds a detailed network topology graph in OpenGraph JSON format compatible with BloodHound.

    **Authors/Maintainers**

    * [Mor David](https://x.com/m0rd4vid) @[mordavid.com](https://www.mordavid.com/)

    **Repo**

    * [https://github.com/mordavid/NetworkHound](https://github.com/mordavid/NetworkHound)
  </Accordion>

  <Accordion title="SCCM" icon="people-group" size={22}>
    #### <Icon icon="people-group" size={22} /> SCCM\_SQL\_Collector

    **Description**

    PoC script to collect SCCM attack paths from a SCCM site DB. Credits to [@sanjivkawa](https://x.com/sanjivkawa) for SQLRecon, which is where most of the scaffolding code to allow for connecting to SQL came from (thanks Sanj!)

    **Authors/Maintainers**

    * [Dave Cossa](https://x.com/G0ldenGunSec)

    **Repo**

    * [https://github.com/G0ldenGunSec/SCCM\_SQL\_Collector](https://github.com/G0ldenGunSec/SCCM_SQL_Collector)
  </Accordion>

  <Accordion title="Snowflake" icon={<SO_Icon />}>
    #### <SO_Icon_Inline size={22} /> SnowHound

    **Description**

    The BloodHound extension for [Snowflake](https://www.snowflake.com/) tenants enables organizations to visualize their Snowflake environment by mapping key elements such as Users, Databases, Roles, Warehouses, and Integrations, along with the permissions that connect them.

    This provides a comprehensive view of access and potential attack paths within the Snowflake tenant, empowering security teams to identify vulnerabilities and better manage their environment's security posture.

    **Authors/Maintainers**

    * [Jared Atkinson](https://x.com/jaredcatkinson) @[SpecterOps](https://specterops.io)

    **Repo**

    * [https://github.com/SpecterOps/SnowHound](https://github.com/SpecterOps/SnowHound)
  </Accordion>

  <Accordion title="vCenter" icon="people-group">
    #### <Icon icon="people-group" size={22} /> vCenterHound

    **Description**

    vCenterHound connects to one or more [vCenters](https://www.vmware.com/products/cloud-infrastructure/vcenter/future-overview), collects infrastructure entities (Datacenter/Cluster/Host/VM/Network/Datastore, etc.) and permissions (Roles/Users/Groups/Assignments), then builds a BloodHound‑compatible JSON graph with Custom Nodes/Edges. The model.json file provides icons and styles for these custom kinds.

    **Authors/Maintainers**

    * [Mor David](https://x.com/m0rd4vid) @[mordavid.com](https://www.mordavid.com/)

    **Repo**

    * [https://github.com/MorDavid/vCenterHound](https://github.com/MorDavid/vCenterHound)
  </Accordion>
</AccordionGroup>

## OpenGraph Tools

#### <SO_Icon_Inline size={22} /> bhopengraph

**Description**

This module provides Python classes for creating and managing graph structures that are compatible with BloodHound OpenGraph. The classes follow the BloodHound OpenGraph schema and best practices.

If you don't know about BloodHound OpenGraph yet, a great introduction can be found here: [https://bloodhound.specterops.io/opengraph/best-practices](https://bloodhound.specterops.io/opengraph/best-practices)

The complete documentation of this library can be found here: [https://bhopengraph.readthedocs.io/en/latest/](https://bhopengraph.readthedocs.io/en/latest/)

**Authors/Maintainers**

* [Remi Gascou](https://x.com/podalirius_)

**Repo**

* [https://github.com/p0dalirius/bhopengraph](https://github.com/p0dalirius/bhopengraph)

#### <SO_Icon_Inline size={22} /> BloodHoundOperator

**Description**
PowerShell client for BloodHound Community Edition and BloodHound Enterprise

Learn more:

* Release blog post: BloodHound Operator — Dog Whispering Reloaded
* Presentation at PowerShell Conference Europe: The Dog Ate My Homework - A new chapter in my BloodHound adventures with PowerShell

**Authors/Maintainers**

* [SadProcessor](https://x.com/sadprocessor)

**Repo**

* [https://github.com/SadProcessor/BloodHoundOperator](https://github.com/SadProcessor/BloodHoundOperator)

#### <Icon icon="people-group" size={22} /> BloodHound OpenGraph Helper Library

**Description**

A Python library for creating BloodHound OpenGraph JSON data that conforms to the BloodHound OpenGraph [schema specification](/opengraph/schema).

**Authors/Maintainers**

* [Luke Roberts](https://x.com/rookuu_)

**Repo**

* [https://github.com/rookuu/bloodhound-opengraph](https://github.com/rookuu/bloodhound-opengraph)
