BloodHound AISAFE
BloodHound-MCP-AI is integration that connects BloodHound with AI through Model Context Protocol, allowing security professionals to analyze Active Directory attack paths using natural language instead of complex Cypher queries.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Model Context Protocol (MCP) Server for BloodHound
BloodHound-MCP is a powerful integration that brings the capabilities of Model Context Procotol (MCP) Server to BloodHound, the industry-standard tool for Active Directory security analysis. This integration allows you to analyze BloodHound data using natural language, making complex Active Directory attack path analysis accessible to everyone.
🥇 First-Ever BloodHound AI Integration! This is the first integration that connects BloodHound with AI through MCP, originally announced here.
🔍 What is BloodHound-MCP?
BloodHound-MCP combines the power of:
- BloodHound: Industry-standard tool for visualizing and analyzing Active Directory attack paths
- Model Context Protocol (MCP): An open protocol for creating custom AI tools, compatible with various AI models
- Neo4j: Graph database used by BloodHound to store AD relationship data
With over 75 specialized tools based on the original BloodHound CE Cypher queries, BloodHound-MCP allows security professionals to:
- Query BloodHound data using natural language
- Discover complex attack paths in Active Directory environments
- Assess Active Directory security posture more efficiently
- Generate detailed security reports for stakeholders
📱 Community
Join our Telegram channel for updates, tips, and discussion:
- Telegram: root_sec
🌟 Star History
[](https://www.star-history.com/#MorDavid/BloodHound-MCP-AI&Date)
✨ Features
- Natural Language Interface: Query BloodHound data using plain English
- Comprehensive Analysis Categories:
- Domain structure mapping
- Privilege escalation paths
- Kerberos security issues (Kerbero
0224c0cdad38OBSERVED · 2026-10-02Exposed tools (75)
75 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
find_all_domain_admins | read | query = |
find_all_kerberoastable_users | read | query = |
find_asreproast_users | read | query = |
find_ca_administrators | read | query = |
find_certificate_enrollment_rights | read | query = |
find_computers_in_protected_users | read | query = |
find_computers_no_smb_signing | read | query = |
find_computers_outbound_ntlm_deny | read | query = |
find_computers_webclient_running | read | query = |
find_dcs_vulnerable_ntlm_relay | read | query = |
find_dcs_weak_certificate_binding | read | query = |
find_dcsync_privileges | read | query = |
find_devices_unsupported_os | read | query = |
find_disabled_azure_tier_zero_principals | read | query = |
find_disabled_tier_zero_principals | read | query = |
find_domain_admin_non_dc_logons | read | query = |
find_domain_users_high_value_paths | read | query = |
find_domain_users_laps_readers | read | query = |
find_domain_users_local_admins | read | query = |
find_domain_users_privileges | read | query = |
find_domain_users_server_rdp | read | query = |
find_domain_users_workstation_rdp | read | query = |
find_domains_with_machine_quota | read | query = |
find_enrollment_agent_templates | read | query = |
find_entra_users_in_domain_admins | read | query = |
find_esc1_vulnerable_templates | read | query = |
find_esc2_vulnerable_templates | read | query = |
find_esc8_vulnerable_cas | read | query = |
find_external_tier_zero_users | read | query = |
find_foreign_group_memberships | read | query = |
find_foreign_tier_zero_principals | read | query = |
find_global_administrators | read | query = |
find_high_privileged_role_members | read | query = |
find_inactive_tier_zero_principals | read | query = |
find_kerberoastable_most_admin | read | query = |
find_kerberoastable_tier_zero | read | query = |
find_nested_tier_zero_groups | read | query = |
find_ntlm_relay_edges | read | query = |
find_onprem_users_in_entra_groups | read | query = |
find_onprem_users_owning_entra_objects | read | query = |
find_paths_from_azure_apps_to_tier_zero | read | query = |
find_paths_from_domain_users_to_tier_zero | read | query = |
find_paths_from_entra_to_tier_zero | read | query = |
find_paths_from_kerberoastable_to_da | read | query = |
find_paths_from_owned_objects | read | query = |
find_paths_to_azure_subscriptions | read | query = |
find_paths_to_privileged_roles | read | query = |
find_pki_hierarchy | read | query = |
find_principals_des_only_kerberos | read | query = |
find_principals_reversible_encryption | read | query = |
find_principals_weak_kerberos_encryption | read | query = |
find_public_key_services | read | query = |
find_shortest_paths_to_domain_admins | read | query = |
find_shortest_paths_to_tier_zero | read | query = |
find_shortest_paths_unconstrained_delegation | read | query = |
find_smartcard_dont_expire_domains | read | query = |
find_sp_graph_assignments | read | query = |
find_synced_tier_zero_principals | read | query = |
find_tier_zero_locations | read | query = |
find_tier_zero_non_expiring_passwords | read | query = |
find_tier_zero_without_smartcard | read | query = |
find_two_way_forest_trust_delegation | read | query = |
find_unsupported_operating_systems | read | query = |
find_users_password_not_rotated | read | query = |
find_users_with_no_password_required | read | query = |
map_domain_trusts | read | query = |
map_ou_structure | read | query = |
onprem_users_direct_azure_roles | read | query = |
onprem_users_direct_entra_roles | read | query = |
onprem_users_group_azure_roles | read | query = |
onprem_users_group_entra_roles | read | query = |
query_bloodhound | read | databases = [ |
sp_app_role_grant | read | query = |
templates_no_security_ext | read | query = |
templates_with_user_san | read | query = |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (3)
OR 'RC4-HMAC-MD5' IN u.supportedencryptiontypes
neo4j, python-dotenv, mcp-server, fastmcp
Gates applied: no_behavioural_pass, no_license.
0224c0cdad38full audit observations/trust-audit/mcp-server/mordavid__bloodhound-ai.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-02 | 0224c0cdad38 | SAFE | B | 89 | first audit |
Questions
What is the BloodHound AI MCP server?
BloodHound-MCP-AI is integration that connects BloodHound with AI through Model Context Protocol, allowing security professionals to analyze Active Directory attack paths using natural language instead of complex Cypher queries.
What tools does BloodHound AI expose?
75 in total: 75 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is BloodHound AI safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does BloodHound AI need?
It reads BLOODHOUND_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does BloodHound AI run?
It speaks stdio, so it runs as a local process your client starts.
How current is this page?
The grade is for one exact copy of the source (0224c0cdad38), read on 2026-10-02. The repository is watched and re-audited when it changes.