E-AZU
AzureHound
Go-based data collector that maps Entra ID and Azure Resource Manager relationships into BloodHound for attack-path analysis.
OVERVIEW
AzureHound (github.com/SpecterOps/AzureHound) is the official data collector that feeds BloodHound with Azure and Entra ID data — the cloud-identity counterpart to SharpHound on-prem. Written in Go, it authenticates against a tenant with a supplied credential (username/password, refresh token, JWT, or a reused `az login` session) and walks the Microsoft Graph and Azure Resource Manager APIs to enumerate users, groups, applications, service principals, devices, directory roles, subscriptions, and management-group relationships.
The tool was originally released as BloodHoundAD/AzureHound and is now maintained under the SpecterOps org alongside BloodHound itself. Once imported into BloodHound, the collected graph surfaces privilege-escalation and lateral-movement paths that stay invisible when each Entra ID object is reviewed on its own — for example a low-privileged user who can reset the password of an Application Administrator, who in turn controls a service principal with Owner rights over a subscription.
USE CASES
Practical use cases
- 01
Mapping Entra ID role assignments, group memberships, and PIM-eligible roles for attack-path analysis in BloodHound.
- 02
Discovering paths from a compromised user or service principal to Global Administrator or subscription Owner.
- 03
Enumerating app registrations and service principal credentials alongside their downstream Azure RM permissions.
- 04
Feeding a tenant-wide identity graph into BloodHound Community Edition or Enterprise for ongoing purple-team review.
QUICK START
Once BloodHound Community Edition or Enterprise is deployed, to collect a tenant's Entra ID and Azure RM identity graph for attack-path analysis.
- Download the `azurehound` binary for your platform from the SpecterOps/AzureHound GitHub releases.
- Authenticate with a client-provided credential — username/password, refresh token, or an existing `az login` session.
- Run `azurehound list` against the tenant to collect users, groups, apps, devices, roles, and RM relationships to a JSON file.
- Import the JSON output into BloodHound Community Edition or Enterprise and run the built-in attack-path queries.
azurehound list -u "$AZ_USER" -p "$AZ_PASS" -t "$AZ_TENANT" -o azurehound.jsonBEFORE YOU RUN IT
What to check before running it
Every Graph and Azure RM call `azurehound` makes shows up in Entra ID sign-in logs and Azure Activity Log under the identity used — agree with the client on expected volume before a full tenant collection.
The exported graph maps every privilege-escalation path in the tenant, including credentials and role relationships — handle and store the output under the engagement's data-handling rules, not on a personal machine.
Use a client-provisioned, scoped credential with an expiry rather than a personal or standing admin account, and confirm with the client whether Conditional Access or risk-based sign-in policies will flag the collection.