bhe_mcp
Related Servers
Alternatives to bhe_mcp
No user-submitted related servers found.
Related Servers
- AlicenseBqualityBmaintenanceEnables security professionals to query and analyze Active Directory attack paths from BloodHound Community Edition data using natural language through Claude Desktop's Model Context Protocol interface.79132GPL 3.0
- FlicenseBqualityCmaintenanceEnables users to query BloodHound Active Directory graph data using natural language, finding attack paths, Kerberoastable accounts, and other AD security insights.23-
- FlicenseCqualityDmaintenanceAn extension that allows Large Language Models to interact with and analyze Active Directory environments through natural language queries instead of manual Cypher queries.100160-
- AlicenseNot gradedqualityCmaintenanceAn MCP server that enables LLMs to query and reason over Active Directory attack graphs collected by BloodHound, providing attack paths, blast radius analysis, choke points, and defender remediation advice.MIT
- AlicenseNot gradedqualityAmaintenanceEnables natural language threat hunting and incident response by connecting LLMs to enterprise security data sources like Elasticsearch, EVTX logs, PCAP files, and Velociraptor.206GPL 3.0
- AlicenseCqualityDmaintenanceEnables LLMs to perform Active Directory penetration testing using tools like NetExec, Bloodhound, Nmap, Certipy, and John the Ripper. Automates vulnerability discovery, attack path analysis, and documentation generation for security assessments.266MIT
TDQS
Scored across 20 tools
Most tools target distinct entity types or domains (group, user, computer, domain, GPO, OU, ADCS, etc.), but there is some potential confusion between graph_analysis and cypher_query (both can explore paths) and between enterprise_info, operations_info, and collection_info which all deal with BHE system metadata. Descriptions are detailed enough to disambiguate in most cases.
Tool names are all snake_case and readable, but there is no consistent verb_noun pattern. Many use an '_info' suffix (group_info, user_info, computer_info), while others are noun phrases (asset_groups, attack_paths, cypher_query) or verb phrases (file_upload). This mix is acceptable but not a uniform convention.
20 tools is on the higher end but appropriate given the breadth of the BloodHound Enterprise API. Each tool covers a distinct functional area, and many pack multiple sub-operations via info_type, so the count is justified without being excessive.
The tool set covers major BloodHound domains: entity queries, graph analysis, cypher execution, attack paths, enterprise admin, file upload, collection status, and data quality. Minor gaps exist, such as limited Azure entity support and missing some niche BHE endpoints, but the surface is generally comprehensive for common workflows.