BloodHound MCP
Related Servers
Alternatives to BloodHound MCP
No user-submitted related servers found.
Related Servers
- AlicenseAqualityDmaintenanceConnects LLMs to BloodHound Enterprise for natural language attack path analysis, Cypher queries, and exploration of Active Directory, Azure/Entra ID, and OpenGraph environments.20GPL 3.0
- FlicenseBqualityCmaintenanceEnables users to query BloodHound Active Directory graph data using natural language, finding attack paths, Kerberoastable accounts, and other AD security insights.23-
- AlicenseBqualityBmaintenanceEnables security professionals to query and analyze Active Directory attack paths from BloodHound Community Edition data using natural language through Claude Desktop's Model Context Protocol interface.79136GPL 3.0
- AlicenseNot gradedqualityDmaintenanceEnables managing Active Directory users, groups, and computers using natural language, with support for queries and updates.57MIT
- AlicenseNot gradedqualityDmaintenanceAn MCP server that enables LLMs to query and reason over Active Directory attack graphs collected by BloodHound, providing attack paths, blast radius analysis, choke points, and defender remediation advice.MIT
- AlicenseCqualityDmaintenanceEnables LLMs to perform Active Directory penetration testing using tools like NetExec, Bloodhound, Nmap, Certipy, and John the Ripper. Automates vulnerability discovery, attack path analysis, and documentation generation for security assessments.266MIT
TDQS
Scored across 106 tools
Many tools have overlapping purposes and unclear boundaries, causing significant ambiguity. For example, there are multiple 'list' tools for similar user attributes (e.g., list_enabled_users_with_password_never_expires vs list_enabled_users_pwd_never_expires_unchanged_1yr) and numerous 'route' tools with similar dangerous rights targeting different node types, making it difficult for an agent to distinguish between them without deep domain knowledge.
The naming is mixed with some consistency but notable deviations. Most tools follow a verb_noun pattern (e.g., list_all_gpos, find_all_enabled_as_rep_roastable_users), but there are inconsistencies like abbreviations (e.g., list_own_en_usrs_local_adm_sess), varying verb styles (find vs list vs route), and occasional use of underscores inconsistently, reducing predictability.
With 106 tools, the count is excessive and feels heavy for the domain of BloodHound (security analysis and Active Directory/Azure reconnaissance). This large number suggests over-fragmentation and redundancy, making it overwhelming for agents to navigate and likely including many tools that could be consolidated or parameterized.
The tool set appears highly complete for the BloodHound domain, covering a wide range of security analysis tasks such as listing, finding, and routing across users, groups, computers, certificates, and Azure resources. There are minor gaps (e.g., some tools marked as [WIP] or requiring specific data like sessions or azurehound), but overall, it provides extensive coverage for attack path discovery and privilege escalation scenarios.