BloodHound MCP
# BloodHound MCP
BloodHound MCP (Model Context Protocol) is an innovative extension of the BloodHound tool, designed to enable Large Language Models (LLMs) to interact with and analyze Active Directory (AD) and Azure Active Directory (AAD) environments through natural language queries. By leveraging the power of LLMs, BloodHound MCP allows users to perform complex queries and retrieve insights from their AD/AAD environments using simple, conversational commands.
## Features
- **Natural Language Queries**: Use conversational language to query your AD/AAD environment without needing to write Cypher queries manually.
- **LLM-Powered Analysis**: Harness the capabilities of Large Language Models to interpret and execute queries on your behalf.
- **Seamless Integration**: Works with existing BloodHound data stored in Neo4j, providing a user-friendly interface for complex analysis.
- **Customizable**: Easily configure the system to work with your specific environment and tools.
## Configure the MCP Server
```json
{
"mcpServers": {
"BloodHound": {
"name": "BloodHound",
"isActive": true,
"command": "uv",
"args": [
"run",
"--with",
"mcp[cli],neo4j",
"mcp",
"run",
"<PATH_TO_THE_PROJECT>server.py"
],
"env": {
"BLOODHOUND_URI": "bolt://localhost:7687",
"BLOODHOUND_USERNAME": "neo4j",
"BLOODHOUND_PASSWORD": "bloodhound"
}
}
}
}
```
## Usage



## Configuration
To customize BloodHound MCP, update the configuration file in your MCP-supported tool. Key settings include:
- Neo4j Database Connection:
- `BLOODHOUND_URI`: The URI of your Neo4j database (e.g., bolt://localhost:7687).
- `BLOODHOUND_USERNAME`: Your Neo4j username.
- `BLOODHOUND_PASSWORD`: Your Neo4j password.
- Server Settings: Adjust the command and args to match your environment and tool requirements.
## Contributing
We welcome contributions to BloodHound MCP! To get involved:
1. Fork the Repository: Create your own copy on GitHub.
2. Create a Branch: Work on your feature or fix in a new branch.
3. Submit a Pull Request: Include a clear description of your changes.
## Special Thanks
Custom queries from : https://github.com/CompassSecurity/BloodHoundQueriesTDQS
Scored across 106 tools
Many tools have overlapping purposes and unclear boundaries, causing significant ambiguity. For example, there are multiple 'list' tools for similar user attributes (e.g., list_enabled_users_with_password_never_expires vs list_enabled_users_pwd_never_expires_unchanged_1yr) and numerous 'route' tools with similar dangerous rights targeting different node types, making it difficult for an agent to distinguish between them without deep domain knowledge.
The naming is mixed with some consistency but notable deviations. Most tools follow a verb_noun pattern (e.g., list_all_gpos, find_all_enabled_as_rep_roastable_users), but there are inconsistencies like abbreviations (e.g., list_own_en_usrs_local_adm_sess), varying verb styles (find vs list vs route), and occasional use of underscores inconsistently, reducing predictability.
With 106 tools, the count is excessive and feels heavy for the domain of BloodHound (security analysis and Active Directory/Azure reconnaissance). This large number suggests over-fragmentation and redundancy, making it overwhelming for agents to navigate and likely including many tools that could be consolidated or parameterized.
The tool set appears highly complete for the BloodHound domain, covering a wide range of security analysis tasks such as listing, finding, and routing across users, groups, computers, certificates, and Azure resources. There are minor gaps (e.g., some tools marked as [WIP] or requiring specific data like sessions or azurehound), but overall, it provides extensive coverage for attack path discovery and privilege escalation scenarios.