Alternatives to AzureHound
A command-line collector that exports Microsoft Azure and Entra ID data for analysis in BloodHound. The listings below can replace it for an important use case. Each note says what changes if you switch.
The original
AzureHound
A command-line collector that exports Microsoft Azure and Entra ID data for analysis in BloodHound.
Replacements
Listings that take over the same core job as AzureHound.
SharpHound
A C# collector that gathers Active Directory data for attack path analysis in BloodHound.
SharpHound is the C# collector gathering on-premises Active Directory data for BloodHound, where AzureHound covers Azure and Entra ID.
ADRecon
A PowerShell script that gathers Active Directory information and builds an Excel report of the environment.
ADRecon is a PowerShell script that documents an Active Directory domain into an Excel report rather than feeding BloodHound.
Also worth comparing
These listings name AzureHound as their own alternative, so the relationship runs both ways.
CloudFox
Inventory cloud permissions and resources during an authorized assessment.
AzureHound collects Azure and Entra ID data for attack path analysis, but only covers Microsoft's cloud and needs a BloodHound instance to view results.
Similar software
Related functionality, not a direct replacement.
BloodHound Community Edition
Maps attack paths through Active Directory and Entra ID relationships.
Prowler
Check cloud environments for security configuration issues.
Maester
An open-source PowerShell test framework that checks a Microsoft 365 tenant's security configuration.
ScubaGear
A CISA PowerShell tool that assesses a Microsoft 365 tenant's configuration against the SCuBA security baselines.
Purple Knight
A free Windows tool that assesses Active Directory, Entra ID and Okta for security weaknesses.