Alternatives to BloodHound Community Edition
Maps attack paths through Active Directory and Entra ID relationships. The listings below can replace it for an important use case. Each note says what changes if you switch.
The original
BloodHound Community Edition
Maps attack paths through Active Directory and Entra ID relationships.
Replacements
Listings that take over the same core job as BloodHound Community Edition.
PingCastle
Active Directory security assessment tool that scores risky configuration.
PingCastle produces a scored risk report of Active Directory configuration from a single scan instead of a graph of attack paths, and is closed source with paid commercial licensing.
Purple Knight
A free Windows tool that assesses Active Directory, Entra ID and Okta for security weaknesses.
Purple Knight assesses AD, Entra ID and Okta against more than 230 indicators with MITRE ATT&CK mapping, but is a closed-source Windows tool without graph-based path analysis.
ADRecon
A PowerShell script that gathers Active Directory information and builds an Excel report of the environment.
ADRecon is a single PowerShell script that documents an Active Directory domain in an Excel report, with no graph database to set up but no attack path view.
ADAudit Plus
A Windows auditing tool that tracks changes in Active Directory, file servers, Windows servers and workstations.
ADAudit Plus tracks changes across AD, Entra ID, servers and workstations as an ongoing audit rather than attack path analysis.
Similar software
Related functionality, not a direct replacement.
SharpHound
A C# collector that gathers Active Directory data for attack path analysis in BloodHound.
AzureHound
A command-line collector that exports Microsoft Azure and Entra ID data for analysis in BloodHound.
Certipy
Audit Active Directory Certificate Services configurations.
NetExec
Assess network services during authorized enterprise security tests.
Impacket
Python library and tool collection for working with network protocols.
Kerbrute
Enumerates Active Directory usernames and tests passwords through Kerberos.