Attack paths & BloodHound
TL;DR
The reason attackers reach Domain Admin isn’t usually one big bug — it’s a chain of small, legitimate permissions that add up to a path. Attack-path thinking (and BloodHound) makes those chains visible, to attackers and defenders alike.
What it is
Active Directory is a web of relationships: who is an admin where, who can reset whose password, who owns which group. Any one link looks harmless. Strung together, they form a route from a normal user to full control.
How it works
BloodHound collects those relationships and draws them as a graph, then finds the shortest path from where you are to where you want to be. A path might read: this user can reset that user’s password → that user is in a group → the group has admin on a server → a Domain Admin logs into that server. Each hop is a normal permission; the chain is the problem.
How to defend
- Run BloodHound yourself and cut the paths — prune excess group membership and dangerous ACLs.
- Adopt admin tiering so high-value accounts never log into low-trust machines.
- Treat “who can reach Domain Admin” as a number to drive down over time.
Reference: the BloodHound docs.