Need help finding something? We're here for you

Contact Us

Need help finding something? We're here for you

Contact Us

BloodHound Basics

BloodHound is the industry-standard tool for attack path management—but most teams never unlock its full power. This course takes you from beginner to capable operator, equipping you to identify, analyze, and act on attack paths in real environments.

rate limit

Code not recognized.

About this course

BloodHound Basics gives security professionals a practical, ground-up understanding of attack path management using both BloodHound Community Edition and BloodHound Enterprise. You’ll learn how adversaries and defenders identify and navigate attack paths across Active Directory, Entra, and Azure environments (and more), building hands-on experience with data collection, ingestion, graph analysis, Cypher querying, API usage, administration, and OpenGraph extensions. 

Through a 50:50 mix of instruction and labs, you’ll move beyond theory to confidently operate BloodHound in real environments—analyzing relationships, uncovering risk, and interpreting findings to drive remediation and prioritization. 

By the end of the course, you’ll be able to operationalize BloodHound for your attack path management practice with confidence. 

Learning objectives

By the end of this course, you'll be able to:

  • Install and configure BloodHound
  • Collect and ingest data
  • Explore data in BloodHound
  • Understand cypher basics and use built-in queries
  • Create custom queries
  • Interact with the BloodHound API
  • Administer BloodHound

Student Requirements

  • Hardware - A machine capable of running containers, e.g. Docker Desktop or Podman. There are no local virtual machines or further special software requirements to participate in this course or labs.
  • Knowledge - This course assumes no prior Active Directory, Entra, Pentesting or Red Teaming knowledge.

Who this course is for

Everyone!

 

Curriculum6 hours

  • Introduction
  • Course Structure
  • Course Materials
  • BloodHound Origin Story
  • Course Intro
  • M1 - Concepts & Components
  • Overview
  • Lecture
  • Self-Study
  • Quiz - Concepts
  • M2 - Installation & Discovery
  • Overview
  • Lecture
  • Self-Study
  • Lab - Install
  • M3 - Collection & Ingestion
  • Overview
  • Lecture
  • Self-Study
  • Lab - Ingest
  • M3 - Collection - BHE
  • Overview
  • Lecture
  • Self-Study
  • Lab - Ingest - BHE
  • M4 - Exploration & Cypher Basics
  • Overview
  • Lecture
  • Self-Study
  • Lab - Explore I
  • Lab - Explore II
  • Lab - Cypher
  • M5 - Administration
  • Overview
  • Lecture
  • Self-Study
  • Lab - Admin
  • Lab - Tiering
  • M5 - Administration - BHE
  • Overview
  • Lecture
  • Self-Study
  • Lab - Admin - BHE
  • M6 - API & Automation
  • Overview
  • Lecture
  • Self-Study
  • Lab - API
  • M7 - OpenGraph
  • Overview
  • Lecture
  • Self-Study
  • Lab - OpenGraph
  • M8 - Findings & Posture - BHE
  • Overview
  • Lecture
  • Self-Study
  • Lab - Findings - BHE
  • M9 - Advanced Usage
  • Overview
  • Lecture
  • Self-Study
  • Lab - BHOperator
  • Outro
  • Recap
  • Feedback
  • Social + Badging

About this course

BloodHound Basics gives security professionals a practical, ground-up understanding of attack path management using both BloodHound Community Edition and BloodHound Enterprise. You’ll learn how adversaries and defenders identify and navigate attack paths across Active Directory, Entra, and Azure environments (and more), building hands-on experience with data collection, ingestion, graph analysis, Cypher querying, API usage, administration, and OpenGraph extensions. 

Through a 50:50 mix of instruction and labs, you’ll move beyond theory to confidently operate BloodHound in real environments—analyzing relationships, uncovering risk, and interpreting findings to drive remediation and prioritization. 

By the end of the course, you’ll be able to operationalize BloodHound for your attack path management practice with confidence. 

Learning objectives

By the end of this course, you'll be able to:

  • Install and configure BloodHound
  • Collect and ingest data
  • Explore data in BloodHound
  • Understand cypher basics and use built-in queries
  • Create custom queries
  • Interact with the BloodHound API
  • Administer BloodHound

Student Requirements

  • Hardware - A machine capable of running containers, e.g. Docker Desktop or Podman. There are no local virtual machines or further special software requirements to participate in this course or labs.
  • Knowledge - This course assumes no prior Active Directory, Entra, Pentesting or Red Teaming knowledge.

Who this course is for

Everyone!

 

Curriculum6 hours

  • Introduction
  • Course Structure
  • Course Materials
  • BloodHound Origin Story
  • Course Intro
  • M1 - Concepts & Components
  • Overview
  • Lecture
  • Self-Study
  • Quiz - Concepts
  • M2 - Installation & Discovery
  • Overview
  • Lecture
  • Self-Study
  • Lab - Install
  • M3 - Collection & Ingestion
  • Overview
  • Lecture
  • Self-Study
  • Lab - Ingest
  • M3 - Collection - BHE
  • Overview
  • Lecture
  • Self-Study
  • Lab - Ingest - BHE
  • M4 - Exploration & Cypher Basics
  • Overview
  • Lecture
  • Self-Study
  • Lab - Explore I
  • Lab - Explore II
  • Lab - Cypher
  • M5 - Administration
  • Overview
  • Lecture
  • Self-Study
  • Lab - Admin
  • Lab - Tiering
  • M5 - Administration - BHE
  • Overview
  • Lecture
  • Self-Study
  • Lab - Admin - BHE
  • M6 - API & Automation
  • Overview
  • Lecture
  • Self-Study
  • Lab - API
  • M7 - OpenGraph
  • Overview
  • Lecture
  • Self-Study
  • Lab - OpenGraph
  • M8 - Findings & Posture - BHE
  • Overview
  • Lecture
  • Self-Study
  • Lab - Findings - BHE
  • M9 - Advanced Usage
  • Overview
  • Lecture
  • Self-Study
  • Lab - BHOperator
  • Outro
  • Recap
  • Feedback
  • Social + Badging