SpecterOps Extends BloodHound Enterprise to AWS
SpecterOps announced July 28 that BloodHound Enterprise now supports Amazon Web Services attack path management and adds BloodHound Hunter, an AI agent interface for hybrid identity security workflows. Help Net Security reports that the release also expands coverage to Microsoft Entra Agent ID and uses the Model Context Protocol to connect approved AI agents and knowledge sources with BloodHound findings.
SpecterOps announced July 28 new BloodHound Enterprise capabilities for mapping attack paths in Amazon Web Services and hybrid identity environments, alongside an AI agent interface called BloodHound Hunter. Help Net Security reports that the update adds support for AWS and Microsoft Entra Agent ID, expanding the product's attack-path-management coverage.
According to Help Net Security, BloodHound Enterprise identifies and prioritizes attack paths across identity providers, cloud platforms, applications, and repositories, then provides remediation guidance. The report describes the product's core premise as graphing the relationships, permissions, trust links, and misconfigurations that an attacker could chain to reach a target.
AI interface uses MCP
The new BloodHound Hunter interface is built into BloodHound Enterprise and uses the Model Context Protocol (MCP), according to Help Net Security. The company described the interface as a way for customers to connect approved AI agents and knowledge sources to BloodHound Enterprise findings.
Help Net Security reports that the interface is intended to support environment-specific remediation prioritization, translation of technical findings for identity and executive teams, and identification of assets or enclaves to protect with Privilege Zones. SpecterOps also said its BloodHound Enterprise MCP enables identity and security teams to use the platform's attack-path intelligence through their own AI agents and workflows.
Hybrid identity attack paths
AWS coverage matters because cloud attack paths can span identity permissions, infrastructure relationships, and configuration errors rather than remaining within a single directory or account boundary. The reported AWS addition places cloud-native authorization relationships in the same broader attack-path-management workflow described by SpecterOps.
For security engineering teams, products that expose graph-derived findings to AI agents introduce a separate governance question: agent access, source grounding, and remediation approvals require controls independent of the underlying graph analysis. In comparable security-automation deployments, connecting an agent to sensitive identity data commonly increases the importance of least-privilege tool access and auditable actions.
The announcement does not provide benchmark data on detection coverage, graph scale, model behavior, or the precise AI agents supported by BloodHound Hunter. Those implementation details would be material for teams assessing operational fit and security controls.
Key Points
- 1BloodHound Enterprise adds AWS attack path management, bringing cloud authorization relationships into SpecterOps' reported hybrid identity security graph.
- 2BloodHound Hunter uses MCP to connect approved AI agents and knowledge sources to attack-path findings, according to Help Net Security.
- 3Comparable AI-assisted security workflows require controls around agent permissions, data grounding, remediation approvals, and auditability alongside graph-based risk prioritization.
Scoring Rationale
The release is relevant to identity-security and cloud-security practitioners using attack-path analysis and AI-assisted workflows. Its practitioner impact is narrower than a broadly adopted model or platform release, and the available reporting does not include performance or deployment evidence.
Sources
Public references used for this report.
Practice with real Telecom & ISP data
90 SQL & Python problems · 15 industry datasets
250 free problems · No credit card
See all Telecom & ISP problems


