Skip to main content
Applies to BloodHound Enterprise and CE The following custom Cypher queries can be imported into BloodHound to enhance visibility.
This file is automatically generated from the JSON query files.

Account Access by Name

Filter to view access of a Jamf Account named or starting with ‘LC’ - increase the maximum edges to see more relationships (i.e. change 5 to 6 to see 1 more)
This query can be imported into BloodHound from the Jamf_Account_Access_by_Name.json file.

Account to Account Attack Paths

Display Jamf Accounts with Attack-Paths impacting other Jamf Accounts - increase the maximum edges to see more relationships (i.e. change 5 to 6 to see 1 more)
This query can be imported into BloodHound from the Jamf_Account_to_Account_Attack_Paths.json file.

Account to Tenant Edges

Show edges from Jamf Accounts to the Jamf Tenant
This query can be imported into BloodHound from the Jamf_Account_to_Tenant_Edges.json file.

All Account Paths

View paths originating from Jamf Accounts with up to 4 edges - increase edges to see more
This query can be imported into BloodHound from the Jamf_All_Account_Paths.json file.

All Computers

Get all Computers
This query can be imported into BloodHound from the Jamf_All_Computers.json file.

All Groups

Get Jamf Groups
This query can be imported into BloodHound from the Jamf_All_Groups.json file.

All Nodes and Edges

Retrieve all nodes and edges where either a Jamf node has an inbound or outbound relationship, limits results to 1000
This query can be imported into BloodHound from the Jamf_All_Nodes_and_Edges.json file.

API Client Attack Paths to Tenant

Display up to 4 edges in attack paths originating from Jamf API Clients with a matching name or name starting with DEMO targeting the tenant
This query can be imported into BloodHound from the Jamf_API_Client_Attack_Paths_to_Tenant.json file.

API Client Immediate Edges

View immediate edges and impacted principals for Jamf API Clients
This query can be imported into BloodHound from the Jamf_API_Client_Immediate_Edges.json file.

Chained Targeted Filtering

An example of chained targeted filtering with multiple conditions in series that creates multiple proprety filters such as restricting to nodes with specific strings in their name, kinds of nodes, and types of edge relationships existing between the nodes
This query can be imported into BloodHound from the Jamf_Chained_Targeted_Filtering.json file.

Expanded Tier 1 to Tier 0 Paths

Expand the graph by one edge showing nodes with edges to Tier 1 nodes with edges to Tier 0 nodes
This query can be imported into BloodHound from the Jamf_Expanded_Tier_1_to_Tier_0_Paths.json file.

Group Administrators Filtered Relationships

Targeted Filtering that limits results to starting jamf_Group nodes starting with ‘TENANT’ in the name and only show edges/relationships specified by r that are one of the three specified edges
This query can be imported into BloodHound from the Jamf_Group_Administrators_Filtered_Relationships.json file.

Group Administrators Targeted Edges

Targeted Filtering Query, display nodes with edges between ‘GROUP_ADMINISTRATORS’ and ‘UPDATE’ or ‘GROUP_ADMINISTRATORS’ and other nodes that start with ‘SOL’
This query can be imported into BloodHound from the Jamf_Group_Administrators_Targeted_Edges.json file.

Group Edges to Accounts

Get immediate edges impacting Jamf Accounts originating from Jamf Groups, swap jamfGroup for jamfTenant to see impact edges to the tenant from groups
This query can be imported into BloodHound from the Jamf_Group_Edges_to_Accounts.json file.

Matched Email Edges

Show nodes with the edge jamfMatchedEdmail
This query can be imported into BloodHound from the Jamf_Matched_Email_Edges.json file.

Tier 1 to Tier 0 Attack Paths

Retrieve attack paths between Tier 1 nodes and Tier 0 nodes that are fully traversable - excludes tenant and site nodes as starting points
This query can be imported into BloodHound from the Jamf_Tier_1_to_Tier_0_Attack_Paths.json file.

Tier 1 to Tier 0 Direct Edges

Retrieve direct edges between Tier 1 nodes and Tier 0 nodes
This query can be imported into BloodHound from the Jamf_Tier_1_to_Tier_0_Direct_Edges.json file.

Tier 1 to Tier 0 Without Contains

Filter out jamf_Contains edges from Tiered node query
This query can be imported into BloodHound from the Jamf_Tier_1_to_Tier_0_Without_Contains.json file.