Announcements
Black Hat USA 2026
SpecterOps is heading to Black Hat USA 2026 with training courses, technical briefings from our researchers, and Arsenal sessions showcasing tools and tradecraft. Learn more on our Black Hat landing page.SO-CON 2026 Talks Available on YouTube
We’re excited to share that SO-CON talks are now available online. We’ve also published the presentation slide decks in a public GitHub repository.2026-07-07
This release opens more administration workflows to auditors in read-only mode, and improves OpenHound collection resilience. Key highlights include:
- OpenHound: Keep long-running jobs alive, identify deployed client versions more easily, and troubleshoot failures with clearer logs.
- Cypher: Run more complex Cypher queries in BloodHound Enterprise and return larger Entity Panel sections than were previously supported.
New Features
Enhancements
Fixed Issues
See the release notes for a full list of fixed issues in this release.2026-06-17
This release expands OpenHound authentication support, improves visibility and access control across BloodHound administration workflows, and speeds up analysis. Key highlights include:
- Access control: Limit sensitive user data and administration API access for non-administrator roles.
- Audit logging: Capture and review more operator actions in audit logs.
- Explore: Highlight only the paths that traverse a selected node in the graph.
- OpenHound: Use an API client to authenticate the Jamf collector.
New Features
Enhancements
Fixed Issues
See the release notes for a full list of fixed issues in this release.2026-06-01
This release addresses an issue where ingestion jobs were running longer than expected on BloodHound Enterprise.
2026-05-28
This release improves Explore workflows, expands Cypher query capabilities for PostgreSQL backends, and tightens OpenGraph validation. Key highlights include:
- Explore workflow improvements: Added Eligible Roles in the Entity Panel and automatic node selection from search results.
- Cypher query enhancements: Expanded Cypher support with new functions and clauses for more powerful queries on PostgreSQL backends.
- OpenGraph validation updates: Tightened kind validation for reserved
tag_prefixes and updated node schema guidance for extension developers.
Enhancements
Fixed Issues
See the release notes for a full list of fixed issues in this release.2026-05-06
This release improves graph processing performance, refines core Explore and Administration workflows, and resolves high-impact reliability issues across API, OpenGraph, and collection operations. Key highlights include:
- Post-Processing Performance: Improved graph index coverage for faster traversal paths and incremental edge updates that reduce unnecessary writes during post-processing.
- Explore Workflow Improvements: Updated panel behavior for Cypher results, clearer saved query organization, and improved Entity Panel controls.
Enhancements
Fixed Issues
See the release notes for a full list of fixed issues in this release.2026-04-21
This release addresses the following issues:
- Resolved an issue where Azure post-processing could fail when PostgreSQL was configured as the graph database on BloodHound Community.
- Expanded the set of supported TLS cipher suites when BloodHound is configured to serve HTTPS directly to resolve SharpHound connectivity issues in certain environments.
- Added an OpenHound download link to the Download Collectors page.
2026-04-13
This release introduces new data collection capabilities, improves core navigation and graph exploration workflows, and resolves high-impact API and query reliability issues. Key highlights include:
- Graph Readability: Improved node labels, clearer directional arrows, and more intuitive selection behavior in Explore for easier graph analysis.
- OpenHound: A new data collector framework for OpenGraph extensions, starting with GitHub, Jamf, and Okta collectors.
- OpenGraph Extension Management: A new Administration page to manage OpenGraph extensions.
- OpenGraph Findings: Analyze custom graph findings in Attack Paths and Posture with extension-specific schemas.
- Environment Targeted Access Control: Scope User and Read-only access by environment with dynamic policy controls.
- Table View Organization: Improved organization and readability of table views.
- Azure Post-Processing: Enhanced post-processing capabilities for Azure data.
- Navigation Sidebar Modernization: Updated navigation sidebar for a more intuitive user experience.
New Features
Enhancements
Fixed Issues
See the release notes for a full list of fixed issues in this release.2026-03-26
This release resolves the following issues:
- Resolved several issues that could cause analysis to fail.
- Resolved an issue preventing Cypher queries on PostgreSQL from respecting minimum and maximum path length limits.
- Resolved an issue where certain Cypher path queries on PostgreSQL could be slower than expected due to an inefficient edge-to-path join pattern.
- BloodHound will no longer support SHA-1 cipher suites when configured to serve HTTPS directly (without a load balancer).
2026-03-23
This release introduces new features, enhancements, and fixed issues to improve data collection, OpenGraph ingestion capabilities, and general usability. Key highlights include:
- Privilege Zones is now generally available!
- Property-based edge matching enables hybrid edge creation using cross-system attributes, such as email, username, or hostname.
- AzureHound collects Federated Identity Credentials (FICs) from Azure and adds new nodes and edges in BloodHound to represent these trust relationships.
- BloodHound Enterprise now allows you to upload nodes and edges in separate OpenGraph data payloads without losing disconnected nodes after ingestion.
New Features
Enhancements
Fixed Issues
See the release notes for a full list of fixed issues in this release.2026-03-04
This release improves graph investigation workflows in Explore and resolves reliability issues in findings export, Zone Builder tagging and filtering, and query naming. Key highlights include:
- Explore adds resizable table columns, Meta node details in the Entity Panel, and clearer edge guidance for Azure role relationships.
- Edge reference coverage expands with a new
valid_edges.jsonschema for valid source-target node relationships and supported edge types. - Fixed issues improve findings export accuracy, Zone Builder Tier Zero tagging timing and zone membership filtering behavior, and prebuilt query naming clarity.
Enhancements
Fixed Issues
See the release notes for a full list of fixed issues in this release.2026-02-17
This release addresses the following issues:
- Resolved an issue causing partial failures after uploading Azure sample data.
- Resolved memory and CPU performance issues during AD Group and Local Group analysis.
2026-02-11
This release enhances data collection capabilities with new customization options, expands permissions for Cypher query management, and improves Zone Builder with better rule testing, clearer terminology, and enhanced object identification.
New Features
Enhancements
Fixed Issues
12 issues resolved across BloodHound, SharpHound, and AzureHound.2026-01-30
This release addresses an issue where Local Group relationships could be incorrectly calculated during analysis.
2026-01-27
This release addresses the following issues:
- Resolved memory and performance issues during local group processing (DCOM, CanPSRemote, AdminTo, CanRDP).
- Resolved an issue where custom icons for nodes in OpenGraph data did not display in the graph on the Explore page.
- Set OpenGraph node search to enabled by default.
2026-01-22
This release introduces new features, enhancements, and fixes to improve usability, performance, and data collection. Key highlights include:
- Keyboard shortcuts improve accessibility
- Zone Builder (renamed) gains clearer forms, rule guidance, and consistent terminology
- APIs add safer filtering, member counts, and source-kind safeguards
- Data collectors add clearer logging and configuration guidance