Integrating with SpecterOps BloodHound Enterprise helps you reduce the risk of attacks by enabling you to easily identify, prioritize, and eliminate the most vital avenues that attackers can exploit.
Supported Actions:
Quest OnDemand Audit ingests BloodHound Enterprise’s defined Tier Zero assets.
Quest OnDemand Audit ingests BloodHound Enterprise’s attack path edge data.
Common Use Cases:
Identify all critical Tier Zero assets via BloodHound Enterprise and through integration with OnDemand Audit automatically monitor them for any suspicious activity indicating they’ve been compromised
Leverage OnDemand Audit’s detailed user activity history to inspect BloodHound Enterprise’s attack path edges prior to removing access to the path – ensuring there are no unexpected consequences to the remediation
Create alert-enabled search for historical changes to the Tier Zero objects to ensure real-time monitoring of critical assets
Integration Instructions
To integrate BloodHound Enterprise with Quest OnDemand Audit, use the link below.
https://support.quest.com/technical-documents/on-demand-audit/current/user-guide/6#TOPIC-1880809
FedRAMP
No
Supplemental Information
Built In BloodHound Tier Zero Asset Searches
Monitoring Audit Health Status