In this episode of Know Your Adversary, Jared Atkinson and Justin Kohler are joined by Andy Robbins, Will Schroeder, and Rohan Vazarkar, the original creators of BloodHound, to celebrate ten years since the tool was first introduced. Together, they revisit the offensive security challenges that led to BloodHound and how a need to understand increasingly complex Active Directory environments ultimately led them to graph theory and attack path analysis.
The discussion traces BloodHound’s evolution from a tool built by red teamers to solve their own operational problems into an open source project that changed how practitioners understand identity-based attack paths. The group shares stories from its early development and DEF CON debut, the expansion from a simple graph of three node and edge types, and the realization that BloodHound wasn’t creating attack paths, but providing a map of relationships and opportunities that had been there all along.
Along the way, they explore how BloodHound changed offensive tradecraft, why visualization made complex attack paths easier to understand, and how defenders began using the same capabilities to find and eliminate those paths at scale. They also reflect on the project’s transition from an offensive tool toward a defensive capability, setting the stage for BloodHound Enterprise and the next chapter of BloodHound’s evolution.
00:00:12:21 - 00:00:33:08
Jared Atkinson
Welcome back to the Know Your Adversary podcast. I'm Jared Atkinson and I'm joined by Justin Kohler. And today is a very special episode because we're joined by the three founders and creators of BloodHound, which is now reaching its 10th year anniversary from when it was originally presented. I think the original presentation was that was a besides Las Vegas or Defcon, I think it was.
00:00:33:08 - 00:00:35:00
Rohan Vazarkar
Def Con Arsenal, technically.
00:00:35:00 - 00:01:06:15
Jared Atkinson
Okay, cool, cool. So we got Andy. Andy Robbins, go ahead and wave. I'll let you wave. We got Will Schroeder with that. That mustache. If you're not watching, just keep the video off, is what I'll recommend. And then we got Rohan Vazarkar joining us. And what we're going to do is we're going to go down, like a little tour of memory lane talking about kind of some nostalgic moments, the development of BloodHound and kind of like talk about some of the big advancements and how it got started, how we updated it as, as we went, and then kind of where we're going in the future.
00:01:06:15 - 00:01:29:07
Jared Atkinson
So maybe we'll start off by allowing, I don't know who wants to take the the first part of it, but maybe kind of the origin of of BloodHound, maybe talk about some of the challenges that you faced as red teamers and, and maybe what the old tradecraft paradigm was and how you tried to overcome those problems, and then maybe talk about why you needed some new solution to overcome them.
00:01:29:08 - 00:01:53:17
Will Schroeder
Sure. I think a lot of this and please jump in. Andy and Rohan when I inevitably forget something. But a lot of this really kind of just evolved piecemeal over time, starting with the Power View tool, which is a PowerShell kind of Active Directory, offensive automation, self-contained type scripts that embody a lot of our tradecraft for about, I know, seven, eight, nine years or more.
00:01:53:17 - 00:02:21:22
Will Schroeder
So we used to operate in a couple of highly complex environments with a lot of domains, tons of different systems talking tens or hundreds of thousands of systems, users and all that. And we started to stumble upon this concept of like, we kind of deemed it derivative local admin. Other people called it the credential shuffle. You know, that standard hop to a system, there's somebody with access, unroll the groups, they have access to other things, hop to that system and just kind of keep going down the line.
00:02:22:00 - 00:02:43:07
Will Schroeder
So we were doing this manually, but instead of just with textual based approaches, we were using structured output with like PowerShell and then chaining all this kind of stuff together. And I remember being in, you know, ops rooms with Andy and Rohan spending days or a couple of weeks trying to chain together, you know, as an 8 or 10 kind of hop type thing for some of those environments.
00:02:43:07 - 00:03:03:04
Will Schroeder
And we were ecstatic when we were actually able to pull it off, because the complexity of those attack paths that we were able to put together, even at that time, was well beyond the kind of 1 to 2 hop kind of standard that a lot of people had before. But we definitely got to the point where the data started to scale very large and just kind of really became out of control.
00:03:03:10 - 00:03:26:15
Will Schroeder
Or we could find maybe a handful of attack paths, but we definitely couldn't find all of them. I vividly remember I think we it was over, I think Christmas break one time, Andy, you know, that 2014, 2015 or whatever exactly it was. And we had talked about this and we went back and then you came back saying like, oh, and I'll let you tell the story of the kind of the graph theory kind of light bulb that went off.
00:03:26:15 - 00:03:44:10
Will Schroeder
And I remember diving down some different languages and this and trying to figure out like structured graph approaches and you kind of you hit on the Neo Forge and all that kind of stuff. But we started to realize there was there was a problem here that even though our solution was kind of novel and useful, we knew that there should be a way to scale it up.
00:03:44:10 - 00:04:00:03
Will Schroeder
And it just took us kind of maybe slightly embarrassing long period of time, I think, to actually get to to what our initial solution was like. It took a while. We kind of, at least from I felt like I for me, I banged around for a long time and never actually got to kind of where the point was that I needed.
00:04:00:05 - 00:04:20:02
Jared Atkinson
I think there's maybe, maybe to kind of like facilitate that conversation. I think there's to your point, Will, it's one of those things to where once you find the solution, it seems obvious in retrospect, but it was 100% not obvious to anybody before kind of that, that light bulb moment. But but also I think there's like, oh man, what is it?
00:04:20:03 - 00:04:37:11
Jared Atkinson
What is the saying? Like necessity is the mother of all invention or something like that. So you kind of alluded to this, this one op that was like previously you had been collecting the data of users and groups and admin access and things like that, and you put them in like pivot tables and Excel, and you'd be tracking who has access to what.
00:04:37:11 - 00:04:50:20
Jared Atkinson
And it was just like this complete hot mess. But then I think I, I may be making this part up, but I think you like overflowed the size of an Excel spreadsheet to where it like, literally could not handle the amount of data that you were trying to process. Does that sound accurate?
00:04:50:21 - 00:05:03:04
Will Schroeder
I was chaining a bunch of PowerShell criminals together, and I may have like, I definitely kind of balked, like either the memory of, I don't know, there's definitely some performance issues with the scale of the data that we're kind of going through at the time.
00:05:03:04 - 00:05:25:22
Jared Atkinson
And then you had like a there was a particular red team op that had hundreds of domains that had all kinds of different connections and all kinds of stuff. And so I guess that's kind of like, I don't know if that's literally the impetus of everything, but that was something that was there was a new kind of like a new approach that was necessary to be able to kind of like apply this like tradecraft approach to solve the problems that you were facing there.
00:05:25:23 - 00:05:43:13
Will Schroeder
And I think we had our biases that we were very much this is kind of the golden age of PowerShell. I remember actually, before all the graph, the for before the Neo Forge approaches and all that kind of stuff. And you would you would did you implement the kind of the graph theory finding you started to explore stuff in PowerShell two level.
00:05:43:14 - 00:05:49:23
Andy Robbins
So back then I did put together a PowerShell script called.
00:05:49:23 - 00:05:51:03
Andy Robbins
Power Path.
00:05:51:08 - 00:06:15:15
Andy Robbins
That used Power View to collect some of that data in a lab that will mentioned earlier. So who's been where? Who belongs to what security groups, who's logged on where as well. And then Jim Truer had released a few years previously a proof of concept or a or a implementation rather of Dijkstra's algorithm in PowerShell on his blog.
00:06:15:15 - 00:06:41:18
Andy Robbins
And so I lifted or stole or borrowed from Jim truer that that PowerShell script. Ported ported modified ported ported. Yeah. That's the word. Yeah. Ported. I ported Jim's script into something that would take the power view output and then give the output that I wanted, which was show me a path from the computer I'm on to a domain admin using the using the graph, the graph.
00:06:41:19 - 00:07:12:10
Andy Robbins
So yeah, at that time, like Will mentioned earlier, the kind of memory consumption that we were talking about was on the order of gigabytes. If we were in a LAN that had 1000 hosts, and so we didn't have gigabytes of Ram just sitting around all the time, and we needed to scale. And so before I had ported Jim Troopers script, I had a conversation with a friend named Sam Meister, and Sam introduced me to the the idea of graph theory.
00:07:12:12 - 00:07:37:21
Andy Robbins
So I had explained to him, you know, like, we have this really hard domain we're trying to attack. We have all this data with, we don't know what to do. How do we do it? And me personally, I'm a lazy idiot. So my perspective on that was how do I, the lazy idiot, take all of this data, put it into the computer and make the computer do all of the thinking and all of the work for me.
00:07:37:23 - 00:07:53:22
Andy Robbins
And Sam's response was, this is like graph Theory 101, brother. Like this is, this is this is so easy. Any graph can do this instantaneously. So found Neo Forge had been community support, worked well enough. Worked for a long time. Well enough.
00:07:53:22 - 00:08:08:01
Will Schroeder
I think this story you told me, Andy, after that conversation was it was something along the lines of have none of you taken a computer science course before? This has been solved for decades. And I was like, oh yeah, I do have a computer science degree. I forgot about that.
00:08:08:03 - 00:08:28:06
Jared Atkinson
Can we do it? Can we do a quick aside and talk about I know this is getting ahead of ourselves, but it's Jermain to this topic. You I think was it Rohan and Andy you went and presented at Neo Forge's conference or some some graph conference. And when you were presenting like you presented, what in cybersecurity was this like extraordinarily novel, like very forward thinking use case.
00:08:28:06 - 00:09:01:12
Jared Atkinson
And to them it was kind of like a cool like you, you ran his algorithm like short. I went to yeah, I went to Graph Connect, the conference put on by Neo Technologies, the company that owns Neo Forge. And at that time, the BloodHound graph model was three classes of nodes and three classes of edges. And I was talking to these people in the audience who I can only imagine they're using a graph to like full proteins and do medical research.
00:09:01:12 - 00:09:38:08
Andy Robbins
And I here I am with my three node classes and three edge classes. But it's also it's a testament to how how powerful a graph actually is and how in discrete mathematics, three components of each type can actually be insanely effective and insanely powerful. So I, you know, I put that out there for anybody who's doing like an open graph thing in the future, if you think you have like, oh, I've only got 2 or 3 nodes, I've only got 2 or 3 edges, that's not enough wrong.
00:09:38:10 - 00:09:40:18
Andy Robbins
That could be that could be more than enough.
00:09:40:18 - 00:10:03:17
Will Schroeder
I remember Andy of, you know, grabbing a beer at a bar in Capitol Hill here in Seattle with you and just it was it was weeks, right, of, you know, debating the exact schema for those three nodes and those three edges and like, you know, reversing the house session and everything. But it was I remember at that time you definitely had the push of or you had the, the thought of this is really important to get the schema correct.
00:10:03:17 - 00:10:17:08
Will Schroeder
And I'm glad that you spent that amount of time and I remember you peppering questions off of me and things like that. So it was it's very crazy to see where we are now based off those original three nodes and the handful of edges. Yeah.
00:10:17:08 - 00:10:18:20
Justin Kohler
I should have pulled the I should have pulled.
00:10:18:20 - 00:10:19:16
Justin Kohler
The stats right now.
00:10:19:17 - 00:10:35:19
Justin Kohler
Like, what is the the I mean, I don't even know if we can obviously with all the open graph extensions both authored by us and like fully supported on all the community. Like if you added all those up like what are the nodes in the edges counts today, it'd be insane. It'd be crazy to kind of look back.
00:10:35:20 - 00:10:51:15
Justin Kohler
Remember, I've seen like pictures over the years of the schema of it growing like when you're talking about three nodes and three edges, and then it just keeps growing and growing. Growing. I'm I'm certain it would be unrecognizable or just like a hairball. It would just be a big black dot. Basically.
00:10:51:16 - 00:11:18:20
Will Schroeder
I remember the the rest of the kind of evolution of the initial kind of proof of concept. What was what was it called? Rohan. It was it was the HTML. Yeah, yeah. To where I think how how all three of us kind of fit together with everything was Andy kind of had the insight for the initial graph component, you know, and then saying neo forge, I built the first very terrible collector that only scaled to a few thousand systems.
00:11:18:20 - 00:11:32:17
Will Schroeder
That was essentially a wrapping around power view to be able to pull this stuff in. So if you have ever tried to do multi-threaded support in PowerShell v2, that's not the most fun. So we wanted to keep everything as we were. Coming from.
00:11:32:17 - 00:11:34:12
Justin Atkinson
A compatibility baby.
00:11:34:14 - 00:11:56:19
Will Schroeder
We were, we were, we were coming from an offensive perspective obviously originally. So we wanted to keep the collector, you know, a single scripted memory for PowerShell v2 for backwards compatibility at the time. And then Rohan actually built, you know, made it usable with kind of the interface and everything. And I do have this vivid memory of was it two days before the DefCon presentation, Rohan?
00:11:56:20 - 00:12:07:20
Will Schroeder
Something like that. You're like, I decided to rewrite the entire front end. And I was panicking and I was like, no, don't do that. We need to have the worship. No. It's fine. You're like, it'll be fine, don't worry about it. And you pulled it off.
00:12:07:23 - 00:12:27:10
Andy Robbins
They were there were a couple of things that that I was reminded of. Rohan, like a couple of days leading up to the product release that we were, like, making fine tune changes on or in some instances, not even fine tuned changes. Just like severe architectural changes and design changes, like maybe in the hour before we released it on stage.
00:12:27:13 - 00:12:44:18
Andy Robbins
But there were a couple things that come to mind. One is that the the layout of the graph nowadays reads from left to right. You know, like a, like an English sentence, you know, so you start over here and you make your way and you get to the to the end of it. That's not the way it started.
00:12:44:18 - 00:13:00:08
Andy Robbins
The way it started was it actually started from the top and it went down. So you kind of started at the top, and then you would go down to get to domain admin. Doesn't make a whole lot of sense, does it? Now the the nodes also didn't have any color to them until maybe a week before the release.
00:13:00:08 - 00:13:22:03
Andy Robbins
We talked to a UX designer. We showed the interface to this UX designer, which is like, just give us some tips. I bought the guy lunch, like, what do you think? And color coding that was, that was that was his input. And it was like it changed everything about making it actually legible. Like it was a huge improvement.
00:13:22:04 - 00:13:24:00
Andy Robbins
It was night and day. We had a lot.
00:13:24:00 - 00:13:25:13
Rohan Vazarkar
Of stuff going on in the week.
00:13:25:13 - 00:13:29:02
Rohan Vazarkar
Leading up to the release where.
00:13:29:04 - 00:13:32:23
Rohan Vazarkar
I have like distinct memories of like maybe.
00:13:33:00 - 00:13:42:20
Rohan Vazarkar
30 minutes before we went up on stage, us sitting in the in the back room trying to get our artifacts published because our CI CD just like, kind of crapped itself.
00:13:42:20 - 00:13:44:08
Andy Robbins
And that's right.
00:13:44:09 - 00:13:56:15
Rohan Vazarkar
I'm sitting there like trying to make sure we have stuff that we can actually give to people and like, absolutely losing my mind when we're about to go up on like, the biggest stage we can possibly go up on, that was a good time.
00:13:56:21 - 00:13:57:21
Andy Robbins
Yeah.
00:13:57:23 - 00:14:09:17
Justin Kohler
So as like, what's one what's like one memory each from all of you guys being on the stage at DefCon and showing this thing that's, like, immensely powerful. You've used it on an operation. You're just going to. You're going to show it.
00:14:09:18 - 00:14:29:20
Will Schroeder
I mean, for me, it was when Rohan pulled this password manager up and I tried to pull the HTML cord out and he said, I believe and I quote, I'm not afraid of these people. And then just continued on with it. So that is I mean, that's the most a lot of memories from that day. But that was by far of just I vividly remember trying to pull the cord out and say, no.
00:14:29:23 - 00:14:47:22
Rohan Vazarkar
Yeah. For for me, it was before we went up on stage, someone told me, oh, don't worry about it. Like the lights are super bright. You're not going to be able to see anybody in the audience. And we get up on stage and I can see every single person in the audience and like, perfect HD clarity and.
00:14:48:02 - 00:15:05:00
Rohan Vazarkar
Yeah. And like, that's that's when, like, the adrenaline started spiking. And I remember talking at like a thousand miles a minute when we're up on stage. So that definitely was part of what contributed to the password manager thing was just like the sheer volume of adrenaline that was in my body at that point.
00:15:05:01 - 00:15:38:01
Andy Robbins
I remember the adrenaline very clearly. Yeah. I'm also reminded of some phrase, something like, people forget what you said, but they remember how you made them feel. And I just remember feeling like an immense amount of support and camaraderie and like I was part of a team when I was on stage with Rohan and Will, and I felt an immense amount of respect from a lot of industry colleagues who showed up for the talk.
00:15:38:01 - 00:16:00:03
Andy Robbins
And then my my mother had passed away the year previously before we had done that. And so my dad was there and the Def Con staff, they, they actually they found out that he was my dad and they escorted him from kind of our prep room, the speaker prep room, and they made like a new front row, like just for him.
00:16:00:03 - 00:16:19:07
Andy Robbins
And then I think sitting next to him was, I believe, Lee Holmes and Shawn Metcalfe. And then Jason Frank was was in that mix as well. So that's that's what I'm going to remember. The rest of my life is just the people who were around and just how accepted and welcome and supported I felt at that time.
00:16:19:09 - 00:16:38:14
Will Schroeder
I think, too, right after the fact of when we had a lot of people coming up. And I think there's definitely some people that said some things along the lines of, well, I guess you ordered automated away most of my job or not. They were saying it kind of half in jest, but, you know, this was this was something that was kind of not a trade secret, but I think it was a skill.
00:16:38:15 - 00:17:00:09
Will Schroeder
Right, Andy? That red teamers at the time would be able to kind of find some of these past through. And kind of the deeper you could go, you know, some people had some tips and tricks for doing some of this kind of stuff. So being able to democratize that entire kind of class of approach and tradecraft and then having the response in that, you know, the hours after, in the days after was pretty, pretty overwhelming for me.
00:17:00:09 - 00:17:01:09
Will Schroeder
I think it's.
00:17:01:09 - 00:17:08:15
Jared Atkinson
It's not normal for red teamers to think that some new innovation is going to get rid of their their entire field. Is it will.
00:17:08:17 - 00:17:15:05
Will Schroeder
Oh definitely not. This is a you know, I know none of us have had any of those thoughts over.
00:17:15:05 - 00:17:48:12
Jared Atkinson
The last couple. No dread about anything ever, ever. As far as technological advancement. I remember when I, when I first started using Power View, I actually I wasn't working with Will, Rohan, Jared, etc. at the time I was working at a different pen test shop and I started using Power View, partly as a reaction to Microsoft Lapse being put out there, because before lapse, you drop into a network and the red 500 password on each domain join system.
00:17:48:13 - 00:18:07:11
Andy Robbins
It's like pretty good odds that the password is going to be the same on every single system. So what does that mean? That means you get you get local admin on one host. You have local admin on almost every host. So like there wasn't really much of a need for BloodHound in my experience at that time. When labs came out, I thought, it's over, it's over.
00:18:07:11 - 00:18:25:07
Andy Robbins
Pen testing is over. Like like like Active Directory and Windows security is solved. It's over. And then, of course, you know, there are reactions to Microsoft Labs being put out. The derivative local admin concept that Will alluded to earlier. And then of course, there are plenty of employed pen testers nowadays.
00:18:25:08 - 00:18:45:07
Justin Kohler
What was it from your persuade. So you miss amount of attention. And you guys are starting to talk about BloodHound everywhere. You're using it internally. Is it it it kind of appears. It's like shooting fish in a barrel for, for a short amount of time. I mean, people were now trying to like, monitor the network traffic, find BloodHound named files on hosts and stuff.
00:18:45:07 - 00:18:50:20
Justin Kohler
But for the for it seemed like you were just like, yep, we got it. Yep. We got it. Yep. We got it.
00:18:50:21 - 00:19:06:18
Jared Atkinson
Even that probably took a little while for any like, defenders to even have a concept of how you would even begin to detect it. So it's like nowadays it seems like collection is the the long pole in the tent, they say. But like at the time it was like, just run that shit, man, and let's see what comes out of it.
00:19:06:19 - 00:19:25:19
Rohan Vazarkar
Early days BloodHound definitely made us very lazy in some aspects because like it went from like something that we actually had to like, really think about and like kind of like a lot of it was just trial and error, like, let's throw a shell on that one, because it sounds like the name of that system might be an admin host.
00:19:25:19 - 00:19:54:00
Rohan Vazarkar
And then all of a sudden, like Post BloodHound, it was like, all right, let me just run collection for like two hours, throw it all in BloodHound, and then like, bam, I'm da because I know the exact like for hosts I need to touch to get there. So and as you alluded, like there was no detection because like we've said this before, but like BloodHound is possibly one of the easiest things to detect on the planet if you're looking for it.
00:19:54:00 - 00:19:59:08
Rohan Vazarkar
And no one was looking for it. So it was kind of just like it was free real estate in a way.
00:19:59:10 - 00:20:19:04
Will Schroeder
Well, the original couple of times we did get detected, it was it was 1 or 2 places. It was something lines of like SMB worm behavior of like a single host talking to SMB and a large number of hosts in a short period of time. But those would be kind of custom analytics, you know, to, to protect against SMB, like ransomware worm type stuff.
00:20:19:06 - 00:20:38:09
Will Schroeder
There's this concept, though, that I think to me kind of is a through line through. We'll talk about kind of the continued development of the schema and everything here in a bit, but this idea that these paths were just always they were always there. Like we didn't discover them, we didn't, like invent this or something like that. Like all these attack paths have always been there and they're still there.
00:20:38:09 - 00:21:01:19
Will Schroeder
We just didn't kind of have a map or a way to visualize and uncover what all the were. So it's been kind of cool as the starting with those three nodes and everything. Right? But then as we started growing, like we attackers have executed a lot of these paths before. And we had. But then as we added more and more things to the BloodHound schema, just this, you know, the map got bigger and bigger and bigger for the past that we're always there.
00:21:01:20 - 00:21:06:10
Will Schroeder
We just kind of have that fog of war kind of cleared up, and we're able to see what was actually underneath.
00:21:06:11 - 00:21:26:09
Jared Atkinson
One of my favorite phrases is the map is not the territory. And the idea is, is that your the territory, the actual terrain that you're interacting with, its infinite, infinitely complex, right. But when you want to map it out, you have to necessarily ignore certain details so that you can have a shrunken down version of it so that you can make decisions.
00:21:26:09 - 00:21:43:15
Jared Atkinson
And, and I think the the idea is, is this really plays on what Andy said about lapse. Right? Which is at the beginning, you didn't even need BloodHound because the bridge 500 was the same everywhere. Once laps came out, that was no longer a base assumption you could make, and so you had to make your map more detailed.
00:21:43:16 - 00:21:59:23
Jared Atkinson
Right? But you kind of like want to make the map just detailed enough to get the job done. And so that's what you did. And then as BloodHound came out and people started getting wise to this idea of nested group membership and derivative local admin and all these types of things, there, there was a necessity and adding additional detail.
00:21:59:23 - 00:22:24:22
Jared Atkinson
And so maybe there's a that's a good transition point in the conversation to start talking about like what came next. So we had those kind of like three, those three nodes and I forget how many edges it started off with four five or whatever was three, three, okay. Three and three. And then there there was a moment when we kind of, when you realized that there was a need to expand the initial schema to include more information, kind of uncover more of that fog of war.
00:22:24:23 - 00:22:31:22
Jared Atkinson
Right? Because again, we're not creating the attack paths. The attack costs were already there. It's just a matter of uncovering them. Right?
00:22:32:01 - 00:22:55:16
Will Schroeder
I think the first major jump was it was Andy, myself and Lee Christiansen, Lea Chagolla Christensen know, were starting to dive into access control lists like on Windows Active Directory. Specifically, we ended up writing a, you know, 70 plus page white paper that got published and that was, you know, that was the the next kind of really big thing.
00:22:55:17 - 00:23:13:15
Will Schroeder
We're like, okay, we need to get all these new edges into BloodHound if we can. But it was such a bigger scale than the original three nodes and the original three edges, it seems, probably doesn't seem like a huge deal now, but it was a huge undertaking at the time for how we had to expand because it went to, you know, dozens, right, Andy?
00:23:13:15 - 00:23:19:16
Will Schroeder
Something like that. Just the complexity and more than it more than doubled. It went up by a factor of like 5 to 10.
00:23:19:18 - 00:23:21:01
Andy Robbins
Yeah. And there.
00:23:21:01 - 00:23:21:12
Andy Robbins
Were.
00:23:21:12 - 00:23:42:19
Andy Robbins
Huge design decisions we had to make at that time. Like, are we going to include the deniers? Are we going to try to parse a Dal in canonical order? Are we going to take into account generational distance of inherited aces? And I remember at that time Rohan and I were operating together quite frequently on on red team assessments.
00:23:42:20 - 00:24:12:04
Andy Robbins
Actually, I was his manager for a time at that time, and we decided the environments that were going into which were very hard targets and very big organizations, they didn't really have any deniers. They didn't really have a lot of conflicting inherited aces, you know, to worry about. So at that time, we said, if we want to ship this thing, then we need to we need to make some decisions about what resolution we're actually going to be including.
00:24:12:05 - 00:24:50:11
Andy Robbins
Like, to use your analogy, Jared, of the map not being in the territory. And those designs, those design decisions way back then still haunt us. Aren't you still are present today. Yeah. So it was it was, you know, did we get do we get everything right all the time? No obviously not. But I think like what Will is saying earlier we knew that this was something that was extraordinarily powerful and kind of, as you know, the custodians of that thing at that time, it was critical to get it right, as right as we knew how to.
00:24:50:12 - 00:25:08:00
Andy Robbins
So that was another thing that we spent. I honestly like, like looking back on it, like from when will have you and Lee, like initially started looking into ACLs until when the actual update happened, it was probably at least a year before we actually shipped it, and I believe it was a derby con. I think it's.
00:25:08:00 - 00:25:35:21
Rohan Vazarkar
It's really important to like, just keep in mind that a lot of the early days of BloodHound were done entirely through an offensive lens, and also through the lens of the assessments we were doing at the time. So, like many of the decisions were informed entirely by what we saw in environments on a regular basis. So, you know, when you look at what we have today where like we have this like behemoth of a product that does like all sorts of things and takes into account all these other things.
00:25:35:21 - 00:25:44:07
Rohan Vazarkar
And you look at some of these old ACS and you're like, well, why didn't they do deny ACS? It's like, well, we didn't need to back then because it just didn't exist.
00:25:44:09 - 00:25:46:17
Justin Kohler
I mean, it's it's still really rare.
00:25:46:19 - 00:25:48:10
Rohan Vazarkar
It's still exceedingly rare for.
00:25:48:10 - 00:25:50:13
Justin Kohler
What was very rare. Yeah. You know.
00:25:50:17 - 00:26:14:08
Andy Robbins
We were also doing a lot of this in our free time. We were we were we were traveling consultants together at the time and we were on the road together. And so what happens after the after the end of the workday? We go to the bar and keep working. So it would be at the bar Maggie's and working on working on all of this stuff until 11, 12, one, whatever.
00:26:14:13 - 00:26:28:22
Justin Kohler
So ACS were the first time you guys expanded the original graph, right? When you created BloodHound, did you know that that was going to happen, that you that or was that like, oh, we had this tradecraft that makes sense to put in this.
00:26:28:23 - 00:26:47:23
Rohan Vazarkar
At least speaking for myself, I can tell you that I never expected BloodHound to be like one tenth of what it is now, much less even like. I mean, I definitely wasn't thinking about any expansions to the graph when we first did BloodHound. Like, we were like, check out this cool POC that we released to everybody. It's awesome.
00:26:47:23 - 00:27:14:02
Speaker 5
And like, that was kind of where that whole conversation ended. And then like over time we're like, oh, like, you know, there's a lot more potential here and there's other stuff we can do. But as Andy said, it was all free time projects. So it was kind of just like it kind of came as it came and there was no like, yeah, there was no like forethought or planning into a lot of stuff, which if you look at some of the old iterations of the UI, you can definitely see there was no forethought into any of that stuff.
00:27:14:04 - 00:27:14:13
Rohan Vazarkar
I think.
00:27:14:13 - 00:27:16:01
Andy Robbins
Two, there was no roadmap.
00:27:16:02 - 00:27:17:09
Andy Robbins
Yeah.
00:27:17:11 - 00:27:48:10
Will Schroeder
Like Andy said, the the ACL stuff kind of emerge from some initial like offensive research that Lee and myself were doing. And then I think after we saw the ACL stuff or after that actually landed, we realized, oh, we could probably get all of Active Directory into here, or at least most of it, like a reasonable percentage of it, because I know the one of the next expansions was containers and Group policy one after that were some like can't lapse things like that.
00:27:48:10 - 00:28:07:18
Will Schroeder
We knew some of the edges would be a bigger challenge than others, but I think after we hit the ACL, we all realized like, oh, we can probably get a lot more of Active Directory into this. But we were still in our minds at that time, I think, conceptually still constrained to Active Directory itself, which obviously we kind of moved.
00:28:07:18 - 00:28:17:13
Will Schroeder
And we'll talk about that in a bit, I'm sure. But we kind of started to move beyond that. But those first those first few releases where we started to grow the coverage over Active Directory itself.
00:28:17:14 - 00:28:47:02
Jared Atkinson
I think Rohan's point is like really prescient about how, like, we were just building it as consultants based on our experience of trying to hack organizations, you know, like we were solving we were solving problems for ourselves, but probably like very practical problems. Right. And yeah, and like you talk about like executed, for instance. And I assume that what somebody realized at some point was, hey, when we laterally move between systems there, we are using certain types of like primitives.
00:28:47:02 - 00:29:10:12
Jared Atkinson
And those, those primitives can be mapped out of like with respect to what users or what principles have the ability to do that on which targets. Right. And so it's like once we once we understand stand that that is a graph relationship. Now it's a matter of can we calculate that in advance or collect the data that is necessary to calculate that in advance and start to draw those conclusions from that perspective?
00:29:10:13 - 00:29:18:12
Will Schroeder
I think that's around the time that we started quoting John Lambert's quote in every single presentation we had for a good, yeah, 8 or 9 years. Right, Andy?
00:29:18:14 - 00:29:19:00
Justin Kohler
What quote.
00:29:19:02 - 00:29:19:20
Andy Robbins
Never stopped.
00:29:19:22 - 00:29:22:21
Will Schroeder
What was it, Andy I'm sorry, I forgot. I think you're the keeper.
00:29:22:21 - 00:29:49:05
Andy Robbins
Of the quote. Something about attackers. Yeah, well, you know, you know what? You know what I wanted wanted to say there as well. Jared, to what you were just saying was the impetus for all of these updates was not coming from anywhere except for our own team necessarily. We were literally making this for our team, for ourselves and for our assessments.
00:29:49:05 - 00:30:13:19
Andy Robbins
And, you know, one of the things that I saw was, you know, why choose Active Directory? Why, why, why go? Why go here? Why go there? It's because the product was a reaction to our methodology as consultants. It wasn't the other way around. It wasn't. Let's build a product and then find a problem to solve. It was we have a really huge problem.
00:30:13:19 - 00:30:15:10
Andy Robbins
How do we fix it?
00:30:15:12 - 00:30:36:07
Will Schroeder
And also one kind of one really quick note to just add on to that, Andy, at least for me, from kind of the original power View side and the collection of things like that, something that was very important of why we went for Active Directory instead of another massive system is that as a domain authenticated user, you could collect most or all of this information.
00:30:36:13 - 00:30:56:04
Will Schroeder
So obviously things are different now for what as far as the remote administrator enumeration, remote session enumeration and things like that. But originally Active Directory was just kind of an open book. It's a directory versus like some kind of Linux based system, like you couldn't remotely retrieve the sewers file or something just as a random authenticated user. Right.
00:30:56:05 - 00:31:12:07
Will Schroeder
So it was I think we hit at director was common. We ran into it a lot and almost every environment we're in. But we also had unique collection mechanisms at the time that let us pull this in from an offensive perspective, as opposed to from an elevated like defensive perspective.
00:31:12:10 - 00:31:52:09
Jared Atkinson
And a really cool, right, like outcome of that is like you talked about, the authenticated users could enumerate everything, but also a lot of our power, like the PowerShell work that you had done in particular, Will, has caused Microsoft to notice and actually make systemic changes. So like I remember is Blackhat Europe and you and I were there I don't know what year was 2015 maybe and tell me or had the presentation about met CIS, which was the way that you could adjust the, the, the registry to limit authenticated users from being able to enumerate sessions, for instance, and so that that hinders the collection from the attacker's point of view in a substantial way.
00:31:52:09 - 00:32:02:13
Jared Atkinson
And now I believe that's that's like the default or at least some version of that is now the default. And that's like a direct Windows 10 1607. Yeah.
00:32:02:15 - 00:32:23:17
Justin Kohler
You guys are talking about the expansion and we, we the next, next phase was obviously like people with Active Directory. Once Azure came out, they connected it to enter ID and that will activate Azure Active Directory, which took me like solid three years to not say Azure Active Directory anymore. So then we expanded into that and then obviously BloodHound like open graph.
00:32:23:17 - 00:32:50:06
Justin Kohler
But but before that, before we get on to like the expansion side or if we want to spend more time there, I'm actually curious, like you guys were targeting domain admins before, and then you started targeting more than just domain admins as probably as you started attacking more things in customer environments. And so your picture of not just like what, what routes we could use, but what we could target kind of started to change, I would imagine.
00:32:50:08 - 00:33:14:06
Andy Robbins
So the question is we used to target domain admins and then we started targeting other things. The truth is, domain admins was never the target. Domain admins was just a convenient stop on the way to our objective. So our red team assessments were all objective based. We would work with our customer to figure out who's your adversary, what keeps you up at night, what file?
00:33:14:06 - 00:33:37:12
Andy Robbins
What system is crucial to the continuing operation of your business? Maybe a payroll system if it's like a generic company. And so if we want to get access to a system in a LAN where Active Directory is the canonical identity provider, domain admins will give you anything in that in that world. So domain admins is not the target domain.
00:33:37:13 - 00:33:43:05
Andy Robbins
Edmonds is the enabler that gets us to any target that we want to to to reach.
00:33:43:05 - 00:34:01:11
Justin Kohler
So then the the definition of then you guys brought in like this concept of high value targets. So like again you're not talking about the objective. You're saying high value targets like it's domain. I'm in equivalence that allow us to get to that objective. But the goal was never domain eminence. The goal that's a byproduct is what you're saying.
00:34:01:11 - 00:34:03:17
Justin Kohler
So I'm.
00:34:03:19 - 00:34:04:20
Andy Robbins
Stop along the way.
00:34:04:23 - 00:34:28:02
Justin Kohler
Yeah. Stereotypical pitch like that's part of what's now in in BloodHound Enterprise is is getting back to that original vision of blood of of what we are trying to do is isolate this critical components like we call that privilege zones and BloodHound enterprise, where you can isolate other things than just tiers, where most of the analysis in BloodHound kind of to date was just protecting that kind of tears or high value target, whatever.
00:34:28:04 - 00:34:50:00
Justin Kohler
Whatever controls the control plane is what you're saying. I before we kind of move on, I this is maybe a little bit of a step back in the conversation, but I'm curious, why did you always want to make it visual? Did you always like as in, you could put this out in text right on a, on a doc or something like that?
00:34:50:00 - 00:34:55:20
Justin Kohler
Did. Why did you always have the concept of, I want to show this visually with like, nodes and edges, like, like a map.
00:34:55:20 - 00:35:33:06
Andy Robbins
I remember at the time there were discussions about an idea called the Offensive dashboard, which the idea was to have like a, an operator assist, a piece of software that, you know, you pull up in a web browser and you've got, you know, here's some stuff, you know, that helps helps the operator out. So I think, I think having something that was, you know, browser based or something that was visual, something that was interactive, the way that a web application is, I think was always in my, to my recollection, part of the idea.
00:35:33:08 - 00:35:36:19
Andy Robbins
But Rohan, maybe you can speak more authoritatively to that than I can.
00:35:37:00 - 00:36:19:22
Rohan Vazarkar
I think, like, you know, one of the the kind of things that led to the visualization was that when we were, when we were building this whole thing, I mean, graphs are very natural for us to read as something that we've encountered in daily life, as in lots of places. But, you know, when we were building this whole thing, having a like really good user interface and user experience that people could interact with, like just became more and more like obvious as something we had to do because like once we built like the original like UI to try and like proof of concept, this like it was never I think it was a foregone conclusion
00:36:19:22 - 00:36:43:06
Rohan Vazarkar
that we were going to have some kind of UI to go with it because, like, we wanted to interact with the data in such a way that we could, like, easily answer the questions we wanted. And the way that manifested originally was like the worst web UI you can imagine, where like 80% of it was a graph and 20% of it was just two controls that let you go from point A to point B, like it was awful.
00:36:43:10 - 00:36:48:19
Rohan Vazarkar
It had like it had nothing that was like redeeming about it other than the fact.
00:36:48:19 - 00:36:52:21
Andy Robbins
That it worked. It worked. It works that redeems it. It works.
00:36:52:21 - 00:37:28:06
Rohan Vazarkar
And it let us answer our questions. And then after that, like it was like, okay, how do we refine this? How do we make this, like more accessible? Because like, once we kind of realized we had something there, like we were always going to show this to other people and like have people use it. But the other thing it really kind of let us do is, you know, as consultants, part of our job was going to people who might not be as technically oriented and trying to explain to them how we did what we did and like what it means, and going into like, client out brief and being like, hey, like, you know, we
00:37:28:06 - 00:37:47:00
Rohan Vazarkar
started here and we like jump to this random computer that had outlook and we stole a bunch of credentials is not nearly as impactful as showing them a graph which just says, like, look, here is the exact path that we took. Like this is the tool we use to do it. And this is like like bit by bit, exactly what it is.
00:37:47:00 - 00:38:09:14
Rohan Vazarkar
And people look at that graph and they say, oh, it makes sense because it's, it's natural for us to read things like that. So I think like the, you know, the evolution of, like having the interface for it was just a natural outcropping of like what we, what we had to do as consultants at the time, which, you know, just goes back to what we were saying earlier.
00:38:09:14 - 00:38:12:12
Rohan Vazarkar
It was built very much for our use case.
00:38:12:14 - 00:38:55:16
Andy Robbins
I think. I think an influence at that time as well on us was just an Warner had a capability called Domain Trust Mapper will like I can't remember if you had worked on that with them as well, but it was like it did nodal analysis of domain trusts. And I remember the customer that we created, BloodHound, you know, for basically I remember the domain trust mapping produced by Justin Warner's tool of, of that environment and how just how easy it made to understand the domain trust situation, which, first of all, domain trust are impossible to understand, know in the first place.
00:38:55:16 - 00:39:08:20
Andy Robbins
But then you start having lines and arrows, you know, on the screen, you actually start to like understand the impact of all those trusts. So I think I think that was part of it as well. I think that was an influence as well at that time.
00:39:08:20 - 00:39:28:20
Justin Kohler
I think for, for me, it gets everybody like anybody with any background in it. It seems like can start to reason about this versus like getting it out brief and not to say anything bad about a pen test report. I mean, we write a lot of them here at at spec drops, but it can be hard to to walk through that.
00:39:28:21 - 00:39:50:06
Justin Kohler
Right. But visually, just seeing an attack path in a graph paints a very different picture is where we talk about like uncovering the paths that were always there. It's kind of like I'm just showing you what an attacker could use before they get they use it on you. So like we're trying to give that visibility back like you guys were trying to use it to execute your.
00:39:50:07 - 00:39:51:07
Andy Robbins
Well and we did.
00:39:51:08 - 00:39:52:10
Justin Kohler
Yeah. Yeah.
00:39:52:15 - 00:39:53:11
Andy Robbins
But we did.
00:39:53:13 - 00:40:02:23
Justin Kohler
And then at some point that flipped to we actually have to have people have the ability to take action at this at scale. And obviously that's where BloodHound Enterprise came in.
00:40:03:00 - 00:40:18:00
Will Schroeder
And I know something that this kind of leads on from that kind of continuing with the evolution of the project, but, you know, the composition edges and Active Directory certificate services and some of the work that Lee and I did several years ago.
00:40:18:01 - 00:40:19:01
Will Schroeder
The anti-war work.
00:40:19:07 - 00:40:51:10
Will Schroeder
Or the intelligence work was even after that. Yeah, but the intelligent ADCs stuff or the composition edges kind of came about. But being able to have those more complex, you know, A and B, but in this particular way have to happen in those get collapsed down or expand it out. I think the ability to visualize those even more complex relationships has been very useful from that just interactive visualization or whatever standpoint that you're talking about to where people it's definitely easier to kind of just have it click than just reading, you know, all the little specific preconditions and things like that and via text.
00:40:51:11 - 00:41:18:17
Justin Kohler
Well, and I think it's also it can communicate different things to two different audiences. Right. So like an attacker or a security person, like I could understand that there's a path like an ADC's edge and this is a bad thing. And they can read on how to execute that. But then a composition edge, while it's useful for an attacker, right, you have to understand the certificates and stuff that you're capture that is also useful for a defender or somebody remediating the path.
00:41:18:18 - 00:41:31:18
Justin Kohler
Right? You have to understand the underlying components. And so if you just say, hey, this configuration exists like you kind of give them a homework assignment versus like here is literally everything that's adding up to this problem. And here's how you can take action against it.
00:41:31:20 - 00:41:54:20
Will Schroeder
And it also touches on just kind of briefly I'll be quick. But it was kind of in this period to as things were evolving, we started to realize that there was as much or more use in defense for BloodHound than just purely offense, because, again, we came from fantastic red team backgrounds, and that's kind of the genesis of the tool those first several years was this is easier ways to hack stuff, right?
00:41:54:21 - 00:42:15:16
Will Schroeder
And then as things started to volunteer time and we started to hear about blue teams using it regularly and they would know rig up like automatic collection scripts on their own and things like this, and try to have copies of the database and all this. And, you know, we didn't have obviously, we just didn't structured architecturally originally to be kind of a defensive support type thing.
00:42:15:16 - 00:42:32:16
Will Schroeder
So it was very interesting to see that we all kind of I think our Andy Rohan and I and a bunch of us started to realize like, oh, there's even more value in defense here. You're looking at the exact same data, the exact same problem, but just flipping your perspective instead of saying, like, I want to hack this, you're assuming will someone hack this?
00:42:32:16 - 00:42:42:20
Will Schroeder
And what's like, you know, was it the sparse cut Andy and some of these different like how do you isolate these things and tiering and all that kind of stuff to kind of come about it from a defensive perspective.
00:42:42:22 - 00:43:03:13
Jared Atkinson
I think there's also a trope in red teaming to some degree, which is like, obviously companies are hiring red teamers because they want to use that to become more secure, or at least that's one purpose for it. And there's a there's this trope to where it's like every year you come back to do a red team for the same customer, and you just execute the same exact attack path because they didn't actually fix it.
00:43:03:13 - 00:43:28:20
Jared Atkinson
And so there's there's something like, how can we leverage this thing which is making us successful as attackers, but actually make it to where we could help the customer remediate it? But also there's there's this idea of you found one attack path during a red team, or maybe a few like five attack paths during a red team. But then you could take kind of the essence of that attack path and then say, show me everywhere where this same problem manifests, right?
00:43:28:21 - 00:43:30:11
Jared Atkinson
And then you could write this.
00:43:30:13 - 00:43:47:00
Will Schroeder
In a lot of those outbreaks or kind of working with some of the defensive teams. I think this is also where started to evolve that we saw the defensive perspective is that we would start to instruct the blue teams on how to run it regularly, or they would ask us like, how could you do this? And we're like, yeah, you should be running this on a regular basis.
00:43:47:01 - 00:44:13:01
Will Schroeder
It shouldn't be. We come in the first day and have a very obvious path, and that's when also when things started to get more difficult for us as red teamers, in a good way. And that's when to me, I think the realization of, oh, this is actually having an impact on a lot of, you know, even potentially to a degree, the industry as a whole of like watching a lot of the things get more and more difficult because people were starting to run this and lock these things down on a regular basis.
00:44:13:03 - 00:44:46:05
Rohan Vazarkar
We actually went out to clients and we did effectively, like kind of a reverse consulting gig where like instead of attacking them, we would just go do a bunch of data collection for BloodHound, and we would turn that into kind of a defensive report of like, here are your like top issues that you have. So like there was a time when we were really considering this from like a defensive use case perspective, and we even did like cipher workshops for people to try to like, teach them how to use this defensively.
00:44:46:07 - 00:44:56:15
Rohan Vazarkar
Andy had this monstrosity of a power BI workbook that we were sharing with people that would do a lot of these, like analytics for us, but you know.
00:44:56:16 - 00:44:57:23
Andy Robbins
That it would try.
00:44:58:02 - 00:45:21:08
Rohan Vazarkar
Yeah, it tried. The idea of using what happened defensively was like very like it became more and more prominent in our minds with, funny enough, a lot of the pushback being this is a red team tool, so we can't use it to be. The number of times I heard that was kind of sad, honestly. But, you know, I think views eventually started to change.
00:45:21:12 - 00:45:31:16
Rohan Vazarkar
And, you know, then we had BloodHound Enterprise where we kind of tailored it to that entire use case. And I think that's when we started seeing like a lot of change on that side of things.
00:45:31:18 - 00:46:03:13
Andy Robbins
So back then, you know, the derivative local admin is like super effective, super tedious. And I remember at that time thinking, okay, like I'm operating, it's me and Will were in this closet somewhere on the East Coast operating from, you know, like plugged into the network of the customer site. And we're on like day 14 of trying to find by hand a derivative local admin path to get to domain app and, and then fast forward a couple of years to when Rohan and I are operating together.
00:46:03:13 - 00:46:24:10
Andy Robbins
We throw. We threw a BloodHound at this customer that had been running it defensively themselves for a few years and, you know, do some data collection, you know, domain users to domain admins. All right. Let's see what path there is. Wait a minute. What do you mean there's no path? There must be something a bug. What happened? Rohan, why did you break BloodHound?
00:46:24:12 - 00:46:49:16
Andy Robbins
It turned out that like they had not done. Or they. They had done, like, so much remediation and so much fix that there was no path for BloodHound to find from domain users to domain admins. And all of a sudden, you know, I was telling Will like, man, I wish we had so much. I wish we had more time to do more interesting things than just hunt for these paths by hand, because this is really tedious, man.
00:46:49:16 - 00:47:02:16
Andy Robbins
And then all of a sudden, yeah, we got lots of time because customers started to implement those fixes and I was like, okay, well, the add paths aren't going to work anymore. Let's go find something else.
00:47:02:18 - 00:47:25:08
Will Schroeder
And that's when also we, you know, we still got some some lifetime out of every time we have a major release, right, for researching new tradecraft with edges and things like that, like the, the stuff that year or two ago, Jared with the release was like like those paths have always been there. We've been in Lane for what, 20 plus years or whatever it is, you know, in varying different kind of kind of ways.
00:47:25:08 - 00:47:43:11
Will Schroeder
But we didn't have a way to model it really effectively because it was a particularly challenging problem. So same with the ADCs stuff. Active directory certificate services was in some environments for ten, 15, 20 years. But it's those passwords. Again I keep coming back to this. Those parts were always there. We just didn't have a way to kind of visualize them.
00:47:43:11 - 00:47:55:09
Will Schroeder
But as we on those harder, harder environments and as we like add some more paths in, then we might be able to come back. Sometimes we'd have a prerelease of some of the new parser collections or something, and then it felt. Then it felt awesome again.
00:47:55:09 - 00:48:35:00
Andy Robbins
But I remember, I remember there was a there was a customer who had like really great internal network segmentation, if I recall correctly, and like their tier zero boxes were like, you know, shoved away in a different Vlan that was off from the rest of the network. And maybe I have this right. Maybe you have it wrong, but will, I think I remember on that customer, I think you executed, you know, the schedule task deployment via GPO to that host that was tier zero, that like from our host, we logically couldn't communicate with because there was no network path directly to that host.
00:48:35:00 - 00:49:02:04
Andy Robbins
But what can every host in Active Directory communicate with the domain controller? And so it kind of it kind of reminds me also of like wills like Active Directory C2 like C2 with like add properties project. Was that like every year maybe you said this, but like every defender action has a tacker reaction. Or maybe I think that was you Jared who said that that was Isaac Newton actually.
00:49:02:06 - 00:49:14:02
Andy Robbins
Okay. So well you know, great great great minds, great minds. He had a great beard to just like you. But yeah, things evolve and change. Before we.
00:49:14:02 - 00:49:49:11
Rohan Vazarkar
Before we go any further, I just want to, like, clarify that Andy's burying the lead on that story about what happened in that this was this was the very last pen test that Andy and I ever did. The one where we ran BloodHound and didn't find anything. And this was after months of doing defensive engagements, and it was so bad that we were like, we had to actually ask other people at the company like what to do, because it had been so long since we had seen an environment where BloodHound didn't just give us the answers.
00:49:49:13 - 00:49:56:10
Rohan Vazarkar
It's like top ten most embarrassing moments of my entire testing career. So I wanted to make sure that full story was there.
00:49:56:16 - 00:49:57:06
Jared Atkinson
So.
00:49:57:06 - 00:50:00:13
Jared Atkinson
So embarrassing. He stopped being a consultant and he became an engineer.
00:50:00:15 - 00:50:02:18
Rohan Vazarkar
That's that's exactly what happened. Yeah.
00:50:03:00 - 00:50:19:18
Will Schroeder
I mean, if you flip that, though, far from I don't know, you can look at it from a perspective. If you shouldn't be the most embarrassing moment, it should be a proud moment, because literally, the work that we had done for all those years, right, is the reason that that became so secure from one, depending on how you look at it.
00:50:20:00 - 00:50:23:11
Will Schroeder
Yeah. Like we had like we actually made a difference for it, right.
00:50:23:12 - 00:50:29:16
Rohan Vazarkar
Sure. 100%. But as a pen tester, that was not a that was not a cool moment for me.
00:50:29:17 - 00:50:33:11
Will Schroeder
That was not the that was not the initial reaction, emotional reaction you had.
00:50:33:11 - 00:50:34:13
Rohan Vazarkar
Yes.
00:50:34:15 - 00:51:12:18
Andy Robbins
It was not. The initial emotional reaction was like, I have failed as an operator and I don't deserve to call myself a red teamer anymore. Maybe I never did so big, big time imposter syndrome moment. Yeah. But then, you know, after kind of, you know, recognizing that thought pattern for what it is, I think I think maybe I moved on to feeling kind of more satisfied that as a pen tester, I could go to a customer now and not just do the same thing year after year after year after year after year, and keep collecting a paycheck for doing the same thing over and over and over and over and over again, and just tail
00:51:12:18 - 00:51:23:00
Andy Robbins
chasing for decades, like seeing, seeing that tail chasing stop. That is, I think, one of the biggest impacts that the product has had. Nice BloodHound pun, by the way.
00:51:23:00 - 00:51:23:21
Jared Atkinson
That was nice.
00:51:24:00 - 00:51:26:15
Andy Robbins
There you go. There you go. It's just for you, Jared. Thanks. Just for you.
00:51:26:15 - 00:51:56:11
Justin Kohler
I know that customer was able to do it, you know, but like, again, like you guys were doing those defensive operations. You ran against that one customer that was able to use like the open source project to do it. And there have been few like several right over the years that have been able to do great work. But like, if that's kind of again, the genesis for why BloodHound Enterprise is created because like, well, a few and the pointy tip of the spear couldn't make use of like the open source tool to to to secure things.
00:51:56:13 - 00:52:18:06
Justin Kohler
You really wanted to kind of do that for the masses and not just like continue to have the attacker have the upper hand. So, gentlemen, Andy Rohan will thank you very much for joining us. Like it's super fun to hear all like the backstories and stuff and like where it came from. And we're going to we're going to do a next part where we go more into the defensive side.
00:52:18:06 - 00:52:34:10
Justin Kohler
So this is kind of a kind of capping out or concluding the the purely offensive work and kind of the lead up to BloodHound Enterprise and all the expansion there. But before we go, do you guys have any final thoughts words for this first part?
00:52:34:12 - 00:53:12:01
Andy Robbins
Just a quick thing I would like to say is back in 2016, we put this software out there as free and open source, which it still is. And personally, I'm very proud of ten years of an open source and free project being out there that we put out there free as in beer or free as in, if you've gotten any kind of value out of BloodHound, I would ask you to please consider making a donation to the Muscular Dystrophy Association, and you can go to MDA.org/donate.
00:53:12:03 - 00:53:14:09
Andy Robbins
To make a donation there.
00:53:14:11 - 00:53:18:05
Justin Kohler
That's awesome. Rohan will any last thoughts.
00:53:18:07 - 00:53:36:12
Rohan Vazarkar
For me? Like I started working on this ten years ago on a whim, tried to escape my roots as a programmer, and somehow went full circle and came back to being a programmer. And now I'm still a full time engineer working on the BloodHound team. So, you know, this is this is day to day for me and still fun.
00:53:36:12 - 00:53:38:05
Rohan Vazarkar
Still love it. Still really cool.
00:53:38:09 - 00:54:02:13
Will Schroeder
And for me, it's been a lot of the offensive work I've done over the last 10 or 15 years. Has not all of it, but a good chunk of it has kind of found its way into BloodHound itself, anywhere from the ACL stuff, active directory, certificate services, modeling, some of the relay, some of the newer stuff with open hounds that we'll talk about, you know, in the next section with some of the GitHub work that I did with Jared and things like that.
00:54:02:13 - 00:54:41:10
Will Schroeder
So it's been very cool for me to be able to see like research, kind of be able to be implemented into this project that continues to provide value for people. So it's been extremely rewarding for me from a career standpoint and just from a personal standpoint, from what we've been able to contribute to everything. I think, you know, anyone that kind of came up in the the offensive industry, you know, knows how much of everyone's career is built on top of other open source projects, you know, whether it's Metasploit and Impact and all these different types of tools that I looked up to for all my years kind of starting out.
00:54:41:10 - 00:54:56:13
Will Schroeder
So it's very surreal to, you know, kind of waking up one day, Andy and Rohan and realizing that BloodHound is kind of one of those de facto tools that fits in that, you know, in that pantheon of tools that people just tend to use all the time. It's just like, oh, yeah, of course you have BloodHound and you run that.
00:54:56:13 - 00:55:01:03
Will Schroeder
So it's been very, very rewarding to kind of see that evolution over the last ten years.
00:55:01:03 - 00:55:17:18
Rohan Vazarkar
For me, having like people in college come up to you at a conference when you're at a booth and tell you that they read about your tool in a textbook is like, truly a very surreal experience that also makes you feel incredibly old at the same time.
00:55:17:18 - 00:55:33:21
Justin Kohler
So that's awesome. Well, again, thank you guys for joining us for part one. And stay tuned for part two, where we kind of go on the more of the defensive use case. And then the ever expanding graph beyond Active Directory. Thank you.
00:55:34:00 - 00:55:34:07
Jared Atkinson
Awesome.
00:55:34:07 - 00:55:36:03
Jared Atkinson
Thanks everybody. Thank you.