Skip to main content

azurehound-analysis

Use for AzureHound and BloodHound Azure or Entra ID attack-path work when the user clearly means Azure semantics such as Global Administrator, privileged Entra roles, service principals, applications, app roles, managed identities, subscriptions, resource groups, VMs, Key Vaults, or hybrid AD/Azure paths. Do not use for generic BloodHound connection checks, unclear graph-domain triage, explicit Cypher authoring/review, or OpenGraph schema-extension work.

ソース情報

リポジトリ
SpecterOps/skills
ソースの最終更新活動
2026年5月29日 15:51
検出された SKILL.md の言語
英語
スター
689
フォーク
77

インストール方法

デフォルトでは、最初にソースを確認する Prompt が選択されています。直接コマンドに切り替えるか、ローカルコピーをダウンロードすることもできます。

ソースファイルを確認

インストールを決める前に、SKILL.md と SkillsMP に表示されている付属ファイルをお読みください。

ファイルエクスプローラー
4 ファイル

SKILL.md を表示中

SKILL.md
ソースの指示 · 読み取り専用プレビュー
name
azurehound-analysis
description
Use for AzureHound and BloodHound Azure or Entra ID attack-path work when the user clearly means Azure semantics such as Global Administrator, privileged Entra roles, service principals, applications, app roles, managed identities, subscriptions, resource groups, VMs, Key Vaults, or hybrid AD/Azure paths. Do not use for generic BloodHound connection checks, unclear graph-domain triage, explicit Cypher authoring/review, or OpenGraph schema-extension work.
metadata
{"author":"GhostWorks"}
# AzureHound Use this skill for AzureHound / Entra ID BloodHound query design and attack-path triage. ## Required context - Authorized Azure tenants/subscriptions and whether AzureHound/Entra collection is present. - Known object IDs, tenant names, privileged roles, subscriptions, or resource scopes. - Hybrid collection availability when paths cross AD, GitHub, Okta, or SCIM. ## Workflow 1. Read `../../references/docs/bloodhound-query-methodology.md` and `../../references/docs/azurehound-methodology.md`. 2. Search `../../references/query-indexes/azurehound.md` for a matching Query Library pattern. 3. Inspect the snapshot and confirm `AZ*` labels/edges before adapting. 4. Use exact `objectid` filters when possible and bound broad tenant paths. 5. Explain each path segment by platform and collector source. ## Common pivots - Users/groups/service principals to privileged Entra roles. - App owners, app role assignments, credentials, and Graph API permission edges. - Managed identities to Azure resources. - Subscription/resource group/VM/Key Vault control paths. - AAD/Entra Connect and synced identity bridges. - GitHub/OIDC or Okta/SCIM hybrid paths when data is present. ## Output Use the shared output contract from `$bloodhound-query` and include Azure-specific caveats such as display-name ambiguity, tenant-scale query cost, non-traversable Graph API edges, and collector freshness.
GitHubで見る