SpecterOps, the company behind the development of BloodHound and the originator of Identity Attack Path Management (APM), launched new platform enhancements that will enable enterprise security professionals to identify, prioritize, and mitigate attack paths in their hybrid infrastructures and AI-operated environments.
The new enhancements include native integration with AWS and Microsoft Entra Agent ID in BloodHound Enterprise. Furthermore, SpecterOps introduced a new interface called BloodHound Hunter for bringing graph-based intelligence about adversaries into automated security operations through an AI-agent.
Also Read: Blackbaud Expands ‘Agents for Good’ Suite, Unveiling Next-Generation AI Capabilities for Its Social Impact Platform
With organizations moving faster towards adopting autonomous artificial intelligence and multi-cloud environments, the problem of exposure management becomes increasingly difficult. This is where SpecterOps comes into play, helping organizations visualize connections between identities, permissions, and misconfigurations, and cutting off pathways before any attackers could use them.
“Attackers do not move through isolated systems. They move through the relationships between them, chaining trust, permissions, and misconfigurations across cloud, identity, and infrastructure until they achieve their objectives,” said Jared Atkinson, Chief Technology Officer at SpecterOps. “Through the growing library of BloodHound Enterprise extensions and new BloodHound Enterprise MCP, identity and security teams can trace and sever abusable pathways using each platform’s native access logic and put that intelligence to work through their own trusted AI agents and workflows.”
Key Platform Enhancements
- Integration of Security Solutions: Using BloodHound Hunter Through the Model Context Protocol (MCP), BloodHound Hunter enables the integration of organization-approved AI solutions and knowledge sources with the BloodHound Enterprise database. It helps security operations interpret graph metrics through a business context, prioritize actions based on local risk models, and implement Privilege Zones to protect valuable enterprise assets.
- Unified Hybrid Environment Attack Mapping: BloodHound Enterprise now combines telemetry from AWS and Microsoft Entra Agent ID alongside existing integrations with Okta, GitHub, Jamf, Active Directory, and Entra. The unified attack graph lets defenders trace exposure routes spanning cloud, SaaS, code repositories, and on-premises systems to identify optimal chokepoints for remediation.
- Targeted Risk Elimination in AWS: Built-in AWS support surfaces hidden lateral movement channels and privilege escalation routes. Security personnel can establish granular Privilege Zones around critical cloud stores, IAM roles, and infrastructure assets to maintain zero-trust boundaries.
- Context-Aware Exposure Analysis for AI Identities: Informed by SpecterOps research into shadow configurations and Copilot deployment risks, the platform’s Entra Agent ID integration helps security teams assess how AI agents, service principals, administrative roles, and delegated credentials create indirect pathways to highly sensitive data.
The new features also augment BloodHound Scentry, SpecterOps’ managed offering that pairs expert offensive tradecraft with BloodHound Enterprise to help enterprises mature their attack path management programs.


