
Forgotten Group Policy Paths: Integrating hidden OU & Site Attacks into BloodHound | SO-CON 26
Source: YouTube · SpecterOps · published Jun 4, 2026 · 44:55
BLUF: The presenter details two key contributions to BloodHound that enhance Active Directory attack path analysis by integrating hidden Organizational Units and site topology data 0:27.
Key Takeaways:
• The presentation focuses on integrating hidden organizational units and Active Directory site attacks into BloodHound to improve reconnaissance accuracy 0:05.
• The first major contribution, released in April 2024, addressed the detection of compromise edges related to organizational units 0:33.
• The second contribution, released in November 2025, expanded coverage to include site server and subnet objects, addressing previous blind spots in network topology 0:41.
• These updates allow red teamers to identify more complex privilege escalation paths that were previously invisible to standard BloodHound queries 0:47.
Closing Statement:
These enhancements significantly deepen the understanding of Active Directory trust relationships and network constraints for security professionals.
Sources:
- 0:05 Introduction to the topic of hidden organizational units and site attacks.
- 0:33 Details on the April 2024 contribution regarding organizational unit compromise edges.
- 0:41 Overview of the November 2025 update covering site servers and subnets.
- 0:47 Explanation of how these contributions link together to improve attack path visibility.
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
For this presentation, we'll be talking a little bit about Group Policy Objects. And more specifically, we are going to talk about how I integrated some hidden organizational units and Active Directory site attacks into BloodHound. Uh very quickly, so I'm Gautier Roland. I'm from Paris. I'm a pentester and red teamer at Synacktiv. And I kind of like Active Directory and Windows. So, a few words of introduction. Um for this presentation that will be telling the story between behind two contributions that I made to BloodHound. Uh the first one was in April 2024 and was about uh organizational units compromise edges. And the second one was in November 2025 and was about uh sites, site server, and subnet objects. Um before going any further, both of these contributions were actually linked to …