
Mapping RBAC in BloodHound | SO-CON 26
Source: YouTube · SpecterOps · published Jun 4, 2026 · 37:32
Hope Walker presents a solution for improving how BloodHound maps Role-Based Access Control (RBAC) in Entra ID, addressing critical gaps in shortest path calculations, scoped assignments, and custom roles 0:00.
Key Takeaways:
• Current BloodHound RBAC mapping has five key issues: inaccurate shortest path calculations, limited scoped assignment support, no custom role visibility, static role representations, and resulting inaccurate findings 3:30.
• The proposed solution abstracts role assignments into separate nodes and uses composition edges that collapse multiple permissions into single edges, preserving shortest path accuracy 6:30.
• By mapping individual permissions rather than predefined roles, custom roles automatically gain coverage since they reuse permissions from built-in roles 8:30.
• Scoped role assignments, such as administrative units, are handled by connecting principals only to resources within that specific scope 12:00.
• This approach is designed to be repeatable across multiple RBAC systems including Azure RM and Intune, though implementation is still in progress 14:00.
This research provides a foundational framework for more accurate attack path analysis in environments using Microsoft's RBAC systems.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
What up, nerds? Thanks for coming to my talk so I can be king nerd for the next 45 minutes while we discuss mapping our back in BloodHound. So, for those of you who don't know me, my name is Hope Walker. I am a senior security researcher at SpecterOps. My main focus is in Azure and Entra ID. I have 10 years of offensive cybersecurity experience. Prior to joining our research team, I did consulting for SpecterOps. And then prior to that in another life, I did long-term red teaming for the DOD. I have done quite a bit of teaching. I've created both our Active Directory course and our Azure course. So, lots of experience with that. And in my free time, I'm a hobby collector. There are a variety of interests. If you want to talk to me about anything that's on the list, and there's probably mor…