Mapping RBAC in BloodHound | SO-CON 26

Mapping RBAC in BloodHound | SO-CON 26

Source: YouTube · SpecterOps · published Jun 4, 2026 · 37:32

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Hope Walker presents a solution for improving how BloodHound maps Role-Based Access Control (RBAC) in Entra ID, addressing critical gaps in shortest path calculations, scoped assignments, and custom roles 0:00.

Key Takeaways:
• Current BloodHound RBAC mapping has five key issues: inaccurate shortest path calculations, limited scoped assignment support, no custom role visibility, static role representations, and resulting inaccurate findings 3:30.
• The proposed solution abstracts role assignments into separate nodes and uses composition edges that collapse multiple permissions into single edges, preserving shortest path accuracy 6:30.
• By mapping individual permissions rather than predefined roles, custom roles automatically gain coverage since they reuse permissions from built-in roles 8:30.
• Scoped role assignments, such as administrative units, are handled by connecting principals only to resources within that specific scope 12:00.
• This approach is designed to be repeatable across multiple RBAC systems including Azure RM and Intune, though implementation is still in progress 14:00.

This research provides a foundational framework for more accurate attack path analysis in environments using Microsoft's RBAC systems.

Sources:

  • 0:00 Introduction and speaker background
  • 3:30 Problems with current BloodHound RBAC mapping
  • 6:30 Solution: role assignment nodes and composition edges
  • 8:30 Custom role coverage through permission map

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

What up, nerds? Thanks for coming to my talk so I can be king nerd for the next 45 minutes while we discuss mapping our back in BloodHound. So, for those of you who don't know me, my name is Hope Walker. I am a senior security researcher at SpecterOps. My main focus is in Azure and Entra ID. I have 10 years of offensive cybersecurity experience. Prior to joining our research team, I did consulting for SpecterOps. And then prior to that in another life, I did long-term red teaming for the DOD. I have done quite a bit of teaching. I've created both our Active Directory course and our Azure course. So, lots of experience with that. And in my free time, I'm a hobby collector. There are a variety of interests. If you want to talk to me about anything that's on the list, and there's probably mor…