HoundMasker: Privacy-Preserving Attack Path Analysis | Hacker Summer 2026 Community Session 2

HoundMasker: Privacy-Preserving Attack Path Analysis | Hacker Summer 2026 Community Session 2

Source: YouTube · Altered Security · published Jul 27, 2026 · 43:29

Penetration Testing
No ratings yet Log in to rate
Transcript Available
Description

This presentation introduces OneMask, a Python tool designed to mask sensitive identity information in Bloodhound JSON data, enabling safe analysis of internal network Active Directory structures using Large Language Models (LLMs) without compromising privacy 11:32.

Key Takeaways:
• Active Directory is central to enterprise security, and Bloodhound is a standard tool for enumerating attack paths, but its data contains sensitive identifiers that pose privacy risks when shared 03:30.
• Uploading raw Bloodhound data to public LLMs is dangerous as models may retain sensitive infrastructure details; OneMask solves this by anonymizing the data while preserving structural relationships 10:23.
• The tool masks usernames, computer names, and descriptions using random strings but preserves Security Identifiers (SIDs) and domain trust relationships to maintain the integrity of the attack graph 14:32.
• A live demo showed OneMask processing JSON files to generate anonymized outputs, which were then queried via a Bloodhound MCP server to demonstrate privilege escalation paths without revealing real identities 18:34.
• While effective, the tool currently supports only specific Bloodhound JSON files and has limitations regarding certain attribute masking, requiring users to verify data for residual sensitive information before use 38:53.

OneMask facilitates secure collaboration and AI-assisted security analysis by removing personally identifiable information while keeping the technical context intact for pentesters and researchers.

Sources:

  • 11:32 Introduction of OneMask tool for data privacy.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Hay. Hay. So we are all I should be starting in five minutes anymore. Time. Let's get started te presentas and so
they will be talking about to that. I had build a couple of weeks
back and it's about blade and things like that when like receiving
that that bots without leading disclosure of any identity
information things about that so before going to that quickly about me
the people who don't know about
me saque y work assist security. Consulten
that netsuite and I am the founder of where we bringing people who are the security like CEOs
sos and security researchers who talk about cybersecurity segment which
is not really more about so we have been source here Internet
go out and check it out and I have been talking at different communities. Besides and filmore communities as well, so tha…