bloodhound-narratorTurn BloodHound attack path exports into dual-layer security reports — CISO executive prose on top, technical remediation playbook below. Automates Active Di...
Install via ClawdBot CLI:
clawdbot install kurostrike/bloodhound-narratorGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Generated Oct 2, 2026
After completing a BloodHound-mapped AD pentest, the consultant exports attack path Cypher JSON and runs BloodHound Narrator to instantly produce a dual-layer report. This eliminates hours of manual prose writing while ensuring every discovered path is scored consistently and paired with remediation guidance.
Internal blue teams periodically ingest BloodHound collections to identify the most dangerous paths in their own forest and prioritize hardening efforts. The severity-scored executive summary helps justify remediation projects to leadership while the technical appendix provides concrete PowerShell fixes and Event IDs to monitor.
Consultants serving government, defense, financial, or OT environments run BloodHound Narrator entirely offline with no API calls or data egress, satisfying classification and data-sovereignty requirements. Findings can be delivered as Markdown reports without any sensitive topology leaving the enclave.
Security teams auditing Active Directory Certificate Services abuse paths (ESC1-ESC13, Golden Certificate, CA management rights) use the dedicated AD CS scoring to surface certificate template misconfigurations. The tool translates complex PKI attack patterns into executive-level impact statements and specific template hardening steps.
During mergers and acquisitions, assessors ingest BloodHound exports from the target organization to rapidly quantify AD risk posture for deal teams. The CISO-layer narrative frames identity compromise paths as business risk, while the technical appendix provides the acquirer a prioritized hardening roadmap for post-close integration.
The MIT-0 licensed tool is distributed freely to drive adoption, while revenue comes from commercial support contracts, enterprise onboarding, and training courses teaching AD attack path analysis and reporting workflows. Consulting firms and MSSPs pay for SLAs and customized severity scoring templates.
A hosted or on-prem orchestration layer wraps BloodHound Narrator to manage engagements, store prior reports, standardize client branding, and provide team collaboration. Despite the tool being offline, firms pay for the workflow and collaboration layer.
Security consultancies use BloodHound Narrator as a force multiplier to reduce report-writing labor by 60-80%, allowing them to take on more AD audit engagements with the same headcount. The value capture is margin expansion and higher engagement throughput rather than direct software sales.
💬 Integration Tip
Run the included synthetic test suite first to validate your PowerShell environment and report output format, then automate ingestion by hooking your BloodHound export pipeline or sharpHound collection schedule directly into the script. Extend the EdgeWeights table in scripts/lib/SeverityClassifier.txt to tune severity scoring for your organization's specific risk model.
Scored Sep 28, 2026
Medical device risk management specialist implementing ISO 14971 throughout product lifecycle. Provides risk analysis, risk evaluation, risk control, and pos...
When the user wants to plan a product launch, feature announcement, or release strategy. Also use when the user mentions 'launch,' 'Product Hunt,' 'feature r...
When the user wants to build a free tool for marketing — lead generation, SEO value, or brand awareness. Use when they mention 'engineering as marketing,' 'f...
管理多类型项目看板,支持新增项目、变更状态与版本、分类管理及查看项目总览和变更日志。
Competitor Analysis — SEO/GEO Intelligence & Market Positioning. Analyze competitor SEO rankings, AI search citations, content strategy, and market posi...
Conduct structured PHQ-9 depression symptom screening and submit the completed assessment for evaluation.