AI & TechArtificial IntelligenceCybersecurityNewswireTechnology

SpecterOps adds AWS attack path management and AI to hybrid security

Originally published on: July 29, 2026
▼ Summary

– BloodHound Enterprise now supports Amazon Web Services and Microsoft Entra Agent ID, expanding attack path management across cloud, identity, and on-premises systems.
– A new AI agent interface, BloodHound Hunter, connects approved AI agents to BloodHound findings via the Model Context Protocol for environment-specific remediation prioritization.
– The tool maps attack paths across hybrid environments, allowing teams to trace a foothold in one platform to critical assets in another and sever it at the most effective chokepoint.
– With native AWS support, BloodHound Enterprise surfaces traversable paths and enables Privilege Zones around vital data stores or assets to block escalation.
– The Microsoft Entra Agent ID extension extends attack path management to Copilot agents and AI identities, revealing indirect paths to privileged access through delegated identities and permissions.

SpecterOps has unveiled a major update to its security platform, designed to give defenders a real-time, dynamic view of how adversaries navigate hybrid environments. The goal is to proactively shut down exploitable pathways before attackers can leverage them. BloodHound Enterprise now extends its attack path management capabilities to Amazon Web Services and Microsoft Entra Agent ID, broadening coverage across cloud and identity systems.

A new AI-powered interface, BloodHound Hunter, injects adversary intelligence directly into AI-assisted security workflows. This allows teams to harness the full power of the attack path graph, focusing on the risks that matter most to the business.

“Attackers do not move through isolated systems. They move through the relationships between them, chaining trust, permissions, and misconfigurations across cloud, identity, and infrastructure until they achieve their objectives,” said Jared Atkinson, Chief Technology Officer at SpecterOps. “Through the growing library of BloodHound Enterprise extensions and new BloodHound Enterprise MCP, identity and security teams can trace and sever abusable pathways using each platform’s native access logic and put that intelligence to work through their own trusted AI agents and workflows.”

BloodHound Enterprise identifies and prioritizes attack paths across identity providers, cloud platforms, applications, and repositories. It then delivers remediation guidance to close those pathways before exploitation occurs. This proactive approach is especially critical as enterprises deploy AI agents, allowing defenders to block pathways rather than relying solely on detection and response after the fact. With BloodHound Hunter, customers can bring their own trusted AI agents and knowledge sources into the BloodHound data ecosystem. Findings are evaluated against their specific environment, controls, and priorities.

The new capabilities include:

Add attack path intelligence to AI Workflows: Built natively into BloodHound Enterprise and leveraging the Model Context Protocol, BloodHound Hunter connects approved AI agents and knowledge sources directly to BloodHound Enterprise findings. Teams can prioritize remediation based on their specific environment, translate technical findings into language executives and identity teams can understand, and pinpoint key assets or enclaves to protect with Privilege Zones.

Map attack paths across hybrid environments: With AWS and Microsoft Entra Agent ID joining existing support for Okta, GitHub, Jamf, Active Directory, and Entra, BloodHound Enterprise now resolves dangerous trust and identity relationships using a single attack graph that spans cloud, SaaS, code, AI, and on-premises systems. Security teams can trace an attack path from a foothold in one platform to critical assets in another, then sever it at the most effective chokepoint.

Eliminate attack paths to critical assets within AWS: Native support for AWS allows BloodHound Enterprise to surface traversable paths and pinpoint chokepoints that prevent a foothold from escalating into a full-scale attack. Security teams can also implement Privilege Zones around vital data stores, roles, or assets, protecting them on their own terms.

Evaluate AI agents and identities within the broader context of enterprise risk: Built on SpecterOps research into abusable Copilot configurations, the BloodHound Enterprise extension for Microsoft Entra Agent ID extends attack path management to Microsoft Copilot agents and AI identities. Security teams can now investigate how AI agents, delegated identities, service principals, and administrative permissions create indirect pathways to privileged access.

These capabilities also enhance the value of BloodHound Scentry, which combines SpecterOps tradecraft expertise with BloodHound Enterprise to accelerate identity attack path management maturity.

(Source: Help Net Security)

Topics

attack path management 98% bloodhound enterprise 95% cloud security 92% ai security agents 90% identity security 88% hybrid environment 85% remediation guidance 83% privilege zones 80% microsoft entra agent id 78% AWS Integration 76%