Skip to content
BloodHound alternative

ADscan vs BloodHound: BloodHound shows you the path. ADscan walks it.

BloodHound is the standard for mapping Active Directory attack paths, and a genuinely good one. This page is not an attempt to unseat it. It is where ADscan picks up where the graph stops: taking the path from a low-privilege user to full domain takeover, proving the exposure is real, and handing you the compliance evidence to go with it.

The one difference that matters

Mapping tells you a path could exist. Exploiting proves it does.

BloodHound collects your directory and draws the edges — who can reset whose password, which ACL grants control, where a Kerberos delegation opens a door. That map is invaluable. But an edge on a graph is a hypothesis. Under real conditions, a path can be blocked by a control the graph cannot see, or it can be even more open than the graph suggests. ADscan settles the question by running the path end to end, with guardrails, and reverting each change it makes. What you get back is not “this looks exploitable” but “this was exploited, here is the proof, here is the exact fix.”

What BloodHound gives you

The map of every path

A directory-wide graph of identities, permissions and trust relationships, and the choke points that collapse many paths at once when you fix them. The reference tool for understanding how privilege moves through your domain.

What ADscan adds on top

The proof the path is real

ADscan takes those paths and executes them — from an unprivileged foothold to Domain Admin — so the finding is validated, not assumed. Each finding maps to DORA, NIS2, ENS and ISO 27001, and the whole thing runs on-premise. Your AD data never leaves your infrastructure.

ADscan vs BloodHound, side by side

Where each tool is built to be strong.

BloodHound comes in two forms: Community Edition (CE), the free Apache-2.0 tool from SpecterOps, and BloodHound Enterprise (BHE), the commercial continuous-monitoring product. The honest read of the row is: they own mapping, ADscan owns proving.

ADscan compared with BloodHound Community Edition and BloodHound Enterprise
DimensionADscanBloodHound CEBloodHound Enterprise
Primary jobExploit the path to prove itMap and visualise the pathMap, prioritise, track fixes
Executes the attack pathYes — runs it to Domain AdminNo — shows the route, you driveNo — maps and scores only
Attack-path graphYes, BloodHound-compatibleThe category standardContinuous, enterprise graph
Guardrails + rollback on live ADYes, reverts each changeRead-only collectorRead-only collector
Compliance mapping (DORA / NIS2 / ENS / ISO 27001)Native, per findingNoNo
Deployment / data residencyOn-prem, AD data never leavesSelf-hosted, on-premSaaS / managed
LicenceFree, source-available (BSL 1.1)Apache-2.0, open sourceCommercial
InteroperabilityImports / emits BloodHound dataNative SharpHound / collectorsSpecterOps ecosystem

Filled node = a deliberate strength. Ring = genuinely covered. Half = covered but shallow or conditional. Dash = not covered. This is a capability comparison, not a scorecard — the tools are built for different jobs.

They work together

ADscan speaks BloodHound. Keep the graph you already trust.

This is not a rip-and-replace. ADscan produces a BloodHound-compatible collection, so the graph you rely on stays in the picture. If you already run BloodHound, ADscan slots in as the exploitation and compliance layer beside it — the map from one, the proof and the audit evidence from the other.

Interoperable by design

ADscan emits a BloodHound-compatible collection and can work from the same graph data. You are not throwing away the visualisation your team knows.

Map first, then prove

Use BloodHound to see the paths and the choke points. Use ADscan to confirm which of them an attacker can actually walk today, and to close them.

One report a board reads

ADscan turns the validated paths into a report that maps to DORA, NIS2, ENS and ISO 27001 — the layer a graph tool was never meant to cover.

What ADscan actually runs

104 techniques catalogued. 71 it executes for you.

Where a graph tool describes an edge, ADscan carries a working technique behind it. The catalogue covers 104 Active Directory attack techniques; 71 of them ADscan executes automatically, end to end (the rest are detected and mapped but not auto-run). That includes the full ADCS certificate-abuse span from ESC1–ESC17, and it produces 79 distinct finding types, each written up with evidence and a fix.

104AD attack techniques catalogued
71techniques ADscan executes end to end
79distinct finding types, each with evidence and a fix
Which one do you reach for?

The honest fit test.

Reach for ADscan when
  • You need to prove a path is exploitable, not just that it might be
  • You are in scope for DORA, NIS2, ENS or ISO 27001 and need mapped evidence
  • You want the exploitation run on-premise, with AD data staying inside your walls
  • You want a report a CISO or an auditor can act on, not only a graph
  • You already use BloodHound and want the exploitation layer beside it
Reach for BloodHound when
  • You want to explore and visualise the attack-path graph interactively
  • You need the free, open-source collector for ad-hoc pentest work
  • You want continuous identity-graph monitoring and choke-point prioritisation (Enterprise)
  • Exploitation and compliance evidence are not what you are solving for right now

Most teams do not choose one over the other. BloodHound CE is the free, open-source (Apache-2.0) mapping standard; ADscan is the exploitation and compliance layer that turns its map into proof.

The one proof point we stand on
In the 6 regulated entities where I ran it, 100% had at least one path to full domain takeover. A map would have shown the edges. What changed the conversation was walking the path and handing over the proof.
Yeray Martín, founder, senior penetration tester
> 95%of environments have attack paths — the gap between a map and a proven exploit
The honest next step

You have the map. See the path walked on your own AD.

A free demo, run by an AD specialist on your real Active Directory. We take a path from a low-privilege user to Domain Admin, prove the exposure, and map it to DORA, NIS2, ENS and ISO 27001 — delivered the same day.

BloodHound Alternative — ADscan vs BloodHound Compared | ADscan