ADscan vs BloodHound: BloodHound shows you the path. ADscan walks it.
BloodHound is the standard for mapping Active Directory attack paths, and a genuinely good one. This page is not an attempt to unseat it. It is where ADscan picks up where the graph stops: taking the path from a low-privilege user to full domain takeover, proving the exposure is real, and handing you the compliance evidence to go with it.
Mapping tells you a path could exist. Exploiting proves it does.
BloodHound collects your directory and draws the edges — who can reset whose password, which ACL grants control, where a Kerberos delegation opens a door. That map is invaluable. But an edge on a graph is a hypothesis. Under real conditions, a path can be blocked by a control the graph cannot see, or it can be even more open than the graph suggests. ADscan settles the question by running the path end to end, with guardrails, and reverting each change it makes. What you get back is not “this looks exploitable” but “this was exploited, here is the proof, here is the exact fix.”
The map of every path
A directory-wide graph of identities, permissions and trust relationships, and the choke points that collapse many paths at once when you fix them. The reference tool for understanding how privilege moves through your domain.
The proof the path is real
ADscan takes those paths and executes them — from an unprivileged foothold to Domain Admin — so the finding is validated, not assumed. Each finding maps to DORA, NIS2, ENS and ISO 27001, and the whole thing runs on-premise. Your AD data never leaves your infrastructure.
Where each tool is built to be strong.
BloodHound comes in two forms: Community Edition (CE), the free Apache-2.0 tool from SpecterOps, and BloodHound Enterprise (BHE), the commercial continuous-monitoring product. The honest read of the row is: they own mapping, ADscan owns proving.
| Dimension | ADscan | BloodHound CE | BloodHound Enterprise |
|---|---|---|---|
| Primary job | Exploit the path to prove it | Map and visualise the path | Map, prioritise, track fixes |
| Executes the attack path | Yes — runs it to Domain Admin | No — shows the route, you drive | No — maps and scores only |
| Attack-path graph | Yes, BloodHound-compatible | The category standard | Continuous, enterprise graph |
| Guardrails + rollback on live AD | Yes, reverts each change | Read-only collector | Read-only collector |
| Compliance mapping (DORA / NIS2 / ENS / ISO 27001) | Native, per finding | No | No |
| Deployment / data residency | On-prem, AD data never leaves | Self-hosted, on-prem | SaaS / managed |
| Licence | Free, source-available (BSL 1.1) | Apache-2.0, open source | Commercial |
| Interoperability | Imports / emits BloodHound data | Native SharpHound / collectors | SpecterOps ecosystem |
Filled node = a deliberate strength. Ring = genuinely covered. Half = covered but shallow or conditional. Dash = not covered. This is a capability comparison, not a scorecard — the tools are built for different jobs.
ADscan speaks BloodHound. Keep the graph you already trust.
This is not a rip-and-replace. ADscan produces a BloodHound-compatible collection, so the graph you rely on stays in the picture. If you already run BloodHound, ADscan slots in as the exploitation and compliance layer beside it — the map from one, the proof and the audit evidence from the other.
Interoperable by design
ADscan emits a BloodHound-compatible collection and can work from the same graph data. You are not throwing away the visualisation your team knows.
Map first, then prove
Use BloodHound to see the paths and the choke points. Use ADscan to confirm which of them an attacker can actually walk today, and to close them.
One report a board reads
ADscan turns the validated paths into a report that maps to DORA, NIS2, ENS and ISO 27001 — the layer a graph tool was never meant to cover.
104 techniques catalogued. 71 it executes for you.
Where a graph tool describes an edge, ADscan carries a working technique behind it. The catalogue covers 104 Active Directory attack techniques; 71 of them ADscan executes automatically, end to end (the rest are detected and mapped but not auto-run). That includes the full ADCS certificate-abuse span from ESC1–ESC17, and it produces 79 distinct finding types, each written up with evidence and a fix.
The honest fit test.
- You need to prove a path is exploitable, not just that it might be
- You are in scope for DORA, NIS2, ENS or ISO 27001 and need mapped evidence
- You want the exploitation run on-premise, with AD data staying inside your walls
- You want a report a CISO or an auditor can act on, not only a graph
- You already use BloodHound and want the exploitation layer beside it
- You want to explore and visualise the attack-path graph interactively
- You need the free, open-source collector for ad-hoc pentest work
- You want continuous identity-graph monitoring and choke-point prioritisation (Enterprise)
- Exploitation and compliance evidence are not what you are solving for right now
Most teams do not choose one over the other. BloodHound CE is the free, open-source (Apache-2.0) mapping standard; ADscan is the exploitation and compliance layer that turns its map into proof.
“In the 6 regulated entities where I ran it, 100% had at least one path to full domain takeover. A map would have shown the edges. What changed the conversation was walking the path and handing over the proof.”
You have the map. See the path walked on your own AD.
A free demo, run by an AD specialist on your real Active Directory. We take a path from a low-privilege user to Domain Admin, prove the exposure, and map it to DORA, NIS2, ENS and ISO 27001 — delivered the same day.