Ross ROSS = Recommend OSS · open-source software intelligence for agents

davidprowe/BadBlood

BadBlood by @davidprowe, Secframe.com, fills a Microsoft Active Directory Domain with a structure and thousands of objects. The output of the tool is a domain similar to a domain in the real world. After BadBlood is ran on a domain, security analysts and engineers can practice using tools to gain an understanding and prescribe to securing Active Directory. Each time this tool runs, it produces different results. The domain, users, groups, computers and permissions are different. Every. Single. Time. observed · 2026-08-28

github.com/davidprowe/BadBlood · homepage · PowerShell · GPL-3.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

32/100

  • Activity 0
  • Release rhythm 35
  • Longevity 100

Flags: no_releases

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 2421
  • days_rel: n/a
  • days_push: 1183
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

2265 stars · 289 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

BadBlood is a PowerShell tool that populates a Microsoft Active Directory domain with thousands of randomized users, groups, computers, and permissions to mimic a realistic production domain. It is designed for security analysts and engineers to practice attack and defense techniques against Active Directory, producing different results on every run.

Use cases

  • populate a lab active directory domain with realistic objects
  • practice active directory attack and defense techniques
  • generate test data for bloodhound analysis
  • create a realistic domain for security training
  • test ad security tools against varied permissions
  • build a cyber range environment for red team practice

When to choose

  • you need a realistic active directory lab with thousands of varied objects
  • you want unique domain structures on each run for repeated training
  • you are practicing with tools like bloodhound against a populated domain

When to avoid

  • you need a controlled, deterministic test dataset
  • you cannot dedicate a disposable lab domain - it requires domain admin and schema admin rights
  • you want a maintained tool with frequent updates

Facets

cli-tool · maturity maintenance

security data-generation developer-tools security penetration-testing developer-tools windows cli active-directory lab-environment powershell security-training bloodhound

2 sources

Member repositories

RepositoryRoleHealth v2
davidprowe/BadBloodmain32

For agents

markdown · JSON · MCP: product_card(name="davidprowe/BadBlood")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem