# davidprowe/BadBlood

BadBlood by @davidprowe, Secframe.com, fills a Microsoft Active Directory Domain with a structure and thousands of objects. The output of the tool is a domain similar to a domain in the real world.  After BadBlood is ran on a domain, security analysts and engineers can practice using tools to gain an understanding and prescribe to securing Active Directory. Each time this tool runs, it produces different results.  The domain, users, groups, computers and permissions are different. Every. Single. Time.

Repository: https://github.com/davidprowe/BadBlood
Canonical: https://ross.abutalabs.com/products/badblood
Homepage: https://www.secframe.com/badblood
Language: PowerShell
License: GPL-3.0
License Family: copyleft
Last push: 2023-06-07T17:14:17+00:00

## Health v2 (maintenance only)
Score: 32/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 35, longevity 100
- inputs: {"age_days": 2421, "days_push": 1183, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2265, forks 289 (observed 2026-08-28T04:06:32.538515+00:00)

## What it is
BadBlood is a PowerShell tool that populates a Microsoft Active Directory domain with thousands of randomized users, groups, computers, and permissions to mimic a realistic production domain. It is designed for security analysts and engineers to practice attack and defense techniques against Active Directory, producing different results on every run.

## Use cases
- populate a lab active directory domain with realistic objects
- practice active directory attack and defense techniques
- generate test data for bloodhound analysis
- create a realistic domain for security training
- test ad security tools against varied permissions
- build a cyber range environment for red team practice

## When to choose
- you need a realistic active directory lab with thousands of varied objects
- you want unique domain structures on each run for repeated training
- you are practicing with tools like bloodhound against a populated domain

## When to avoid
- you need a controlled, deterministic test dataset
- you cannot dedicate a disposable lab domain - it requires domain admin and schema admin rights
- you want a maintained tool with frequent updates

## Facets
- artifact type: cli-tool
- maturity: maintenance
- function: security, data-generation, developer-tools
- domain: security, penetration-testing, developer-tools
- platform: windows, cli
- tags: active-directory, lab-environment, powershell, security-training, bloodhound

## Member repositories
- davidprowe/BadBlood (main) score 32

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:06:32.538515+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T02:42:24.297903+00:00, confidence not recorded.
  - readme: https://github.com/davidprowe/BadBlood (fetched 2026-08-28T04:06:32.538515+00:00, sha 23af26a85304)
  - homepage: https://www.secframe.com/badblood (fetched 2026-08-29T10:22:38.382181+00:00, sha 0d48a205584b)
- Data as of 2026-08-30T08:39:29.467469+00:00.
