# PlumHound/PlumHound

Bloodhound Reporting for Blue and Purple Teams

Repository: https://github.com/PlumHound/PlumHound
Canonical: https://ross.abutalabs.com/products/plumhound
Language: Python
License: GPL-3.0
License Family: copyleft
Topics: active, directory, blueteam, purpleteam, bloodhound, bloodhoundad, infosec, active-directory, bloodhoundad-cypher-queries, purple-teams, plumhound-tasks, bloodhoundad-pathfinding-engine, neo4j, bluehound, attack-paths, activedirectory, cypher-query, redteam, reporting-tool, penetration-testing
Last push: 2025-11-15T11:44:12+00:00

## Health v2 (maintenance only)
Score: 63/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 52, release rhythm 57, longevity 100
- inputs: {"age_days": 2315, "days_push": 291, "days_rel": 291, "gap_med": 0, "n_releases_24m": 6}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1310, forks 130 (observed 2026-08-28T04:04:19.952101+00:00)

## What it is
PlumHound is a Python CLI reporting engine that wraps BloodHoundAD's Neo4j Cypher queries into consumable security reports for Blue and Purple teams. It identifies Active Directory vulnerabilities and attack paths resulting from business operations, policies, and legacy configurations.

## Use cases
- generate Active Directory security reports from BloodHound data
- find attack paths to Domain Admin in Active Directory
- run scheduled BloodHound Cypher queries for continuous AD auditing
- harden common Active Directory misconfigurations
- analyze busiest paths to Domain Admin with BlueHound module
- produce HTML reports for blue and purple team exercises
- audit AD privilege escalation paths from Neo4j

## When to choose
- you already collect BloodHound data and need repeatable, operations-friendly reports
- your blue or purple team wants continual AD security lifecycle assessment rather than one-off red team use
- you need task-list-driven or single-query Cypher reporting against a Neo4j backend

## When to avoid
- you have no BloodHound/Neo4j data collection pipeline in place
- you need a general-purpose vulnerability scanner rather than AD-specific path analysis
- you want a GUI-driven tool instead of a command-line workflow

## Facets
- artifact type: cli-tool
- maturity: active
- function: security, search-engine, developer-tools
- domain: security, penetration-testing, developer-tools
- platform: python, cli, cross-platform
- tags: bloodhound, active-directory, neo4j, cypher, blue-team, purple-team, red-team, attack-paths, infosec, reporting, linux

## Member repositories
- PlumHound/PlumHound (main) score 63

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:19.952101+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:49:53.896179+00:00, confidence not recorded.
  - readme: https://github.com/PlumHound/PlumHound (fetched 2026-08-28T04:04:19.952101+00:00, sha dcc9a645092c)
  - registry_pypi: https://pypi.org/pypi/plumhound/json (fetched 2026-08-29T12:07:55.207260+00:00, sha d68a66af4c61)
- Data as of 2026-08-30T08:39:29.467469+00:00.
