BQL Queries
Bloodhound Query Language (BQL) is a domain-specific language used to query the graph database representation of Active Directory structures within Bloodhound. It enables analysts to identify misconfigurations, such as unconstrained delegation, by leveraging the relationships and attributes stored in the database. BQL is designed to be intuitive, with syntax inspired by graph traversal principles, making it a critical tool for reconnaissance and exploitation planning.
Basic Syntax and Query Structure¶
BQL queries follow a pattern of MATCH and RETURN clauses to define patterns and retrieve results. The MATCH clause identifies nodes and relationships, while RETURN specifies the data to output. Filters can be applied using WHERE to narrow results.
Example 1: Find all users
u.name, u.sid, and u.lastLogon.
Example 2: Filter by attribute
Detecting Unconstrained Delegation¶
Unconstrained delegation occurs when a service account is allowed to delegate credentials to any service, often indicated by the TrustedForDelegation flag or the msDS-AllowedToActOnBehalfOfOtherIdentity attribute. BQL can detect this by querying for service principal names (SPNs) with these properties.
Example 3: Find SPNs with unconstrained delegation
TrustedForDelegation flag is enabled, a common indicator of unconstrained delegation.
Example 4: Check for msDS-AllowedToActOnBehalfOfOtherIdentity
msDS-AllowedToActOnBehalfOfOtherIdentity attribute is set to "*", another sign of unconstrained delegation.
Key Takeaways¶
- BQL is essential for analyzing AD structures and identifying misconfigurations like unconstrained delegation.
- Basic queries like
MATCH (u:User)help map user and object relationships. - Filtering with
WHEREallows precise targeting of attributes (e.g.,TrustedForDelegation). - Unconstrained delegation detection relies on querying SPNs and specific attributes to uncover risky configurations.
- Always validate results in the Bloodhound UI to refine queries and explore relationships further.