Skip to content

BQL Queries

Bloodhound Query Language (BQL) is a domain-specific language used to query the graph database representation of Active Directory structures within Bloodhound. It enables analysts to identify misconfigurations, such as unconstrained delegation, by leveraging the relationships and attributes stored in the database. BQL is designed to be intuitive, with syntax inspired by graph traversal principles, making it a critical tool for reconnaissance and exploitation planning.


Basic Syntax and Query Structure

BQL queries follow a pattern of MATCH and RETURN clauses to define patterns and retrieve results. The MATCH clause identifies nodes and relationships, while RETURN specifies the data to output. Filters can be applied using WHERE to narrow results.

Example 1: Find all users

MATCH (u:User) RETURN u
This query retrieves all user objects in the database. Each result includes properties like u.name, u.sid, and u.lastLogon.

Example 2: Filter by attribute

MATCH (u:User) WHERE u.OperatingSystem = "Windows Server 2016" RETURN u
This query filters users based on their operating system attribute, demonstrating how to apply conditions.


Detecting Unconstrained Delegation

Unconstrained delegation occurs when a service account is allowed to delegate credentials to any service, often indicated by the TrustedForDelegation flag or the msDS-AllowedToActOnBehalfOfOtherIdentity attribute. BQL can detect this by querying for service principal names (SPNs) with these properties.

Example 3: Find SPNs with unconstrained delegation

MATCH (s:ServicePrincipalName) 
WHERE s.TrustedForDelegation = true 
RETURN s
This query identifies all SPNs where the TrustedForDelegation flag is enabled, a common indicator of unconstrained delegation.

Example 4: Check for msDS-AllowedToActOnBehalfOfOtherIdentity

MATCH (o:Object) 
WHERE o."msDS-AllowedToActOnBehalfOfOtherIdentity" = "*" 
RETURN o
This query searches for objects (e.g., service accounts) where the msDS-AllowedToActOnBehalfOfOtherIdentity attribute is set to "*", another sign of unconstrained delegation.


Key Takeaways

  • BQL is essential for analyzing AD structures and identifying misconfigurations like unconstrained delegation.
  • Basic queries like MATCH (u:User) help map user and object relationships.
  • Filtering with WHERE allows precise targeting of attributes (e.g., TrustedForDelegation).
  • Unconstrained delegation detection relies on querying SPNs and specific attributes to uncover risky configurations.
  • Always validate results in the Bloodhound UI to refine queries and explore relationships further.