SpecterOps announced
that BloodHound Enterprise (BHE) will be available to government
customers next month. BHE is an Attack Path Management (APM) security
solution for defending Microsoft Active Directory (AD) and Azure
AD/Entra ID. SpecterOps is in the final stages of FedRAMP certification
and BHE will soon be FedRAMP HIGH compliant.
This certification was streamlined through a partnership with Palantir
FedStart - a SaaS offering that helps accelerate federal go-to-market by
enabling companies to run their products within Palantir's secure and
accredited environment. Companies that are part of the FedStart program
benefit from FedRAMP and IL5 compliance managed by Palantir, with
Palantir responsible for government ATO conversations, compliance
artifacts, continuous monitoring, and control assessments. BHE is
deployed as an application on top of this platform to comply with and
inherit further security controls FedRAMP requires.
"The average government agency will have tens of thousands of AD Attack
Paths, making them an attacker's easiest, most reliable, and most
effective method to deploy malware or other offensive cyber operations,"
said Justin Kohler, VP of Products at SpecterOps. "BHE provides the
critical Attack Path Management capability that is sorely needed in the
public sector. Many of us at SpecterOps come from a federal service
background and have always wanted to bring our capability to
FedRAMP-required environments."
BHE is designed to help organizations proactively and continuously
identify, manage, and remediate millions of AD Attack Paths. It gives IT
Ops and SecOps professionals the tools needed to dramatically and
measurably improve their AD security posture with minimal effort. BHE
with FedRAMP meets the high security and compliance standards of the
federal government and allows for faster adoption by government agencies
seeking to secure their AD or Azure AD/Entra ID environments.
CISA and Microsoft have recommended BloodHound, an open-source tool from
SpecterOps related to BloodHound Enterprise, for securing Microsoft
Active Directory. BHE product revenue grew 200% year over year over the
past two years and is used worldwide by companies like Capital Group,
the University of Texas at Austin, and Woodside Energy.