SpecterOps
- Company typePrivate
- Founded2017
- HeadquartersAlexandria, United States
- Headcount251–500
- GTM typeB2B
- OfferingSoftware
SpecterOps firmographics
Firmographics- Name
- SpecterOps
- Legal name
- Specter Ops, Inc.
- Website
- https://specterops.io
- Company type
- Private
- Founded year
- 2017
- Operating status
- Operating
- Headcount range
- 251–500 employees
- Ownership category
- akta.pro rank
SpecterOps industry classification
Industry- Product category
- Cybersecurity Software
- NAICS
- Computer Systems Design and Related Services (54151)
- SIC
- Services-Detective, Guard & Armored Car Services (7381)
- akta.pro primary industry
- Network Security Managed Services (Firewall/IDS/IPS/SASE) (BPAEADAG)
Keywords
Where SpecterOps is headquartered
LocationHeadquarters
- HQ city
- Alexandria
- HQ country
- United States
- HQ region
- North America
Offices2 records
Markets served
SpecterOps business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- BloodHound Enterprise (BHE) subscription: Recurring SaaS subscription for the BloodHound Enterprise platform with 200+ enterprise customers; supports land-and-expand via expanded platform coverage (Okta, GitHub, Mac, Scentry, OpenGraph) and self-managed encryption keys.
- Professional services (red team, pen testing, assessments, advisory): Adversary-style offensive services including red team engagements, penetration testing, web application security assessments, AI red team, attack path assessments, maturity assessments, program development, and purple team assessments.
- Training and education: Paid training programs covering Adversary Tactics (Red Team Operations, Identity-Driven Offensive Tradecraft, Detection, Tradecraft Analysis) and Adversary Perspectives (Active Directory, Azure), delivered at Black Hat and other events.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | BloodHound Enterprise - quote-based enterprise subscription |
| Freemium | Pay-as-you-go | BloodHound Community Edition - free open-source |
| Other | Pay-as-you-go | Training courses - paid instructor-led training |
Go-to-market motion5 records
Distribution channels6 records
Marketing channels10 records
SpecterOps product offering
Product offeringCore offering
SpecterOps develops cybersecurity software and delivers offensive security services focused on identity attack path management. Its flagship commercial product, BloodHound Enterprise, maps and analyzes Active Directory and Azure identity attack paths, while the firm also publishes several open-source security tools (BloodHound CE, Mythic, Ghostwriter, Nemesis). The company additionally offers professional services including red teaming, penetration testing, and security program development for enterprise customers.
Product overview
SpecterOps delivers a platform-plus-modules portfolio centered on BloodHound Enterprise (BHE), the industry's leading identity attack path management platform for hybrid and AI-enabled enterprise environments. The core BHE platform is extended by modules including Privilege Zones (zone-based access enforcement) and OpenGraph (graphing technologies outside AD/Azure, such as Okta, GitHub, and Mac), and supplemented by the newly launched BloodHound Scentry tool for accelerating attack path remediation. The free, open-source BloodHound Community Edition, plus open-source projects Mythic (C2 framework), Ghostwriter (pen-test reporting), and Nemesis (offensive data enrichment) anchor the community offering. On top of the platform, SpecterOps sells offensive services (Red Team Exercises, Penetration Testing, Web Application Security Assessments, AI Red Team, Attack Path Assessments, Maturity Assessments, Program Development, Purple Team Assessments) and training (Adversary Tactics, Adversary Perspectives). Newer offerings include AI Cyber Ranges for evaluating AI model performance, the GhostWorks AI cyber innovation lab, and the BloodHound MCP developer tool for AI agent integrations.
Differentiator
Problem solved
Functional benefit
Brands
- BloodHound Enterprise: Enterprise platform for identity attack path management across hybrid and AI-enabled environments, including Active Directory, Entra ID, Okta, GitHub, and Mac.
- BloodHound Community Edition
- BloodHound Scentry
- OpenGraph
- Mythic
- Ghostwriter
- Nemesis
- GhostWorks
Products and services
- BloodHound Enterprise Enterprise platform that continuously maps, analyzes, and remediates identity-based attack paths in Active Directory and Azure environments. It is used by enterprise security teams to visualize privilege escalation paths and reduce identity-related risk.
- BloodHound Community Edition Free, open-source attack path mapping tool for Active Directory and Azure that serves as the community counterpart to BloodHound Enterprise. Used by security practitioners, red teamers, and defenders for ad-hoc identity analysis.
- Privilege Zones Capability that lets security teams define, monitor, and enforce zones of privileged access within identity environments to constrain attack path impact. Targeted at enterprise identity and access management teams.
- OpenGraph Extensible data model and ingestion framework that allows organizations to add custom entity types and relationships into BloodHound Enterprise beyond default Active Directory and Azure objects. Used by enterprise security teams to tailor attack path analysis to their environment.
- BloodHound Scentry Detection module for BloodHound Enterprise that continuously monitors identity environments for attack path changes and high-risk conditions, alerting defenders to emerging identity threats.
- Mythic Open-source red team command and control framework used by offensive security operators to collaborate and manage adversary tradecraft across engagements.
- Ghostwriter Open-source reporting and project management tool designed for offensive security teams to automate and standardize the production of client deliverables and engagement documentation.
- Nemesis Open-source data processing and enrichment platform used to ingest, correlate, and analyze data collected during offensive security engagements.
- AI Cyber Ranges Hands-on cybersecurity training and exercise environments, including dedicated AI cyber range scenarios, used by enterprise security teams and individuals to practice defensive and offensive techniques.
- GhostWorks Integrated offensive security operations platform combining command-and-control, reporting, and data enrichment tooling to support managed red team service delivery for enterprise clients.
- BloodHound MCP Integration layer that connects BloodHound Enterprise data to AI assistants via the Model Context Protocol, allowing analysts to query attack path information through conversational interfaces.
- Red Team Services Full-scope adversary simulation engagements in which SpecterOps operators emulate real-world threat actors to test and improve enterprise detection and response capabilities.
- Penetration Testing Targeted, time-boxed technical assessments of enterprise networks, applications, and infrastructure to identify exploitable vulnerabilities and produce remediation guidance.
- Web Application Security Application-layer security assessments covering web apps and APIs, including dynamic testing and code-aware review, designed for enterprise development and product security teams.
- AI Red Team
Quantifiable outcome
- 200+ customers for BloodHound Enterprise
- +2 more outcomes
Companies that use SpecterOps
Customer profileNamed customers7 records
Segments5 records
Ideal customer profiles2 records
SpecterOps technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration11 records
AI capability12 records
Feature10 records
SpecterOps partnerships and signals
Strategic signalPartnerships
13 partnerships are on record, tiered flagship and core.
- OpenAIflagshipSpecterOps was selected for OpenAI's Trusted Access for Cyber (TAC) program in April 2026, gaining access to advanced cyber-capable models (e.g., GPT-5.4-Cyber) for defensive research. In June 2026 the relationship expanded into the OpenAI Daybreak Cyber Partner Program, with co-developed AI training workshops at Black Hat USA 2026 and embedded AI capabilities (Triage, automated enclave discovery) inside BloodHound and GhostWorks.
- CiscoflagshipAnnounced at Cisco Live EMEA in Amsterdam on February 10, 2026, Cisco and SpecterOps jointly launched Active Directory Defense for Cisco Duo, embedding SpecterOps' identity attack path capabilities into Cisco's Duo security offering.
- TinescoreSpecterOps and Tines announced a partnership to automate attack path management through a native BloodHound integration, enabling automated attack path identification and mitigation within Tines workflows.
- Kevin Mandia (CEO of Mandiant)coreStrategic individual investor and advisor participation in Series A extension; provides industry expertise and credibility.
- Microsoft SentinelcoreNative integration between BloodHound Enterprise and Microsoft Sentinel for security workflow and SIEM integration.
- Palo Alto NetworkscoreIntegration of BloodHound Enterprise with Palo Alto Networks products for identity attack path management.
- ServiceNowcoreIntegration of BloodHound Enterprise with ServiceNow for security workflow and remediation management.
- OktacoreCoverage of Okta identity environments in BloodHound Enterprise for attack path detection and remediation, announced March 2026.
- GitHubcoreBloodHound Enterprise coverage of GitHub environments for cross-platform attack path mapping (via OpenGraph), announced March 2026.
- Apple (Mac)coreAdded Mac environment coverage in BloodHound Enterprise for hybrid attack path detection, announced March 2026.
- Amazon Web Services (AWS)coreAWS is SpecterOps' cloud hosting provider and infrastructure partner, leveraging AWS security certifications and isolated single-tenant architecture for BloodHound Enterprise.
- UK AI Security InstitutecoreCollaboration with the UK AI Security Institute applying SpecterOps' adversary tradecraft knowledge across public and private engagements.
- BloodHoundGang Slack CommunitycoreOperates and hosts the BloodHoundGang Slack community (slack.specterops.io) as a core channel for tradecraft sharing and project collaboration.
Scale indicators8 records
Recent moves6 records
Expansion highlights7 records
SpecterOps competitors and assessment
Company assessmentBroad incumbents
- CrowdStrike: Endpoint and cloud security leader whose Falcon Identity Threat Detection and Falcon Identity Threat Protection overlap with SpecterOps' identity attack path focus, but CrowdStrike operates as a broad platform across EDR, SIEM, and identity rather than specializing in attack-path mapping.
- Microsoft (Defender for Identity / Security Copilot): Owner of Active Directory and Entra ID with native Defender for Identity and Security Copilot capabilities that increasingly cover identity attack-path analytics. SpecterOps lists Microsoft as both a customer (BloodHound Enterprise) and a partner (Microsoft Sentinel integration), making Microsoft both a competitor and ecosystem participant.
- Palo Alto Networks (Cortex / Unit 42): Broad cybersecurity platform with Cortex XSIAM and Unit 42 attack-path-adjacent services, and a disclosed integration partner of BloodHound Enterprise. Competes at the platform layer while cooperating at the integration layer.
- Tenable: Vulnerability management leader extending into identity and exposure management (Tenable Identity Exposure / formerly Tenable.ad) with BloodHound-style AD attack-path visualization. Closest large-cap competitor in identity attack path management.
- Wiz: Cloud security platform with identity-aware cloud detection and response (CDR) capabilities and acquisition-driven identity exposure analytics. Competes indirectly by extending attack-path visibility into cloud and identity from a cloud-native base.
Direct peers
- BeyondTrust: Privileged access management vendor offering identity security, AD/Entra auditing, and attack-path-adjacent capabilities. Closely aligned with SpecterOps' focus on identity-driven lateral movement and privilege escalation.
- CyberArk: Privileged access management leader offering identity security, just-in-time access, and identity threat detection that overlap with BloodHound Enterprise's identity attack path management focus.
- Obsidian Security: Identity threat detection and response (ITDR) vendor focused on SaaS and identity provider attack paths. A direct competitor to BloodHound Enterprise in the emerging identity threat detection category.
Emerging players
- Saviynt: Cloud-native identity governance and administration platform with converged identity security, including risk-aware identity analytics that intersect with SpecterOps' attack-path prioritization capabilities.
Others
- Semgrep (and emerging code/identity security players): Developer-first security vendor; representative of the broader ecosystem of code and identity security companies that could converge on attack-path and identity-exposure analytics, complementing or competing with SpecterOps' BloodHound platform.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat7 records
Key risks6 records
Key highlights7 records
Customer concentration
SpecterOps social profiles
Digital presenceSpecterOps compliance and trust
Trust signalCompliance8 records
SpecterOps financial estimates
Financial estimateRevenue estimate
Valuation estimate
SpecterOps leadership team
Management profileNumber of profiles
Profiles9 records
SpecterOps funding detail
Funding detailFunding overview
Funding rounds5 records
Investors6 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
SpecterOps M&A and investment
M&A and investmentM&A1 record
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about SpecterOps
What does SpecterOps do?
SpecterOps develops cybersecurity software and delivers offensive security services focused on identity attack path management. Its flagship commercial product, BloodHound Enterprise, maps and analyzes Active Directory and Azure identity attack paths, while the firm also publishes several open-source security tools (BloodHound CE, Mythic, Ghostwriter, Nemesis). The company additionally offers professional services including red teaming, penetration testing, and security program development for enterprise customers.
Is SpecterOps a public or private company?
SpecterOps is a private company. It is classified as venture growth investor backed and is currently operating.
When was SpecterOps founded?
SpecterOps was founded in 2017. It employs 251 to 500 people.
Where is SpecterOps based?
SpecterOps is headquartered in Alexandria, United States, in the North America region.
How does SpecterOps make money?
Three revenue lines are on record. BloodHound Enterprise (BHE) subscription is the primary driver. The others are professional services (red team, pen testing, assessments, advisory) and training and education.
Who are SpecterOps's main competitors?
Broad incumbents on record are CrowdStrike, Microsoft (Defender for Identity / Security Copilot), Palo Alto Networks (Cortex / Unit 42), Tenable and Wiz. Direct peers are BeyondTrust, CyberArk and Obsidian Security. Saviynt is listed as an emerging player. Semgrep (and emerging code/identity security players) is listed as an others.
Does SpecterOps have an API?
Yes. SpecterOps offers a public BloodHound API (referenced as 'extensive API') and a BloodHound MCP (Model Context Protocol) server for AI agent integrations. The MCP exposes 13 composite tools (domain_info, user_info, group_info, computer_info, ou_info, gpo_info, graph_analysis, adcs_info, cypher_query, data_quality, custom_nodes, asset_groups, file_upload) plus resources (e.g., bloodhound://cypher/reference, bloodhound://guides/ad, bloodhound://guides/azure) for AI agent interaction with BloodHound data. The MCP also supports file upload for controlled SharpHound/AzureHound collection uploads. API documentation is available at https://bloodhound.specterops.io/. The BloodHound MCP repository is open source at https://github.com/mwnickerson/bloodhound_mcp. Developer documentation is at bloodhound.specterops.io.
What industry is SpecterOps in?
SpecterOps's product category is Cybersecurity Software. Its primary akta.pro industry code is BPAEADAG, Network Security Managed Services (Firewall/IDS/IPS/SASE). Its NAICS code is 54151 and its SIC code is 7381.