Developer docs
API playgroundTry for free, no card

Search company profiles

SpecterOps

Full company profile

uuid00006s2

Namestring
SpecterOps
Legal namestring
Specter Ops, Inc.
Websiteurl
specterops.io
Company typeenum
Private
Founded yearint
2017
Operating statusenum
Operating
Ownership categoryenum
Headcount rangeband
251–500
akta.pro rankint
HeadquartersAlexandria, United States
HQ citystring
Alexandria
HQ countrystring
United States
HQ regionstring
North America
Markets served

Serves global market

Offices2 records

Each record includes

City, Country, Type, Description, Source

Keyword5 values
identity attack path management, cybersecurity software, adversary simulation, offensive security services, penetration testing
Industry1 code
1Network Security Managed Services (Firewall/IDS/IPS/SASE)
CodeBPAEADAGPrimaryYes
NAICS code1 code
  • Computer Systems Design and Related Services54151
SIC code1 code
  • Services-Detective, Guard & Armored Car Services7381
Product category
Cybersecurity Software
GTM motion5 records

Each record includes

Type, Description, Source

Revenue model3 records
1BloodHound Enterprise (BHE) subscription
TypeSubscription Recurring
Description

Recurring SaaS subscription for the BloodHound Enterprise platform with 200+ enterprise customers; supports land-and-expand via expanded platform coverage (Okta, GitHub, Mac, Scentry, OpenGraph) and self-managed encryption keys.

businesswire.com
2Professional services (red team, pen testing, assessments, advisory)
TypeProfessional Services
Description

Adversary-style offensive services including red team engagements, penetration testing, web application security assessments, AI red team, attack path assessments, maturity assessments, program development, and purple team assessments.

specterops.io
3Training and education
TypeProfessional Services
Description

Paid training programs covering Adversary Tactics (Red Team Operations, Identity-Driven Offensive Tradecraft, Detection, Tradecraft Analysis) and Adversary Perspectives (Active Directory, Azure), delivered at Black Hat and other events.

specterops.io
Marketing channels10 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels6 records

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components4 values
Personnel, Technology or R&D, Marketing or Sales, Operations
Pricing details3 tiers
1BloodHound Enterprise - quote-based enterprise subscription
ModelSubscriptionBilling cadenceAnnual
Notes

Not publicly listed; obtained via demo request. Supports on-prem, cloud, hybrid with expanded platform coverage (Okta, GitHub, Mac), Privilege Zones, OpenGraph, BloodHound Scentry, and self-managed encryption keys.

specterops.io
2BloodHound Community Edition - free open-source
ModelFreemiumBilling cadencePay-as-you-go
Notes

Free, open-source self-hosted version of BloodHound for individual practitioners and community use.

specterops.io
3Training courses - paid instructor-led training
ModelOtherBilling cadencePay-as-you-go
Notes

Training offered at Black Hat USA and via dedicated course pages; specific course fees not publicly disclosed.

specterops.io
GTM typeB2B
B2B
Offering typeSoftware
Software
Brand1 of 8 records shown
1BloodHound Enterprise
Description

Enterprise platform for identity attack path management across hybrid and AI-enabled environments, including Active Directory, Entra ID, Okta, GitHub, and Mac.

specterops.io
+7 more records
Core offering1 text field

SpecterOps develops cybersecurity software and delivers offensive security services focused on identity attack path management. Its flagship commercial product, BloodHound Enterprise, maps and analyzes Active Directory and Azure identity attack paths, while the firm also publishes several open-source security tools (BloodHound CE, Mythic, Ghostwriter, Nemesis). The company additionally offers professional services including red teaming, penetration testing, and security program development for enterprise customers.

Differentiator
Functional benefit
Problem solved
Quantifiable outcome1 of 3 values shown
  • 200+ customers for BloodHound Enterprise
+2 more records
Product overview1 text field

SpecterOps delivers a platform-plus-modules portfolio centered on BloodHound Enterprise (BHE), the industry's leading identity attack path management platform for hybrid and AI-enabled enterprise environments. The core BHE platform is extended by modules including Privilege Zones (zone-based access enforcement) and OpenGraph (graphing technologies outside AD/Azure, such as Okta, GitHub, and Mac), and supplemented by the newly launched BloodHound Scentry tool for accelerating attack path remediation. The free, open-source BloodHound Community Edition, plus open-source projects Mythic (C2 framework), Ghostwriter (pen-test reporting), and Nemesis (offensive data enrichment) anchor the community offering. On top of the platform, SpecterOps sells offensive services (Red Team Exercises, Penetration Testing, Web Application Security Assessments, AI Red Team, Attack Path Assessments, Maturity Assessments, Program Development, Purple Team Assessments) and training (Adversary Tactics, Adversary Perspectives). Newer offerings include AI Cyber Ranges for evaluating AI model performance, the GhostWorks AI cyber innovation lab, and the BloodHound MCP developer tool for AI agent integrations.

Product and service15 records
1BloodHound Enterprise
CategoryIdentity Security
Description

Enterprise platform that continuously maps, analyzes, and remediates identity-based attack paths in Active Directory and Azure environments. It is used by enterprise security teams to visualize privilege escalation paths and reduce identity-related risk.

2BloodHound Community Edition
CategoryIdentity Security
Description

Free, open-source attack path mapping tool for Active Directory and Azure that serves as the community counterpart to BloodHound Enterprise. Used by security practitioners, red teamers, and defenders for ad-hoc identity analysis.

3Privilege Zones
CategoryIdentity Security
Description

Capability that lets security teams define, monitor, and enforce zones of privileged access within identity environments to constrain attack path impact. Targeted at enterprise identity and access management teams.

4OpenGraph
CategoryIdentity Security
Description

Extensible data model and ingestion framework that allows organizations to add custom entity types and relationships into BloodHound Enterprise beyond default Active Directory and Azure objects. Used by enterprise security teams to tailor attack path analysis to their environment.

5BloodHound Scentry
CategoryIdentity Security
Description

Detection module for BloodHound Enterprise that continuously monitors identity environments for attack path changes and high-risk conditions, alerting defenders to emerging identity threats.

6Mythic
CategoryOffensive Security
Description

Open-source red team command and control framework used by offensive security operators to collaborate and manage adversary tradecraft across engagements.

7Ghostwriter
CategoryOffensive Security
Description

Open-source reporting and project management tool designed for offensive security teams to automate and standardize the production of client deliverables and engagement documentation.

8Nemesis
CategoryOffensive Security
Description

Open-source data processing and enrichment platform used to ingest, correlate, and analyze data collected during offensive security engagements.

9AI Cyber Ranges
CategorySecurity Training
Description

Hands-on cybersecurity training and exercise environments, including dedicated AI cyber range scenarios, used by enterprise security teams and individuals to practice defensive and offensive techniques.

10GhostWorks
CategoryOffensive Security
Description

Integrated offensive security operations platform combining command-and-control, reporting, and data enrichment tooling to support managed red team service delivery for enterprise clients.

11BloodHound MCP
CategoryIdentity Security
Description

Integration layer that connects BloodHound Enterprise data to AI assistants via the Model Context Protocol, allowing analysts to query attack path information through conversational interfaces.

12Red Team Services
CategoryProfessional Services
Description

Full-scope adversary simulation engagements in which SpecterOps operators emulate real-world threat actors to test and improve enterprise detection and response capabilities.

13Penetration Testing
CategoryProfessional Services
Description

Targeted, time-boxed technical assessments of enterprise networks, applications, and infrastructure to identify exploitable vulnerabilities and produce remediation guidance.

14Web Application Security
CategoryProfessional Services
Description

Application-layer security assessments covering web apps and APIs, including dynamic testing and code-aware review, designed for enterprise development and product security teams.

15AI Red Team
Scale indicator8 records

Each record includes

Type, Value, Description, Source

Partnership13 partners
Strategic tierFlagshipTypeStrategic or Co-development PartnerAnnounced on2026-04-01
Description

SpecterOps was selected for OpenAI's Trusted Access for Cyber (TAC) program in April 2026, gaining access to advanced cyber-capable models (e.g., GPT-5.4-Cyber) for defensive research. In June 2026 the relationship expanded into the OpenAI Daybreak Cyber Partner Program, with co-developed AI training workshops at Black Hat USA 2026 and embedded AI capabilities (Triage, automated enclave discovery) inside BloodHound and GhostWorks.

Strategic tierFlagshipTypeStrategic or Co-development PartnerAnnounced on2026-02-10
Description

Announced at Cisco Live EMEA in Amsterdam on February 10, 2026, Cisco and SpecterOps jointly launched Active Directory Defense for Cisco Duo, embedding SpecterOps' identity attack path capabilities into Cisco's Duo security offering.

Strategic tierCoreTypeTechnology or IntegrationAnnounced on2025-12-04
Description

SpecterOps and Tines announced a partnership to automate attack path management through a native BloodHound integration, enabling automated attack path identification and mitigation within Tines workflows.

4Kevin Mandia (CEO of Mandiant)
Strategic tierCoreTypeStrategic or Co-development Partner
Description

Strategic individual investor and advisor participation in Series A extension; provides industry expertise and credibility.

finsmes.com
Strategic tierCoreTypeTechnology or Integration
Description

Native integration between BloodHound Enterprise and Microsoft Sentinel for security workflow and SIEM integration.

Strategic tierCoreTypeTechnology or Integration
Description

Integration of BloodHound Enterprise with Palo Alto Networks products for identity attack path management.

Strategic tierCoreTypeTechnology or Integration
Description

Integration of BloodHound Enterprise with ServiceNow for security workflow and remediation management.

Strategic tierCoreTypeTechnology or Integration
Description

Coverage of Okta identity environments in BloodHound Enterprise for attack path detection and remediation, announced March 2026.

Strategic tierCoreTypeTechnology or Integration
Description

BloodHound Enterprise coverage of GitHub environments for cross-platform attack path mapping (via OpenGraph), announced March 2026.

Strategic tierCoreTypeTechnology or Integration
Description

Added Mac environment coverage in BloodHound Enterprise for hybrid attack path detection, announced March 2026.

Strategic tierCoreTypeTechnology or Integration
Description

AWS is SpecterOps' cloud hosting provider and infrastructure partner, leveraging AWS security certifications and isolated single-tenant architecture for BloodHound Enterprise.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

Collaboration with the UK AI Security Institute applying SpecterOps' adversary tradecraft knowledge across public and private engagements.

13BloodHoundGang Slack Community
Strategic tierCoreTypeOthers
Description

Operates and hosts the BloodHoundGang Slack community (slack.specterops.io) as a core channel for tradecraft sharing and project collaboration.

specterops.io
Recent move6 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight7 records

Each record includes

Type, Description

Peers10 records
TypeBroad incumbent
Description

Endpoint and cloud security leader whose Falcon Identity Threat Detection and Falcon Identity Threat Protection overlap with SpecterOps' identity attack path focus, but CrowdStrike operates as a broad platform across EDR, SIEM, and identity rather than specializing in attack-path mapping.

TypeBroad incumbent
Description

Owner of Active Directory and Entra ID with native Defender for Identity and Security Copilot capabilities that increasingly cover identity attack-path analytics. SpecterOps lists Microsoft as both a customer (BloodHound Enterprise) and a partner (Microsoft Sentinel integration), making Microsoft both a competitor and ecosystem participant.

TypeBroad incumbent
Description

Broad cybersecurity platform with Cortex XSIAM and Unit 42 attack-path-adjacent services, and a disclosed integration partner of BloodHound Enterprise. Competes at the platform layer while cooperating at the integration layer.

TypeBroad incumbent
Description

Vulnerability management leader extending into identity and exposure management (Tenable Identity Exposure / formerly Tenable.ad) with BloodHound-style AD attack-path visualization. Closest large-cap competitor in identity attack path management.

TypeDirect peer
Description

Privileged access management vendor offering identity security, AD/Entra auditing, and attack-path-adjacent capabilities. Closely aligned with SpecterOps' focus on identity-driven lateral movement and privilege escalation.

TypeDirect peer
Description

Privileged access management leader offering identity security, just-in-time access, and identity threat detection that overlap with BloodHound Enterprise's identity attack path management focus.

TypeEmerging player
Description

Cloud-native identity governance and administration platform with converged identity security, including risk-aware identity analytics that intersect with SpecterOps' attack-path prioritization capabilities.

TypeDirect peer
Description

Identity threat detection and response (ITDR) vendor focused on SaaS and identity provider attack paths. A direct competitor to BloodHound Enterprise in the emerging identity threat detection category.

TypeBroad incumbent
Description

Cloud security platform with identity-aware cloud detection and response (CDR) capabilities and acquisition-driven identity exposure analytics. Competes indirectly by extending attack-path visibility into cloud and identity from a cloud-native base.

TypeOthers
Description

Developer-first security vendor; representative of the broader ecosystem of code and identity security companies that could converge on attack-path and identity-exposure analytics, complementing or competing with SpecterOps' BloodHound platform.

Market position
Strengths5 records

Each record includes

Headline, Details, Source

Weaknesses5 records

Each record includes

Headline, Details, Source

Competitive moat7 records

Each record includes

Type, Details

Key risks6 records

Each record includes

Headline, Details, Source

Key highlights7 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Named customers7 records

Each record includes

Name, Industry, Type, Use case, Source, UUID

Segment5 records

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile2 records

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
Yes
API detail
Has APIbool
Yes

Docs URL, Description

Integration11 records

Each record includes

Title, Type, Description, Source

AI capability12 records

Each record includes

Type, Description, Source

AI maturity
App detail

Has app

Feature10 records

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
Profiles9 records

Each record includes

Name, Designation, Designation category, Overview, Profile commentary, Source

No data
Compliance8 records

Each record includes

Name, Class, Description

Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds5 records

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors6 records

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A1 record

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

SpecterOps

Cybersecurity Softwarespecterops.io

SpecterOps firmographics

Firmographics
Name
SpecterOps
Legal name
Specter Ops, Inc.
Website
https://specterops.io
Company type
Private
Founded year
2017
Operating status
Operating
Headcount range
251–500 employees
Ownership category
akta.pro rank

SpecterOps industry classification

Industry
Product category
Cybersecurity Software
NAICS
Computer Systems Design and Related Services (54151)
SIC
Services-Detective, Guard & Armored Car Services (7381)
akta.pro primary industry
Network Security Managed Services (Firewall/IDS/IPS/SASE) (BPAEADAG)

Keywords

  • Identity attack path management
  • Cybersecurity software
  • Adversary simulation
  • Offensive security services
  • Penetration testing

Where SpecterOps is headquartered

Location

Headquarters

HQ city
Alexandria
HQ country
United States
HQ region
North America

Offices2 records

Markets served

SpecterOps business model

Business model
GTM type
B2B
Offering type
Software
Cost components
Personnel, Technology or R&D, Marketing or Sales, Operations

Revenue model

  1. BloodHound Enterprise (BHE) subscription: Recurring SaaS subscription for the BloodHound Enterprise platform with 200+ enterprise customers; supports land-and-expand via expanded platform coverage (Okta, GitHub, Mac, Scentry, OpenGraph) and self-managed encryption keys.
  2. Professional services (red team, pen testing, assessments, advisory): Adversary-style offensive services including red team engagements, penetration testing, web application security assessments, AI red team, attack path assessments, maturity assessments, program development, and purple team assessments.
  3. Training and education: Paid training programs covering Adversary Tactics (Red Team Operations, Identity-Driven Offensive Tradecraft, Detection, Tradecraft Analysis) and Adversary Perspectives (Active Directory, Azure), delivered at Black Hat and other events.

Pricing tiers

ModelBillingPrice
SubscriptionAnnualBloodHound Enterprise - quote-based enterprise subscription
FreemiumPay-as-you-goBloodHound Community Edition - free open-source
OtherPay-as-you-goTraining courses - paid instructor-led training

Go-to-market motion5 records

Distribution channels6 records

Marketing channels10 records

SpecterOps product offering

Product offering

Core offering

SpecterOps develops cybersecurity software and delivers offensive security services focused on identity attack path management. Its flagship commercial product, BloodHound Enterprise, maps and analyzes Active Directory and Azure identity attack paths, while the firm also publishes several open-source security tools (BloodHound CE, Mythic, Ghostwriter, Nemesis). The company additionally offers professional services including red teaming, penetration testing, and security program development for enterprise customers.

Product overview

SpecterOps delivers a platform-plus-modules portfolio centered on BloodHound Enterprise (BHE), the industry's leading identity attack path management platform for hybrid and AI-enabled enterprise environments. The core BHE platform is extended by modules including Privilege Zones (zone-based access enforcement) and OpenGraph (graphing technologies outside AD/Azure, such as Okta, GitHub, and Mac), and supplemented by the newly launched BloodHound Scentry tool for accelerating attack path remediation. The free, open-source BloodHound Community Edition, plus open-source projects Mythic (C2 framework), Ghostwriter (pen-test reporting), and Nemesis (offensive data enrichment) anchor the community offering. On top of the platform, SpecterOps sells offensive services (Red Team Exercises, Penetration Testing, Web Application Security Assessments, AI Red Team, Attack Path Assessments, Maturity Assessments, Program Development, Purple Team Assessments) and training (Adversary Tactics, Adversary Perspectives). Newer offerings include AI Cyber Ranges for evaluating AI model performance, the GhostWorks AI cyber innovation lab, and the BloodHound MCP developer tool for AI agent integrations.

Differentiator

Problem solved

Functional benefit

Brands

  • BloodHound Enterprise: Enterprise platform for identity attack path management across hybrid and AI-enabled environments, including Active Directory, Entra ID, Okta, GitHub, and Mac.
  • BloodHound Community Edition
  • BloodHound Scentry
  • OpenGraph
  • Mythic
  • Ghostwriter
  • Nemesis
  • GhostWorks

Products and services

  • BloodHound Enterprise Enterprise platform that continuously maps, analyzes, and remediates identity-based attack paths in Active Directory and Azure environments. It is used by enterprise security teams to visualize privilege escalation paths and reduce identity-related risk.
  • BloodHound Community Edition Free, open-source attack path mapping tool for Active Directory and Azure that serves as the community counterpart to BloodHound Enterprise. Used by security practitioners, red teamers, and defenders for ad-hoc identity analysis.
  • Privilege Zones Capability that lets security teams define, monitor, and enforce zones of privileged access within identity environments to constrain attack path impact. Targeted at enterprise identity and access management teams.
  • OpenGraph Extensible data model and ingestion framework that allows organizations to add custom entity types and relationships into BloodHound Enterprise beyond default Active Directory and Azure objects. Used by enterprise security teams to tailor attack path analysis to their environment.
  • BloodHound Scentry Detection module for BloodHound Enterprise that continuously monitors identity environments for attack path changes and high-risk conditions, alerting defenders to emerging identity threats.
  • Mythic Open-source red team command and control framework used by offensive security operators to collaborate and manage adversary tradecraft across engagements.
  • Ghostwriter Open-source reporting and project management tool designed for offensive security teams to automate and standardize the production of client deliverables and engagement documentation.
  • Nemesis Open-source data processing and enrichment platform used to ingest, correlate, and analyze data collected during offensive security engagements.
  • AI Cyber Ranges Hands-on cybersecurity training and exercise environments, including dedicated AI cyber range scenarios, used by enterprise security teams and individuals to practice defensive and offensive techniques.
  • GhostWorks Integrated offensive security operations platform combining command-and-control, reporting, and data enrichment tooling to support managed red team service delivery for enterprise clients.
  • BloodHound MCP Integration layer that connects BloodHound Enterprise data to AI assistants via the Model Context Protocol, allowing analysts to query attack path information through conversational interfaces.
  • Red Team Services Full-scope adversary simulation engagements in which SpecterOps operators emulate real-world threat actors to test and improve enterprise detection and response capabilities.
  • Penetration Testing Targeted, time-boxed technical assessments of enterprise networks, applications, and infrastructure to identify exploitable vulnerabilities and produce remediation guidance.
  • Web Application Security Application-layer security assessments covering web apps and APIs, including dynamic testing and code-aware review, designed for enterprise development and product security teams.
  • AI Red Team

Quantifiable outcome

  • 200+ customers for BloodHound Enterprise
  • +2 more outcomes

Companies that use SpecterOps

Customer profile

Named customers7 records

Segments5 records

Ideal customer profiles2 records

SpecterOps technology and API

Technology

Technology focussed Yes

API detail

Has API
Yes
API docs
API detail

Core technology

AI maturity

App detail

Integration11 records

AI capability12 records

Feature10 records

SpecterOps partnerships and signals

Strategic signal

Partnerships

13 partnerships are on record, tiered flagship and core.

  • OpenAIflagshipStrategic or Co-development Partner · 1 April 2026SpecterOps was selected for OpenAI's Trusted Access for Cyber (TAC) program in April 2026, gaining access to advanced cyber-capable models (e.g., GPT-5.4-Cyber) for defensive research. In June 2026 the relationship expanded into the OpenAI Daybreak Cyber Partner Program, with co-developed AI training workshops at Black Hat USA 2026 and embedded AI capabilities (Triage, automated enclave discovery) inside BloodHound and GhostWorks.
  • CiscoflagshipStrategic or Co-development Partner · 10 February 2026Announced at Cisco Live EMEA in Amsterdam on February 10, 2026, Cisco and SpecterOps jointly launched Active Directory Defense for Cisco Duo, embedding SpecterOps' identity attack path capabilities into Cisco's Duo security offering.
  • TinescoreTechnology or Integration · 4 December 2025SpecterOps and Tines announced a partnership to automate attack path management through a native BloodHound integration, enabling automated attack path identification and mitigation within Tines workflows.
  • Kevin Mandia (CEO of Mandiant)coreStrategic or Co-development PartnerStrategic individual investor and advisor participation in Series A extension; provides industry expertise and credibility.
  • Microsoft SentinelcoreTechnology or IntegrationNative integration between BloodHound Enterprise and Microsoft Sentinel for security workflow and SIEM integration.
  • Palo Alto NetworkscoreTechnology or IntegrationIntegration of BloodHound Enterprise with Palo Alto Networks products for identity attack path management.
  • ServiceNowcoreTechnology or IntegrationIntegration of BloodHound Enterprise with ServiceNow for security workflow and remediation management.
  • OktacoreTechnology or IntegrationCoverage of Okta identity environments in BloodHound Enterprise for attack path detection and remediation, announced March 2026.
  • GitHubcoreTechnology or IntegrationBloodHound Enterprise coverage of GitHub environments for cross-platform attack path mapping (via OpenGraph), announced March 2026.
  • Apple (Mac)coreTechnology or IntegrationAdded Mac environment coverage in BloodHound Enterprise for hybrid attack path detection, announced March 2026.
  • Amazon Web Services (AWS)coreTechnology or IntegrationAWS is SpecterOps' cloud hosting provider and infrastructure partner, leveraging AWS security certifications and isolated single-tenant architecture for BloodHound Enterprise.
  • UK AI Security InstitutecoreStrategic or Co-development PartnerCollaboration with the UK AI Security Institute applying SpecterOps' adversary tradecraft knowledge across public and private engagements.
  • BloodHoundGang Slack CommunitycoreOthersOperates and hosts the BloodHoundGang Slack community (slack.specterops.io) as a core channel for tradecraft sharing and project collaboration.

Scale indicators8 records

Recent moves6 records

Expansion highlights7 records

SpecterOps competitors and assessment

Company assessment

Broad incumbents

  • CrowdStrike: Endpoint and cloud security leader whose Falcon Identity Threat Detection and Falcon Identity Threat Protection overlap with SpecterOps' identity attack path focus, but CrowdStrike operates as a broad platform across EDR, SIEM, and identity rather than specializing in attack-path mapping.
  • Microsoft (Defender for Identity / Security Copilot): Owner of Active Directory and Entra ID with native Defender for Identity and Security Copilot capabilities that increasingly cover identity attack-path analytics. SpecterOps lists Microsoft as both a customer (BloodHound Enterprise) and a partner (Microsoft Sentinel integration), making Microsoft both a competitor and ecosystem participant.
  • Palo Alto Networks (Cortex / Unit 42): Broad cybersecurity platform with Cortex XSIAM and Unit 42 attack-path-adjacent services, and a disclosed integration partner of BloodHound Enterprise. Competes at the platform layer while cooperating at the integration layer.
  • Tenable: Vulnerability management leader extending into identity and exposure management (Tenable Identity Exposure / formerly Tenable.ad) with BloodHound-style AD attack-path visualization. Closest large-cap competitor in identity attack path management.
  • Wiz: Cloud security platform with identity-aware cloud detection and response (CDR) capabilities and acquisition-driven identity exposure analytics. Competes indirectly by extending attack-path visibility into cloud and identity from a cloud-native base.

Direct peers

  • BeyondTrust: Privileged access management vendor offering identity security, AD/Entra auditing, and attack-path-adjacent capabilities. Closely aligned with SpecterOps' focus on identity-driven lateral movement and privilege escalation.
  • CyberArk: Privileged access management leader offering identity security, just-in-time access, and identity threat detection that overlap with BloodHound Enterprise's identity attack path management focus.
  • Obsidian Security: Identity threat detection and response (ITDR) vendor focused on SaaS and identity provider attack paths. A direct competitor to BloodHound Enterprise in the emerging identity threat detection category.

Emerging players

  • Saviynt: Cloud-native identity governance and administration platform with converged identity security, including risk-aware identity analytics that intersect with SpecterOps' attack-path prioritization capabilities.

Others

  • Semgrep (and emerging code/identity security players): Developer-first security vendor; representative of the broader ecosystem of code and identity security companies that could converge on attack-path and identity-exposure analytics, complementing or competing with SpecterOps' BloodHound platform.

Market position

Strengths5 records

Weaknesses5 records

Competitive moat7 records

Key risks6 records

Key highlights7 records

Customer concentration

SpecterOps social profiles

Digital presence

SpecterOps compliance and trust

Trust signal

Compliance8 records

SpecterOps financial estimates

Financial estimate

Revenue estimate

Valuation estimate

SpecterOps leadership team

Management profile

Number of profiles

Profiles9 records

SpecterOps funding detail

Funding detail

Funding overview

Funding rounds5 records

Investors6 records

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

SpecterOps M&A and investment

M&A and investment

M&A1 record

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about SpecterOps

What does SpecterOps do?

SpecterOps develops cybersecurity software and delivers offensive security services focused on identity attack path management. Its flagship commercial product, BloodHound Enterprise, maps and analyzes Active Directory and Azure identity attack paths, while the firm also publishes several open-source security tools (BloodHound CE, Mythic, Ghostwriter, Nemesis). The company additionally offers professional services including red teaming, penetration testing, and security program development for enterprise customers.

Is SpecterOps a public or private company?

SpecterOps is a private company. It is classified as venture growth investor backed and is currently operating.

When was SpecterOps founded?

SpecterOps was founded in 2017. It employs 251 to 500 people.

Where is SpecterOps based?

SpecterOps is headquartered in Alexandria, United States, in the North America region.

How does SpecterOps make money?

Three revenue lines are on record. BloodHound Enterprise (BHE) subscription is the primary driver. The others are professional services (red team, pen testing, assessments, advisory) and training and education.

Who are SpecterOps's main competitors?

Broad incumbents on record are CrowdStrike, Microsoft (Defender for Identity / Security Copilot), Palo Alto Networks (Cortex / Unit 42), Tenable and Wiz. Direct peers are BeyondTrust, CyberArk and Obsidian Security. Saviynt is listed as an emerging player. Semgrep (and emerging code/identity security players) is listed as an others.

Does SpecterOps have an API?

Yes. SpecterOps offers a public BloodHound API (referenced as 'extensive API') and a BloodHound MCP (Model Context Protocol) server for AI agent integrations. The MCP exposes 13 composite tools (domain_info, user_info, group_info, computer_info, ou_info, gpo_info, graph_analysis, adcs_info, cypher_query, data_quality, custom_nodes, asset_groups, file_upload) plus resources (e.g., bloodhound://cypher/reference, bloodhound://guides/ad, bloodhound://guides/azure) for AI agent interaction with BloodHound data. The MCP also supports file upload for controlled SharpHound/AzureHound collection uploads. API documentation is available at https://bloodhound.specterops.io/. The BloodHound MCP repository is open source at https://github.com/mwnickerson/bloodhound_mcp. Developer documentation is at bloodhound.specterops.io.

What industry is SpecterOps in?

SpecterOps's product category is Cybersecurity Software. Its primary akta.pro industry code is BPAEADAG, Network Security Managed Services (Firewall/IDS/IPS/SASE). Its NAICS code is 54151 and its SIC code is 7381.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales
Live signals
Techzine EuropeSpecterOps: What a (proper) LLM jailbreak test looks likeSpecterOps AI/ML applied scientist Neeraj Gupta argues that LLM jailbreak testing requires more than ad-hoc scripts, spreadsheets and screenshots, calling for a standardised, automated process. He describes using AI judge models, logging prompts, models, configurations and results, and maintaining an AI bill of materials for compliance.Security BoulevardNew Passkey Attacks Explained: What Security Researchers Found This AugustSpecterOps presented "Pass-the-Passkey" research at Black Hat USA 2026, detailing over 20 techniques exploiting Windows 11's WebAuthn logging and Microsoft Entra ID's replay validation gaps, including a replay chain that impersonates privileged admins. Unit 42 disclosed "Pass-ta-key" attacks on Google Password Manager's synced passkeys, and Dirk-jan Mollema showed Windows Hello for Business keys usable without a fresh PIN. Microsoft patched the Windows logging flaw on July 14, 2026.The Hacker NewsChrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows BrowsersCybersecurity researchers from SpecterOps have detailed a post-exploitation technique using the Chrome DevTools Protocol (CDP) to hijack authenticated sessions in running Google Chrome and Microsoft Edge browsers on Windows. This method allows attackers with existing code execution privileges to extract cookies, saved passwords, and browser data by injecting code into the browser process, bypassing some of Google's recent security updates like App-Bound Encryption. The technique relies on specific version signatures for Chrome 147 and Edge 147, though it aims to sidestep protections designed to prevent off-device replay of stolen credentials.Cyber Security NewsBlacklight Toolkit Finds Codex, Claude Code, and Cursor Artifacts Exposing Tokens and Session DataSpecterOps has released Blacklight, an open-source toolkit designed to identify local artifacts generated by AI coding agents like Codex, Claude Code, and Cursor. The toolkit helps security teams manage the exposure of sensitive data, such as authentication files and session histories, associated with these AI tools. With the increasing use of AI agents in coding, the need for robust endpoint security measures, including the protection of local artifacts, has become increasingly critical for organizations.Tech Wire AsiaOpenAI expands access to cyber AI models with tighter safeguardsOpenAI is expanding access to its cyber AI models through the Daybreak program, giving approved partners tools for vulnerability discovery and incident response. The company assessed its Astra model at the High cybersecurity threshold, requiring safeguards before deployment. It may reach the Critical level, prompting stricter controls and isolated testing.The New StackOpenAI built a model it doesn’t want most people to useOpenAI released GPT-5.6 Cyber, a security-focused model available through its Daybreak Red tier, which answered 95% of exploit-chain requests in internal tests. The model found two V8 flaws and three database vulnerabilities, but its reports were shorter and less detailed than GPT-5.6 Sol. Daybreak users must use hardware security keys starting September 1, 2026.Cyber PressWSUS Flaw Lets Attackers Turn Enterprise Update Servers Into Malware Delivery SystemsA SpecterOps researcher demonstrated how attackers can coerce a WSUS server's machine account to authenticate to a relay point, then access the SUSDB database. Stored procedures can be chained to create custom updates and deliver payloads, bypassing signature checks. Microsoft's July 2026 advisories include related CVEs, prompting mitigation steps like EPA and port restrictions.Cyber Security NewsHackers Can Leverage WSUS Servers to Deliver Malware and Compromise Enterprise EndpointsSpecterOps researcher Beyviel David published a novel attack chain that allows adversaries to hijack Windows Server Update Services (WSUS) by exploiting NTLM authentication coercion and a logic flaw in the ContentSyncAgent.dll library. The vulnerability enables attackers to forge malicious updates with arbitrary payloads that bypass digital signature validation when using .txt or .esd file extensions, achieving persistent code execution on domain-joined endpoints without requiring valid user credentials. The researchers also released open-source tools including ludus_wsus and NotWSUSpicious to help security teams test for this exposure, along with mitigation recommendations such as enabling Extended Protection for Authentication on SQL servers and network segmentation.SecuritybriefSpecterOps adds AWS & Entra Agent ID to BloodHoundSpecterOps has added Amazon Web Services and Microsoft Entra Agent ID support to BloodHound Enterprise, extending its attack path management platform into hybrid cloud and AI-linked environments. The company also introduced BloodHound Hunter, an AI agent interface built on the Model Context Protocol that connects approved AI agents and knowledge sources to BloodHound Enterprise findings, enabling security teams to map and disrupt attack paths across cloud, identity, and on-premises infrastructure from a single attack graph. The additions reflect growing concern that AI agents create new identity and access risks by operating across multiple systems, pushing organizations to examine permissions and trust relationships rather than just AI tool behavior.Business Wire BlogSpecterOps Extends Attack Path Management Across Hybrid and Agentic AI WorkflowsSpecterOps announced new capabilities for BloodHound Enterprise, including support for Amazon Web Services and Microsoft Entra Agent ID, along with a new AI agent interface called BloodHound Hunter. The additions extend attack path management across hybrid cloud, identity, AI, and on-premises environments, allowing security teams to trace and sever abusable pathways before exploitation. The company positions these capabilities as particularly important as enterprises deploy AI agents, enabling proactive rather than reactive threat response.