Andy Robbins
- Co-created BloodHound with Will Schroeder and Rohan Vazarkar, released at DEF CON 24
- Extended attack-path analysis to Azure and Entra ID in BloodHound 4.0
- Principal product architect at SpecterOps
Bio
Andy Robbins co-created BloodHound with Will Schroeder and Rohan Vazarkar, released at DEF CON 24, and led its extension from on-premises Active Directory into Azure and Entra ID. He is a principal product architect at SpecterOps.
Profile built from public project, conference, and company records.
Where their work shows up
BloodHound's contribution is conceptual as much as technical: model an identity environment as a graph, and privilege escalation stops being a list of misconfigurations and becomes a shortest path between two nodes. Defenders had been auditing group membership one object at a time while attackers were reading the whole graph. Attack-path management as a product category, and the way ITDR tools now present findings, both follow from that. See orphaned account abuse, entitlement accumulation, and the best ITDR for Active Directory ranking.
Related on Start with Identity
- GlossaryIdentity Resilience
The ability to keep authenticating and authorising legitimate users, and to recover the identity system itself, when the identity provider or directory is degra
- ExpertCo-creator of BloodHound, AD CS attack research
Will Schroeder co-created BloodHound and has published a long run of Active Directory research, including the Certified Pre-Owned work on Active Directory Certi
- ExpertCreator of mimikatz
Benjamin Delpy, who publishes as gentilkiwi, wrote mimikatz in 2011 after finding that Windows held both an encrypted copy of a password and the key to decrypt
- ExpertEntra ID and Active Directory researcher
Dirk-jan Mollema researches Microsoft identity from the outside and writes the tooling to prove his findings: ROADtools for Entra ID, mitm6 and krbrelayx for re