Cypher: Shortest Path to Domain Admins

Find the shortest attack path from any owned user to the Domain Admins group. The bread-and-butter BloodHound query — run it after every collection to see what changed. Mark accounts as owned in the BloodHound UI before running.

Tool
MATCH
Category
Enumeration / BloodHound Cypher Queries
Platform
cross-platform
Requires
no credentials

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

MATCH p=shortestPath((u:User {owned:true})-[*1..]->(g:Group {name:'DOMAIN ADMINS@<DOMAIN>'})) RETURN p

Examples

MATCH p=shortestPath((u:User {owned:true})-[*1..]->(g:Group {name:'DOMAIN ADMINS@CORP.LOCAL'})) RETURN p

Tags

bloodhound cypher shortest-path domain-admins graph

References