I mainly use BloodHound Enterprise for internal architecture planning, audits, and daily general testing engagements.
What is our primary use case?
How has it helped my organization?
The simulation capability in BloodHound has significantly influenced our security strategy as it helps us plan attacks and take initial steps in compromising networks, considerably impacting our engagements.
What is most valuable?
The custom Cypress queries in BloodHound Enterprise is the most valuable feature. It allows me to edit almost everything hourly, which is excellent.
What needs improvement?
I don't have any specific improvements in mind, as I haven't encountered any significant issues with BloodHound Enterprise. However, a few months ago, there was a problem with the digesters having trouble importing data from the normal digesters, a significant issue that needed attention.
For how long have I used the solution?
I have been using BloundHound Enterprise for one year.
What do I think about the stability of the solution?
I've noticed some stability issues with BloodHound Enterprise, especially in larger environments with thousands of computers and user accounts. Sometimes, when processing data, it doesn't display accurate information or process all the data correctly, which can lead to bugs or incorrect results.
What do I think about the scalability of the solution?
The scalability is good since adding or removing users in BloodHound Enterprise was straightforward.
How was the initial setup?
The initial installation and deployment of BloodHound Enterprise from Broadcom was quite simple. I didn't encounter any difficulties or accuracy issues during the process.
What other advice do I have?
I haven't explored cost-saving aspects or utilized integration capabilities within BloodHound. Additionally, I haven't used AI features in Broadcom for threat detection yet, leaving that to our IT team to handle.
If you're already familiar with the field, learning to use BloodHound Enterprise shouldn't be too tricky as the UI is user-friendly and the features are straightforward. I'd rate my overall experience around an eight, mainly due to occasional performance issues and deeper operational concerns. However, in terms of features, UI, and ease of use, it's top-notch.
Which deployment model are you using for this solution?
On-premises

