> ## Documentation Index
> Fetch the complete documentation index at: https://specterops-bp-2641-crowdstrike-integration.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# 2026-06-17 Release Notes

> Learn about new features, enhancements, and fixed issues in BloodHound.

|             |                |               |                |                |
| ----------- | -------------- | ------------- | -------------- | -------------- |
| **Release** | **BloodHound** | **OpenHound** | **SharpHound** | **AzureHound** |
| 2026-06-17  | v9.3.0         | v0.2.1        | No release     | v2.12.2        |

<Tip>
  Use the filters on the right side of this page to narrow down the updates by component. You can select multiple filters at the same time to refine your results.
</Tip>

<Update label="OpenHound" description="New Feature" tags={["Data Collection"]}>
  ## Jamf API Client Authentication

  Authenticate the OpenHound Jamf collector with a Jamf Pro API client instead of relying on a Jamf user account and password.

  This update adds support for Jamf [API clients](/openhound/collectors/jamf/collect-data) as the recommended authentication method. API clients are not tied to a user account, can be scoped to a dedicated API role, and can be rotated or revoked independently, making them a better fit for production environments and least-privilege access.
</Update>

<Update label="OpenHound" description="New Feature" tags={["Data Collection"]}>
  ## GitHub Enterprise SSO Support

  Connect OpenHound to GitHub Enterprise environments that enforce single sign-on at the enterprise level.

  This update adds support for [GitHub Enterprise](/openhound/collectors/github/configure-enterprise-app) environments where SSO blocked OpenHound from accessing repositories through the configured GitHub App.
</Update>

<Update label="BloodHound" description="Enhancement" tags={["Administration"]}>
  ## Role-Based Access Hardening

  Read access for the **User**, **Power User**, and **Read-only** roles has been reduced to limit exposure to sensitive user data and administrative API endpoints.

  This update refines the permission model for administration-related APIs so these roles retain access only to the endpoints and data required for their supported workflows.

  For example, these roles can use the [List Users Minimal](/reference/bloodhound-users/list-users-minimal) endpoint to read user data, but cannot access sensitive information through the broader [List Users](/reference/bloodhound-users/list-users) endpoint.
</Update>

<Update label="BloodHound" description="Enhancement" tags={["Administration"]}>
  ## Auditor Access Improvements

  Users with the **Auditor** role can now view the **Manage Users** and **Manage Clients** tables without requiring the permissions needed to create or modify those resources.

  This update adds read-only access to those management views while keeping administrative actions such as **Create User**, **Create Client**, and other modification workflows restricted to the **Admin** role.
</Update>

<Update label="BloodHound" description="Enhancement" tags={["Administration"]}>
  ## Expanded Audit Logging

  [Audit logs](/reference/audit/list-audit-logs) now capture additional high-risk user actions, including running Cypher queries, editing collector clients or schedules, and running on-demand collections.

  This change improves visibility into sensitive operator actions for security reviews and compliance workflows.
</Update>

<Update label="BloodHound" description="Enhancement" tags={["Accessibility"]}>
  ## Accessibility Improvements

  Data tables now provide more accessible headers, sorting behavior, keyboard navigation, and screen reader announcements.

  This update improves table usability across supported browsers and helps align the experience with WCAG 2.1 accessibility requirements.
</Update>

<Update label="BloodHound" description="Enhancement" tags={["API"]}>
  ## OpenGraph Extension Namespace Visibility

  The [List OpenGraph Extensions Information](/reference/opengraph-experimental/list-opengraph-extensions-information) endpoint now includes each extension's [`namespace`](/opengraph/developer/graph-definition#param-namespace) key in its response body.

  This change gives the API and the [OpenGraph Management](/opengraph/extensions/manage) page the information needed to expose the namespace prefix used for extension-defined node types.
</Update>

<Update label="BloodHound" description="Enhancement" tags={["Explore"]}>
  ## Full-Path Highlighting

  When you select a node in the graph, BloodHound now dims paths that do not traverse the selected node. This includes inbound and outbound object control, making it easier to isolate how a node participates in longer Attack Paths.

  Full-path highlighting is enabled by default. See [Object interaction](/analyze-data/explore/search#object-interaction) for more information.
</Update>

<Update label="BloodHound" description="Enhancement" tags={["Post-Processing"]}>
  ## Analysis Performance Improvements

  Optimized processing logic for the following edge types, significantly reducing time in analysis:

  * [Owns](/resources/edges/owns)
  * [WriteOwner](/resources/edges/write-owner)
  * [EnrollOnBehalfOf](/resources/edges/enroll-on-behalf-of)
  * [ADCSESC1](/resources/edges/adcs-esc1)
  * [ADCSESC3](/resources/edges/adcs-esc3)
  * [ADCSESC4](/resources/edges/adcs-esc4)
  * [ADCSESC6a](/resources/edges/adcs-esc6a)
  * [ADCSESC6b](/resources/edges/adcs-esc6b)
  * [ADCSESC13](/resources/edges/adcs-esc13)
  * [SyncLAPSPassword](/resources/edges/sync-laps-password)
  * [ReadLAPSPassword](/resources/edges/read-laps-password)
  * [DCSync](/resources/edges/dc-sync)
  * [CanRDP](/resources/edges/can-rdp)
  * [AdminTo](/resources/edges/admin-to)
  * [ExecuteDcom](/resources/edges/execute-dcom)
  * [CanPSRemote](/resources/edges/can-ps-remote)
</Update>

<Update label="BloodHound" description="Enhancement" tags={["OpenGraph"]}>
  ## Pre-Installed SpecterOps Extensions

  <img src="https://mintcdn.com/specterops-bp-2641-crowdstrike-integration/_rZ1zFkP5xLBuV5I/assets/enterprise-edition-pill-tag.svg?fit=max&auto=format&n=_rZ1zFkP5xLBuV5I&q=85&s=4a7cab6298d422be44331dd276b8e56d" alt="BloodHound Enterprise logo" style={{ width: "25%" }} width="225" height="45" data-path="assets/enterprise-edition-pill-tag.svg" />

  BloodHound Enterprise now includes pre-installed OpenGraph extensions for GitHub, Jamf, and Okta. This streamlines extension management by making these supported extensions available without a separate installation step.

  See [OpenGraph Extensions](/opengraph/extensions/manage) to learn more.
</Update>

<Update label="BloodHound" description="Enhancement" tags={["Posture"]}>
  ## Updated Attack Path Type Names

  <img src="https://mintcdn.com/specterops-bp-2641-crowdstrike-integration/_rZ1zFkP5xLBuV5I/assets/enterprise-edition-pill-tag.svg?fit=max&auto=format&n=_rZ1zFkP5xLBuV5I&q=85&s=4a7cab6298d422be44331dd276b8e56d" alt="BloodHound Enterprise logo" style={{ width: "25%" }} width="225" height="45" data-path="assets/enterprise-edition-pill-tag.svg" />

  The **Attack Paths** table on the **Posture** page now uses Privilege Zones terminology (where appropriate) instead of older **Tier Zero** naming.

  This update keeps Attack Path type names aligned with the latest findings documentation in BloodHound Enterprise.
</Update>

<Update label="BloodHound" description="Enhancement" tags={["Zone Builder"]}>
  ## Search Across Certification Statuses

  <img src="https://mintcdn.com/specterops-bp-2641-crowdstrike-integration/_rZ1zFkP5xLBuV5I/assets/enterprise-edition-pill-tag.svg?fit=max&auto=format&n=_rZ1zFkP5xLBuV5I&q=85&s=4a7cab6298d422be44331dd276b8e56d" alt="BloodHound Enterprise logo" style={{ width: "25%" }} width="225" height="45" data-path="assets/enterprise-edition-pill-tag.svg" />

  Search for objects across all [certification statuses](/analyze-data/privilege-zones/certification#by-status) in Zone Builder.

  This improvement helps you confirm whether a specific object is already present in a zone without selecting each certification status separately and running multiple searches.
</Update>

<Update label="BloodHound" tags={["Fixed Issues"]}>
  ## API

  {/*BED-6775*/} Resolved an issue where the **Composition** and **Relay Target** accordions in the Entity panel did not populate in the following ADCS edges, causing the related node and edge data to appear empty:

  * [CoerceAndRelayNTLMToADCS](/resources/edges/coerce-and-relay-ntlm-to-adcs)
  * [CoerceAndRelayNTLMToSMB](/resources/edges/coerce-and-relay-ntlm-to-smb)
  * [ADCSESC1](/resources/edges/adcs-esc1)
  * [ADCSESC3](/resources/edges/adcs-esc3)

  ## Cypher

  * {/*BED-7759*/} Fixed an issue where editing a saved query while another query was selected displayed the wrong query in the edit box, potentially causing you to overwrite the wrong saved query.
  * {/*BED-8360*/} Fixed a performance issue where reusing Cypher query variables caused queries to run significantly slower instead of making them more restrictive as intended.

  ## Posture

  <img src="https://mintcdn.com/specterops-bp-2641-crowdstrike-integration/_rZ1zFkP5xLBuV5I/assets/enterprise-edition-pill-tag.svg?fit=max&auto=format&n=_rZ1zFkP5xLBuV5I&q=85&s=4a7cab6298d422be44331dd276b8e56d" alt="BloodHound Enterprise logo" style={{ width: "25%" }} width="225" height="45" data-path="assets/enterprise-edition-pill-tag.svg" />

  {/*BED-8392*/} Resolved an issue where enabling **Logarithmic Chart Scale** caused the **Historical Findings** and **Total Attack Paths** charts to go blank.
</Update>

<Update label="OpenHound" tags={["Fixed Issues"]}>
  {/*BED-8389*/} Resolved an issue where the the OpenHound Okta collector appeared to connect successfully but returned incomplete data, with relevant Okta-based saved queries returning no results.
</Update>

<Update label="AzureHound" tags={["Fixed Issues"]}>
  <img src="https://mintcdn.com/specterops-bp-2641-crowdstrike-integration/_rZ1zFkP5xLBuV5I/assets/enterprise-edition-pill-tag.svg?fit=max&auto=format&n=_rZ1zFkP5xLBuV5I&q=85&s=4a7cab6298d422be44331dd276b8e56d" alt="BloodHound Enterprise logo" style={{ width: "25%" }} width="225" height="45" data-path="assets/enterprise-edition-pill-tag.svg" />

  {/*BED-8176*/} Resolved an issue for hosted `edge-*` AzureHound container images where an invalid collector version string caused BloodHound to reject uploads from the collector as unsupported.
</Update>
