Skip to content

[New Integration] added SpecterOps BloodHound Enterprise integration - #21063

Open
omkarj-metron wants to merge 3 commits into
elastic:mainfrom
SpecterOps:feature/bloodhound_enterprise
Open

[New Integration] added SpecterOps BloodHound Enterprise integration#21063
omkarj-metron wants to merge 3 commits into
elastic:mainfrom
SpecterOps:feature/bloodhound_enterprise

Conversation

@omkarj-metron

Copy link
Copy Markdown

Proposed commit message

Add a new SpecterOps BloodHound Enterprise Fleet integration (bloodhound_enterprise v1.0.0).

WHAT:

  • CEL-based Case & Alert Sync (health_check) that polls BloodHound Enterprise, creates/updates Elastic Security Cases, attaches Security Alerts for at-risk principals, and deletes stale cases
  • Optional finding data stream for raw attack-path finding documents (disabled by default)
  • Ingest pipelines, field mappings, package docs, and Attack Path Overview Kibana assets

WHY:

  • Enable customers to track BloodHound Enterprise attack-path findings in Elastic Security Cases/Alerts for investigation and remediation

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
  • I have verified that any added dashboard complies with Kibana's Dashboard good practices

Author's Checklist

  • Package lives under packages/bloodhound_enterprise/
  • elastic-package check passes
  • Pipeline tests pass for health_check and finding
  • System tests pass and sample_event.json generated
  • Docs rendered from _dev/build/docs/README.md
  • Changelog link: updated to this PR URL after open
  • CODEOWNERS entry coordinated with Elastic reviewers
  • Leftover scaffold assets (e.g. unused log stream) removed if not intentional

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Reviewers

Buildkite won't run for external contributors automatically; you need to add a comment:

  • /test : will kick off a build in Buildkite.

NOTE: https://github.com/elastic/integrations/blob/main/.buildkite/pull-requests.json contains all those details.

@omkarj-metron
omkarj-metron marked this pull request as ready for review September 4, 2026 07:43
@omkarj-metron
omkarj-metron requested a review from a team as a code owner September 4, 2026 07:43
@omkarj-metron

Copy link
Copy Markdown
Author

/test

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant