> ## Documentation Index
> Fetch the complete documentation index at: https://specterops-fetch-json-component.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Overview

> Learn about JamfHound, an OpenGraph extensions and data collector for JAMF Pro.

<img noZoom src="https://mintcdn.com/specterops-fetch-json-component/pkiaFEhjWYPnhxMb/assets/enterprise-AND-community-edition-pill-tag.svg?fit=max&auto=format&n=pkiaFEhjWYPnhxMb&q=85&s=c83d7e4a67c741a979c0e77bf15c1252" alt="Applies to BloodHound Enterprise and CE" width="482" height="45" data-path="assets/enterprise-AND-community-edition-pill-tag.svg" />

JamfHound is an OpenGraph extension and data collector for [JAMF Pro](https://www.jamf.com/products/jamf-pro/) locally hosted and cloud environments that helps security professionals visualize and analyze their JAMF Pro configurations in BloodHound.

It collects data about users, groups, sites, scripts, API integrations, and other entities within a JAMF Pro tenant and represents them as [nodes](/opengraph/extensions/jamfhound/reference/schema#nodes) and [edges](/opengraph/extensions/jamfhound/reference/schema#edges) in BloodHound's graph database.

<Note>The other main products in JAMF's portfolio are [JAMF Protect](https://www.jamf.com/products/jamf-protect/), [JAMF Account](https://learn.jamf.com/en-US/bundle/jamf-account-documentation/page/Jamf_Account_Documentation.html), [JAMF Now](https://www.jamf.com/products/jamf-now/), and [JAMF Connect](https://www.jamf.com/products/jamf-connect/). JamfHound **does not** currently support these products.</Note>

## JAMF Pro Attack Paths

JAMF Pro is a highly valuable target for attackers in the modern enterprise. The privileged MDM
actions required to administer Apple devices with JAMF Pro allow elevated access to local devices and complicates the jobs of EDRs and defensive teams trying to differentiate benign and malicious actions.

Compromising a JAMF Pro tenant can provide attackers with a wide range of access to laterally move to Apple devices, exfiltrate information, lock or DOS devices, and more.

<Frame>
  <img src="https://mintcdn.com/specterops-fetch-json-component/Aknesi2NwciziFMX/images/extensions/jamfhound/jamf-graph.png?fit=max&auto=format&n=Aknesi2NwciziFMX&q=85&s=bc9015c4fda101751b1b15cbf9af19e7" alt="Example JamfHound graph" width="990" height="883" data-path="images/extensions/jamfhound/jamf-graph.png" />
</Frame>

SpecterOps has identified and exploited numerous JAMF Pro misconfigurations and blind spots during red team engagements and penetration tests in hardened macOS client environments. One such attack path has been highlighted in the [State of Attack Path Management](https://specterops.io/wp-content/uploads/sites/3/2025/08/StateofAPM-2025_1037-0_Updated.pdf) (p 59,60).

Our research on JAMF attack paths is still ongoing.

## JAMF Pro Trial

JAMF Pro provides a [free trial](https://www.jamf.com/request-trial/) for organizations interested in testing their MDM capability.

## References

We recommend reading the following posts and pages to learn more about potential JAMF Pro attack vectors:

* [Lance Cain and Daniel Mayer (SpecterOps): Leveraging Jamf For Red Teaming in Enterprise Environments](https://i.blackhat.com/BH-USA-25/Presentations/USA-25-Cain-Mayer-Leveraging-Jamf-for-Red-Teaming.pdf)
* [Video: Leveraging Jamf For Red Teaming in Enterprise Environments](https://www.youtube.com/watch?v=6TZD5Gb7z0c)
* [Calum Hall and Luke Roberts (GitHub): Come to the Dark Side, We Have Apples | Turning macOS Management Evil](https://i.blackhat.com/USA21/Wednesday-Handouts/us-21-Come-To-The-Dark-Side-We-Have-Apples-Turning-MacOS-Management-Evil.pdf)
* [(1nf1n1ty): macOS Red Teaming | Abusing MDMs](https://blog.1nf1n1ty.team/hacktricks/macos-hardening/macos-red-teaming#abusing-mdms)

## Research Tools

Here are some interesting GitHub repositories related to JAMF Pro security research:

* [Eve JAMF Post Exploitation Toolkit](https://github.com/RobotOperator/Eve)
* [Typhon Mythic Agent](https://github.com/MythicAgents/typhon)
* [Jamf-Attack-Toolkit](https://github.com/ReversecLabs/Jamf-Attack-Toolkit)

## Community

Please join us in the `#jamf` channel of the [BloodHound Community Slack](https://slack.specterops.io/) workspace if you want to chat about attack paths in JAMF or the usage of JamfHound. You are also welcome to open an issue or pull request on [GitHub](https://github.com/SpecterOps/JamfHound).
