OpenHound Jamf / JamfHound
Use this skill for OpenHound Jamf OpenGraph query design and attack-path triage with JamfHound/OpenHound Jamf data.
Required context
- Authorized Jamf tenants/sites and managed device scope.
- Whether JamfHound/OpenHound Jamf extension/schema/data is loaded.
- Collector account type/permissions, Jamf Cloud vs on-prem context, and site scoping.
- Target accounts, groups, API clients, sites, computers, tenant objects, policies, scripts, or profiles.
Workflow
- Read
../../references/docs/bloodhound-query-methodology.md,../../references/docs/openhound-jamf-methodology.md, and../../references/docs/collector-source-index.md. - Inspect JamfHound schema/object examples under
../../references/examples/jamfhound/when node/property shape matters. - Search
../../references/query-indexes/openhound-jamf.mdand../../references/examples/example-cypher.mdfor a saved-search starting point. - Inspect the referenced JSON snapshot before adapting.
- Preserve
jamf_labels/edges andr.traversable = Truefilters where the source query uses them. - Distinguish tenant-wide paths from site-scoped permissions and identify hybrid identity/device bridge assumptions.
Common pivots
- Accounts/groups/API clients to tenant administration.
- Site-scoped admin paths to managed computers.
- Policy/script/profile creation or modification control.
- Disabled principal hygiene and stale access.
- Jamf paths linked to SSO/identity providers when hybrid data exists.
- Okta/Jamf hybrid device-management paths when OktaHound or another collector produced bridge data.
Output
Use the shared output contract from $bloodhound-query and include Jamf-specific caveats such as site scoping, collector account privilege, disabled-account interpretation, extension/schema availability, hybrid bridge availability, and managed-device collection completeness.