IAM Vulnerability Discovery · Built by IAM engineers

See every weakness in your identity stack.

IAM X-ray scans Active Directory, Entra ID, and beyond — and tells you, in plain language, exactly where attackers will go next. No CVSS gymnastics. No vendor marketing. Just the findings that matter, ranked by real-world blast radius.

32built-in scanners
4identity providers (roadmap)
0hardcoded priv-group lists
live demo · loops every 9s
Designed against the realities of
The Problem

You already know your AD has problems.
You just can't prove it on a dashboard.

Generic scanners miss identity.

Vuln scanners flag CVEs on hosts. They don't see Kerberoastable accounts, AdminSDHolder drift, or that one Tier-1 user who is in Domain Admins via two layers of nested groups.

Built-in tools are static.

PowerShell scripts and the Microsoft AD Health checker are point-in-time. They don't follow privilege chains. They don't know your custom delegation groups. And they certainly don't write a clean executive summary.

BloodHound is a forensic tool.

BloodHound is excellent for incident response. It's not a recurring audit your CISO can read on a Monday. We sit in that gap.

How it works

Three steps. Every customer. Every IDP.

A single pipeline runs across Active Directory, Entra ID, Okta, and offline snapshots. Same engine. Same risk model. Same reports.

01

Connect

Bind read-only via LDAPS, ingest a SharpHound zip, or point at a JSON snapshot. Credentials live in the OS keystore, never in config.

corp.acme.local
IAM X-ray
02

Discover

Reverse-engineer your privileged-group registry from confirmed admins. No static "Domain Admins" assumption — we find your custom delegation groups automatically.

03

Report

Risk-scored findings, evidence rows, plain-language glossary. Interactive HTML, full XLSX, signed PDF. The CSV registry your auditor will actually read.

5
11
9
3
CriticalHighMediumLow
What it finds

32 scanners and counting.

Each scanner produces a structured Finding with risk-scored evidence, plain-language glossary, and prioritized remediation. Add a scanner = one new file.

Tier-0

Kerberos & delegation

Kerberoastable, AS-REP roastable, unconstrained delegation, RBCD, krbtgt rotation, shadow credentials. Mapped to MITRE T1558.

Tier-0

ACL surface

OU-direct user delegation, AdminSDHolder drift, DCSync rights, sensitive-group write paths. Catches the persistence tricks attackers actually use.

Tier-0

AD CS

ESC1 / ESC2 / ESC3 / ESC8 detection. The rest of the ESC family is one file each — the model is in place.

Privilege model

Reverse-engineered priv groups

Walks up from confirmed administrators to discover your actual privileged-group surface — including custom delegation groups static checkers will never find.

Lifecycle

Account hygiene

Inactive, never-logged-in, disabled-with-groups, externals without expiry, password never expires, password expired, weak password policy.

Inventory

Endpoint & structure

Out-of-support OS, LAPS coverage gaps, empty OUs, unlinked GPOs, identical-membership clusters, human/non-human classification.

The deliverable

Reports your CISO will actually read.

Every run produces an interactive HTML executive summary, a full XLSX, a CSV pair for downstream pipelines, and an archive-grade PDF. Plus a privileged-groups registry CSV your auditor will love.

  • Plain-language glossary on every finding type — share with stakeholders, no decoder ring required.
  • Filter by severity, scanner, search across evidence. Print-ready.
  • Risk score 0–100 with a custom IAM model that knows blast radius beats CVSS.
  • Standalone HTML — no external CDN calls, no telemetry, air-gap ready.
IAM X-ray — Executive Summary
corp.acme.local · 28 findings · Generated 2026-04-28
Critical5
High11
Medium9
Low3
CRITICAL
DCSync rights granted to non-DC principal
ad.dcsync_rights · risk score 92 · 1 affected
CRITICAL
Unconstrained delegation on svc.legacy
ad.unconstrained_delegation · risk score 88 · 1 affected
CRITICAL
AD CS template ESC1 — enrollee-supplies-subject
ad.adcs_esc1 · risk score 87 · 2 templates
HIGH
Standard accounts with privileged access
ad.standard_accounts_with_privileged_access · risk score 76 · 7 accounts
Architecture

Modular by design. Pluggable forever.

Connectors translate each IDP into a common model. Scanners read the model. Reports read scanner output. Adding a check is a single file.

Connectors
AD live (LDAPS) AD offline (snapshot) Entra ID Okta · soon Ping · soon
Common Model
User Group Computer OU GPO Cert template ACE
Scanners (32)
Account hygiene Password policy Kerberos Delegation ACL drift AD CS Inventory
Reports
HTML exec XLSX CSV PDF Priv-group registry
Modules

Buy only what you need.

Every module is separately licensed. License keys are validated at scanner registration time — Ed25519 signed, offline-verifiable, no phone-home.

Shipping v0.0.1

AD Vulnerability Discovery

31 scanners across account lifecycle, password policy, Kerberos, delegation, ACL surface, AD CS, and inventory. Live + offline.

  • Live LDAPS ingestion via ldap3
  • Offline JSON snapshot for consulting
  • Reverse-engineered priv-group registry
  • 4 ESC scanners (ESC1/2/3/8)
Preview 1 scanner

Entra Vulnerability Discovery

First scanner: privileged-without-MFA. CA drift, dormant guests, app-consent risk, PIM coverage in development.

  • msgraph-sdk integration
  • Priv-account classification reuses AD config
  • Same risk model, same reports
Roadmap

Okta & Ping

Connectors scaffolded. Scanner suite buildout follows customer demand.

Shipping

Environment Discovery

Probes the target and writes a customer-config seed. Cuts new-tenant setup from hours to minutes.

Roadmap

Investigation

Targeted deep-dives on a single user, group, or computer: every relationship, every membership, every cert, every ACL.

Roadmap

Audit & Reporting

Scheduled scans, drift reports, regulatory packs (SOX, PCI-DSS, HIPAA, ISO 27001, NIS2).

Built by people who've fixed it

From the IAM engineer's perspective.

"

Every static "list of priv groups" tool I've used has missed the custom delegation groups my team actually uses. So I built one that walks up from confirmed admins instead.

PauloIAM Engineer Manager · 10+ years · founder
"

CVSS scores were never built for identity. krbtgt being old and one stale user account aren't comparable. So we shipped a custom risk model — and we map it back to CVSS so your vuln management tools still get fed.

Engineering principleFrom the design doc

Ready to see what's hiding in your AD?

Spin it up against the synthetic snapshot in two minutes. Open the live HTML report. Decide if you want it pointed at your real environment.