IAM X-ray scans Active Directory, Entra ID and Google Cloud identity, tells you in plain language where an attacker would go next, and then does the account work that follows: terminations, transfers, onboarding and Entra SSO applications. It runs on your machine. Your directory data never leaves it.
$ iamxray run --connector ad-live --domain corp.acme.local [ad-live] bound to dc01.corp.acme.local ✓ [scanners] running 37 in dependency order... → ad.privileged_groups_discovery 3 groups → ad.kerberoastable [HIGH] 4 accounts → ad.unconstrained_delegation [CRITICAL] 1 account → ad.adcs_esc1 [CRITICAL] 2 templates → ad.dcsync_rights [CRITICAL] 1 principal → ad.standard_accounts_with_priv_access [HIGH] 7 accounts [reports] writing executive-summary.html, full-report.xlsx, evidence.csv, executive-report.pdf Done. 28 findings · 5 critical · 11 high · 9 medium · 3 low▌
Vulnerability scanners flag CVEs on hosts. They do not see Kerberoastable accounts, AdminSDHolder drift, or the one Tier 1 user who reaches Domain Admins through two layers of nested groups.
PowerShell scripts and portal blades are point in time. They do not follow privilege chains, they do not know your custom delegation groups, and they do not write an executive summary.
BloodHound is excellent for incident response. It is not a recurring audit your CISO can read on a Monday, and it does not close the account afterwards. IAM X-ray sits in that gap.
One pipeline runs against a live Active Directory, a live Entra tenant, an offline export or a portable snapshot. Same engine, same risk model, same reports.
Bind read only over LDAPS, connect to Entra through Microsoft Graph, or point at an offline export or a .iamx snapshot. Credentials live in the OS keystore or an environment variable, never in the config file.
Build your privileged group registry from confirmed administrators. No fixed Domain Admins list: the scanners find your custom delegation groups and everyone who reaches them through nesting.
Risk scored findings, evidence rows, a plain language glossary. Interactive HTML, full XLSX, CSV and PDF, plus the privileged groups CSV your auditor will read.
Every scanner produces a structured finding with a 0 to 100 risk score, the evidence rows behind it, a plain language glossary entry and a remediation. Adding a check is one new file.
Kerberoastable and AS-REP roastable accounts, unconstrained and resource based constrained delegation, krbtgt password age, shadow credentials.
Direct user delegation on OUs, AdminSDHolder drift, DCSync rights on principals that are not domain controllers, write paths into sensitive groups.
ESC1, ESC2, ESC3 and ESC8 on enrollable certificate templates and web enrollment endpoints.
Walks up from confirmed administrators to find your real privileged group surface, including the custom delegation groups a fixed list never sees. Then reports who is privileged, how, and which standard accounts got there through nesting.
Inactive, never logged in, disabled with groups, external accounts without expiry, password never expires, expired, not required, too old. Blank, reused and breached passwords from an NT hash export you supply.
Out of support operating systems, LAPS coverage gaps, empty OUs, unlinked GPOs, identical membership clusters, human versus non human inventory, privileged accounts not in CyberArk, and local administrators on Windows and Unix hosts.
Every run produces an interactive HTML executive summary, a full XLSX, CSV files for downstream pipelines, and a PDF. Plus a privileged groups registry CSV for your auditor.
Connectors translate each directory into a common model. Scanners read the model. Reports read scanner output. Adding a check is a single file.
One download carries every module. The free trial unlocks offline Active Directory files. A licence unlocks the rest; which automation features a tier includes is listed on the marketplace.
35 AD scanners across Kerberos, delegation, ACLs, AD CS, passwords, lifecycle and inventory. Runs against a live domain over LDAPS or against an offline export or snapshot, with the same findings either way.
27 checks across identity, groups, licensing, conditional access, privileged access and app registrations, each tagged with CIS Microsoft 365 and Microsoft references. Read only, delegated sign in or an app registration.
31 read only controls over organization and folder IAM, custom roles, service accounts and keys, organization policies, Security Command Center, audit logging, project posture, billing and budgets.
Continuous Active Directory change monitoring. An LDAP poll plus domain controller security events give who created, deleted, enabled, disabled, changed or locked which account or group.
One dossier for a user, group or computer: identity facts, direct and transitive groups, how it is privileged, the ACLs it holds, its exposure flags and a blast radius with the reasoning written out.
Termination, transfer and onboarding for Active Directory, driven from a form, a single user id or a CSV batch. Every run is planned, previewed, executed and audited.
Search, review and create enterprise applications in Entra from one declarative profile. SAML or OIDC, previewed before any write, audited without secrets, reversible.
Discovery probes a directory and writes a seed configuration with the evidence for each guess. The local accounts scanner enumerates local administrators on Windows and Unix hosts without an agent.
Your DNA Technology account is the licence holder. You sign in from inside the app by confirming a short code in your browser. No key to paste.
A licence is sold per seat on the marketplace. Each device you sign in on takes one seat. Buy as many seats as you have machines.
Move a seat to a new device from inside the app: unlimited moves in the first 30 days, then 3 per rolling 30 days. Release any device from your account page.
Every feature of both modules, one trial per account, no card. When it ends the app returns to the sign in screen and nothing you produced is taken away.
Every static list of privileged groups I have used missed the custom delegation groups my team actually relied on. So I built one that walks up from confirmed admins instead.
CVSS was never built for identity. An old krbtgt password and one stale user account are not comparable. So the product scores exposure, impact, likelihood and blast radius on its own scale.
Download the demo, load an export of your directory, and read the report on your own machine. Nothing leaves it. Buy seats when you want live connections, assessments and automation.