IAM vulnerability discovery and automation · A DNA Technology product

See every weakness in your identity stack.

IAM X-ray scans Active Directory, Entra ID and Google Cloud identity, tells you in plain language where an attacker would go next, and then does the account work that follows: terminations, transfers, onboarding and Entra SSO applications. It runs on your machine. Your directory data never leaves it.

37Active Directory, Entra and host scanners
27Entra assessment checks
31GCP assessment controls
illustration · loops every 9s
Designed against the realities of
The Problem

You already know your directory has problems.
You just cannot prove it on a dashboard.

Generic scanners miss identity.

Vulnerability scanners flag CVEs on hosts. They do not see Kerberoastable accounts, AdminSDHolder drift, or the one Tier 1 user who reaches Domain Admins through two layers of nested groups.

Built-in tools are static.

PowerShell scripts and portal blades are point in time. They do not follow privilege chains, they do not know your custom delegation groups, and they do not write an executive summary.

BloodHound is a forensic tool.

BloodHound is excellent for incident response. It is not a recurring audit your CISO can read on a Monday, and it does not close the account afterwards. IAM X-ray sits in that gap.

How it works

Three steps. Live or offline.

One pipeline runs against a live Active Directory, a live Entra tenant, an offline export or a portable snapshot. Same engine, same risk model, same reports.

01

Connect

Bind read only over LDAPS, connect to Entra through Microsoft Graph, or point at an offline export or a .iamx snapshot. Credentials live in the OS keystore or an environment variable, never in the config file.

corp.acme.local
IAM X-ray
02

Discover

Build your privileged group registry from confirmed administrators. No fixed Domain Admins list: the scanners find your custom delegation groups and everyone who reaches them through nesting.

03

Report

Risk scored findings, evidence rows, a plain language glossary. Interactive HTML, full XLSX, CSV and PDF, plus the privileged groups CSV your auditor will read.

5
11
9
3
CriticalHighMediumLow
What it finds

37 scanners. One risk model.

Every scanner produces a structured finding with a 0 to 100 risk score, the evidence rows behind it, a plain language glossary entry and a remediation. Adding a check is one new file.

Tier 0

Kerberos and delegation

Kerberoastable and AS-REP roastable accounts, unconstrained and resource based constrained delegation, krbtgt password age, shadow credentials.

Tier 0

ACL surface

Direct user delegation on OUs, AdminSDHolder drift, DCSync rights on principals that are not domain controllers, write paths into sensitive groups.

Tier 0

AD CS

ESC1, ESC2, ESC3 and ESC8 on enrollable certificate templates and web enrollment endpoints.

Privilege model

Discovered privileged groups

Walks up from confirmed administrators to find your real privileged group surface, including the custom delegation groups a fixed list never sees. Then reports who is privileged, how, and which standard accounts got there through nesting.

Passwords and lifecycle

Account hygiene

Inactive, never logged in, disabled with groups, external accounts without expiry, password never expires, expired, not required, too old. Blank, reused and breached passwords from an NT hash export you supply.

Inventory and hosts

Structure, endpoints, local accounts

Out of support operating systems, LAPS coverage gaps, empty OUs, unlinked GPOs, identical membership clusters, human versus non human inventory, privileged accounts not in CyberArk, and local administrators on Windows and Unix hosts.

The deliverable

Reports your CISO will actually read.

Every run produces an interactive HTML executive summary, a full XLSX, CSV files for downstream pipelines, and a PDF. Plus a privileged groups registry CSV for your auditor.

  • Plain language glossary on every finding type. Share it with stakeholders without a decoder ring.
  • Filter by severity, scanner, search across evidence. Print-ready.
  • Risk score 0 to 100 from an IAM model that weighs exposure, impact, likelihood and blast radius.
  • Standalone HTML: no external CDN calls, no telemetry, works air gapped.
IAM X-ray: Executive Summary
corp.acme.local · 28 findings · Generated 2026-04-28
Critical5
High11
Medium9
Low3
CRITICAL
DCSync rights granted to non-DC principal
ad.dcsync_rights · risk score 92 · 1 affected
CRITICAL
Unconstrained delegation on svc.legacy
ad.unconstrained_delegation · risk score 88 · 1 affected
CRITICAL
AD CS template ESC1: enrollee supplies subject
ad.adcs_esc1 · risk score 87 · 2 templates
HIGH
Standard accounts with privileged access
ad.standard_accounts_with_privileged_access · risk score 76 · 7 accounts
Architecture

Modular by design.

Connectors translate each directory into a common model. Scanners read the model. Reports read scanner output. Adding a check is a single file.

Connectors
AD live (LDAPS)AD offline (snapshot)Snapshot (.iamx)Entra ID (Graph)Okta · not yet
Common Model
UserGroupComputerOUGPOCert templateACE
Scanners (37)
Account hygienePassword policyKerberosDelegationACL driftAD CSInventoryLocal accounts
Reports
HTML execXLSXCSVPDFPrivileged groups CSVTrend report
Modules

What ships today.

One download carries every module. The free trial unlocks offline Active Directory files. A licence unlocks the rest; which automation features a tier includes is listed on the marketplace.

Trial and licensed

Active Directory vulnerability discovery

35 AD scanners across Kerberos, delegation, ACLs, AD CS, passwords, lifecycle and inventory. Runs against a live domain over LDAPS or against an offline export or snapshot, with the same findings either way.

  • Discovered privileged group registry, not a fixed list
  • Executive HTML, full XLSX, CSV and PDF reports
  • Run history and trend report across runs
  • Portable .iamx snapshot file for archiving and diffing
Licensed

Entra assessment

27 checks across identity, groups, licensing, conditional access, privileged access and app registrations, each tagged with CIS Microsoft 365 and Microsoft references. Read only, delegated sign in or an app registration.

  • 0 to 100 score, heat map and prioritised gaps
  • Per policy Conditional Access review
  • Directory and licence analysis with reclaimable licences
  • Run over run tracking and an executive PDF
Licensed

GCP assessment

31 read only controls over organization and folder IAM, custom roles, service accounts and keys, organization policies, Security Command Center, audit logging, project posture, billing and budgets.

  • Application Default Credentials or a scoped service account
  • Missing permissions show as not assessed, never as a pass
  • Score, findings, run history and trend
Licensed

Live Feed

Continuous Active Directory change monitoring. An LDAP poll plus domain controller security events give who created, deleted, enabled, disabled, changed or locked which account or group.

  • New objects checked against your mandatory attribute rules
  • Daily, weekly, monthly and yearly statistics
  • Runs as a scheduled task on the collector host
Trial (offline) and licensed

Investigation

One dossier for a user, group or computer: identity facts, direct and transitive groups, how it is privileged, the ACLs it holds, its exposure flags and a blast radius with the reasoning written out.

  • Works offline from a snapshot or live
  • Every fact reproducible from the data
Automation module

Automation

Termination, transfer and onboarding for Active Directory, driven from a form, a single user id or a CSV batch. Every run is planned, previewed, executed and audited.

  • Termination: disable, move OU, strip groups, set description, reset password, manager and failure emails, Entra MFA reset, sign in block and session revoke
  • Transfer: attribute changes with manager verification
  • Onboarding: account and group creation
  • Unattended folder watcher for scheduled runs
Automation module

Entra SSO applications

Search, review and create enterprise applications in Entra from one declarative profile. SAML or OIDC, previewed before any write, audited without secrets, reversible.

  • Claims, group claims and app roles with user and group assignments
  • SCIM provisioning
  • Certificates and client secrets with expiry dates, issue a new secret shown once
  • Graph API permissions found by search, with admin consent
  • Review of any existing app: owners, URLs, credentials, assignments, requested versus granted permissions
Trial (offline) and licensed

Environment discovery and local accounts

Discovery probes a directory and writes a seed configuration with the evidence for each guess. The local accounts scanner enumerates local administrators on Windows and Unix hosts without an agent.

  • Domain, OU layout, privileged OU and naming pattern candidates
  • Windows local Administrators, Unix root and sudo groups
  • Discovery runs on offline files in the trial; the local accounts scan reaches live hosts and needs a licence
Not yet shipping: the Okta connector is wired for authentication but collects no data yet. Ping is not started. We say so here so you do not buy for it.
Licensing

Per seat. Signed in, not keyed in.

One account

Your DNA Technology account is the licence holder. You sign in from inside the app by confirming a short code in your browser. No key to paste.

One seat, one device

A licence is sold per seat on the marketplace. Each device you sign in on takes one seat. Buy as many seats as you have machines.

Move or release

Move a seat to a new device from inside the app: unlimited moves in the first 30 days, then 3 per rolling 30 days. Release any device from your account page.

15 day trial

Every feature of both modules, one trial per account, no card. When it ends the app returns to the sign in screen and nothing you produced is taken away.

Built by people who've fixed it

From the IAM engineer's perspective.

"

Every static list of privileged groups I have used missed the custom delegation groups my team actually relied on. So I built one that walks up from confirmed admins instead.

Paulo ValadaresDNA Technology · IAM engineering
"

CVSS was never built for identity. An old krbtgt password and one stale user account are not comparable. So the product scores exposure, impact, likelihood and blast radius on its own scale.

Engineering principleFrom the design doc

See what is hiding in your Active Directory.

Download the demo, load an export of your directory, and read the report on your own machine. Nothing leaves it. Buy seats when you want live connections, assessments and automation.