Scanner
Area
Tier
What it finds
ad.kerberoastable
Kerberos
tier-0
User accounts with SPNs registered. Tickets crackable offline.
ad.as_rep_roastable
Kerberos
tier-0
UAC DONT_REQ_PREAUTH set — crack without a foothold.
ad.unconstrained_delegation
Delegation
tier-0
Accounts that can impersonate anyone who authenticates to them.
ad.resource_based_constrained_delegation
Delegation
tier-0
msDS-AllowedToActOnBehalfOfOtherIdentity audit.
ad.shadow_credentials
PKINIT
tier-0
msDS-KeyCredentialLink populated, with priv emphasis.
ad.krbtgt_password_age
Kerberos
tier-0
krbtgt rotation age vs configurable threshold.
ad.adminsdholder_acl_drift
ACL
tier-0
Non-default ACEs on AdminSDHolder.
ad.dcsync_rights
ACL
tier-0
DS-Replication-Get-Changes-* on non-DC principals.
ad.sensitive_group_acl_write
ACL
tier-0
Non-priv user-direct write rights on priv groups.
ad.ou_permissions_direct_user
ACL
tier-1
Direct-user delegation on OUs (vs group-based).
ad.adcs_esc1
AD CS
tier-0
Enrollee-supplies-subject + client auth on enrollable template.
ad.adcs_esc2
AD CS
tier-0
Any Purpose EKU on enrollable template.
ad.adcs_esc3
AD CS
tier-0
Certificate Request Agent template enrollable by low-priv.
ad.adcs_esc8
AD CS
tier-0
CAs exposing HTTP web enrollment (NTLM relay).
ad.privileged_groups_discovery
Privilege
foundation
Reverse-engineered priv-group registry (CSV output).
ad.privileged_entitlement
Privilege
inventory
Who is privileged and how (designated vs indirect).
ad.standard_accounts_with_privileged_access
Privilege
tier-1
Non-designated accounts with priv access via groups.
ad.password_never_expires
Password
tier-2
UAC DONT_EXPIRE_PASSWORD set.
ad.password_age
Password
tier-2
pwdLastSet exceeds configured policy.
ad.password_expired
Password
tier-2
UAC PASSWORD_EXPIRED set on enabled account.
ad.password_not_required
Password
tier-1
UAC PASSWD_NOTREQD set — empty password possible.
ad.inactive_accounts
Lifecycle
tier-2
Enabled accounts past inactivity threshold.
ad.never_logged_in
Lifecycle
tier-2
Created but never authenticated.
ad.disabled_accounts_with_groups
Lifecycle
tier-2
Disabled accounts retaining group memberships.
ad.external_users_without_expiry
Lifecycle
tier-1
External-named accounts without account_expires.
ad.os_out_of_support
Endpoint
tier-1
Domain-joined hosts on EOL operating systems.
ad.laps_coverage_gap
Endpoint
tier-1
Workstations/servers without LAPS enrollment.
ad.empty_ous
Inventory
hygiene
OUs with no children — frequently retain stale ACLs.
ad.gpos_not_linked
Inventory
hygiene
GPOs not linked to any object.
ad.identical_group_memberships
RBAC
hygiene
Same memberOf set, different titles/departments.
ad.human_vs_nonhuman_inventory
Inventory
inventory
Privileged / external / service / standard counts.
entra.mfa_gap_for_privileged
Entra
tier-0
Privileged Entra accounts without enforced MFA.