Features

Every check, in one place.

37 scanners shipping today. Risk scored evidence, a plain language glossary, and a remediation on every finding. The same findings whether the data came from a live directory or an offline file.

Scanner
Area
Tier
What it finds
ad.kerberoastable
Kerberos
tier-0
User accounts with SPNs registered. Tickets crackable offline.
ad.as_rep_roastable
Kerberos
tier-0
Pre authentication not required. Crackable without a foothold.
ad.krbtgt_password_age
Kerberos
tier-0
krbtgt password age against your threshold.
ad.unconstrained_delegation
Delegation
tier-0
Accounts that can impersonate anyone who authenticates to them.
ad.resource_based_constrained_delegation
Delegation
tier-0
msDS-AllowedToActOnBehalfOfOtherIdentity audit.
ad.shadow_credentials
PKINIT
tier-0
msDS-KeyCredentialLink populated, privileged accounts first.
ad.adminsdholder_acl_drift
ACL
tier-0
Non default ACEs on AdminSDHolder.
ad.dcsync_rights
ACL
tier-0
Replication rights on principals that are not domain controllers.
ad.sensitive_group_acl_write
ACL
tier-0
Write rights on privileged groups held by non privileged users.
ad.ou_permissions_direct_user
ACL
tier-1
Delegation on OUs granted to users directly instead of groups.
ad.adcs_esc1
AD CS
tier-0
Enrollee supplies subject plus client authentication on an enrollable template.
ad.adcs_esc2
AD CS
tier-0
Any Purpose EKU on an enrollable template.
ad.adcs_esc3
AD CS
tier-0
Certificate Request Agent template enrollable by low privilege users.
ad.adcs_esc8
AD CS
tier-0
Certificate authorities exposing HTTP web enrollment (NTLM relay).
ad.privileged_groups_discovery
Privilege
foundation
Discovered privileged group registry (CSV output).
ad.privileged_entitlement
Privilege
inventory
Who is privileged and how: designated or indirect.
ad.standard_accounts_with_privileged_access
Privilege
tier-1
Non designated accounts with privileged access through groups.
ad.privileged_accounts_not_in_cyberark
Privilege
tier-1
Privileged accounts not onboarded to CyberArk.
ad.compromised_passwords
Password
tier-0
Blank, reused and breached passwords from an NT hash export you supply. Breach lookup is opt in.
ad.password_never_expires
Password
tier-2
Password never expires flag set.
ad.password_age
Password
tier-2
pwdLastSet older than your policy allows.
ad.password_expired
Password
tier-2
Password expired on an enabled account.
ad.password_not_required
Password
tier-1
Password not required flag set. An empty password is possible.
ad.inactive_accounts
Lifecycle
tier-2
Enabled accounts past the inactivity threshold.
ad.never_logged_in
Lifecycle
tier-2
Created but never authenticated.
ad.disabled_accounts_with_groups
Lifecycle
tier-2
Disabled accounts that kept their group memberships.
ad.external_users_without_expiry
Lifecycle
tier-1
External accounts with no expiry date.
ad.missing_mandatory_user_attributes
Data hygiene
hygiene
Enabled users missing the attributes your standard says are mandatory.
ad.missing_mandatory_group_attributes
Data hygiene
hygiene
Groups missing mandatory attributes such as description or manager.
ad.os_out_of_support
Endpoint
tier-1
Domain joined hosts on operating systems out of support.
ad.laps_coverage_gap
Endpoint
tier-1
Workstations and servers without LAPS.
ad.empty_ous
Inventory
hygiene
OUs with no children. They often keep stale ACLs.
ad.gpos_not_linked
Inventory
hygiene
GPOs not linked anywhere.
ad.identical_group_memberships
RBAC
hygiene
Same group set, different titles or departments.
ad.human_vs_nonhuman_inventory
Inventory
inventory
Privileged, external, service and standard account counts.
entra.mfa_gap_for_privileged
Entra
tier-0
Privileged Entra accounts without enforced MFA.
host.local_accounts
Hosts
tier-1
Local administrators on Windows and Unix hosts, agentless. Off until you configure credentials.

Tier here is the attack relevance the scanner carries in its findings, not a licence tier.

Beyond the scanners

Entra assessment

27 checks

Identity, groups, licensing, conditional access, privileged access and app registrations. Score out of 100, heat map, per policy Conditional Access review, directory and licence analysis, executive PDF, run over run diff. Read only, delegated device code sign in or an app registration.

GCP assessment

31 controls

Organization and folder IAM, primitive roles, external principals, custom roles, service accounts and keys, organization policies, Security Command Center, audit logging, project posture, billing, budgets and Recommender. A missing permission is reported as not assessed, never as a pass.

Live Feed

Continuous

Account and group creations, deletions, enables, disables, password changes, attribute and membership changes and lockouts from an LDAP poll plus domain controller security events. New objects are checked against your mandatory attribute rules.

Investigation

One subject

A dossier for any user, group or computer: direct and transitive groups, how it is privileged, the ACLs it holds, exposure flags and a blast radius with the reasoning written out. Works offline from a snapshot.

Snapshots, trends and reports

Portable .iamx snapshot

Collect a directory once into a single SQLite file, then scan, investigate or compare it anywhere, including a machine with no network path to the domain.

Trends across runs

Every completed run is added to a history. The progression report shows the trend and the accounts added or removed since the last run.

Four report formats

Interactive HTML executive summary with severity, scanner and search filters, full XLSX, CSV evidence, PDF, and the privileged groups registry CSV.

Architecture

Modular by design.

Connectors translate each directory into a common model. Scanners read the model. Reports read scanner output. Adding a check is a single file.

Connectors
AD live (LDAPS)AD offline (snapshot)Snapshot (.iamx)Entra ID (Graph)Okta · not yet
Common Model
UserGroupComputerOUGPOCert templateACE
Scanners (37)
Account hygienePassword policyKerberosDelegationACL driftAD CSInventoryLocal accounts
Reports
HTML execXLSXCSVPDFPrivileged groups CSVTrend report

See what is hiding in your Active Directory.

Download the demo, load an export of your directory, and read the report on your own machine. Nothing leaves it. Buy seats when you want live connections, assessments and automation.