Features

Every check, in one place.

32 scanners shipping today. Risk-scored evidence, plain-language glossary, prioritized remediation.

Scanner
Area
Tier
What it finds
ad.kerberoastable
Kerberos
tier-0
User accounts with SPNs registered. Tickets crackable offline.
ad.as_rep_roastable
Kerberos
tier-0
UAC DONT_REQ_PREAUTH set — crack without a foothold.
ad.unconstrained_delegation
Delegation
tier-0
Accounts that can impersonate anyone who authenticates to them.
ad.resource_based_constrained_delegation
Delegation
tier-0
msDS-AllowedToActOnBehalfOfOtherIdentity audit.
ad.shadow_credentials
PKINIT
tier-0
msDS-KeyCredentialLink populated, with priv emphasis.
ad.krbtgt_password_age
Kerberos
tier-0
krbtgt rotation age vs configurable threshold.
ad.adminsdholder_acl_drift
ACL
tier-0
Non-default ACEs on AdminSDHolder.
ad.dcsync_rights
ACL
tier-0
DS-Replication-Get-Changes-* on non-DC principals.
ad.sensitive_group_acl_write
ACL
tier-0
Non-priv user-direct write rights on priv groups.
ad.ou_permissions_direct_user
ACL
tier-1
Direct-user delegation on OUs (vs group-based).
ad.adcs_esc1
AD CS
tier-0
Enrollee-supplies-subject + client auth on enrollable template.
ad.adcs_esc2
AD CS
tier-0
Any Purpose EKU on enrollable template.
ad.adcs_esc3
AD CS
tier-0
Certificate Request Agent template enrollable by low-priv.
ad.adcs_esc8
AD CS
tier-0
CAs exposing HTTP web enrollment (NTLM relay).
ad.privileged_groups_discovery
Privilege
foundation
Reverse-engineered priv-group registry (CSV output).
ad.privileged_entitlement
Privilege
inventory
Who is privileged and how (designated vs indirect).
ad.standard_accounts_with_privileged_access
Privilege
tier-1
Non-designated accounts with priv access via groups.
ad.password_never_expires
Password
tier-2
UAC DONT_EXPIRE_PASSWORD set.
ad.password_age
Password
tier-2
pwdLastSet exceeds configured policy.
ad.password_expired
Password
tier-2
UAC PASSWORD_EXPIRED set on enabled account.
ad.password_not_required
Password
tier-1
UAC PASSWD_NOTREQD set — empty password possible.
ad.inactive_accounts
Lifecycle
tier-2
Enabled accounts past inactivity threshold.
ad.never_logged_in
Lifecycle
tier-2
Created but never authenticated.
ad.disabled_accounts_with_groups
Lifecycle
tier-2
Disabled accounts retaining group memberships.
ad.external_users_without_expiry
Lifecycle
tier-1
External-named accounts without account_expires.
ad.os_out_of_support
Endpoint
tier-1
Domain-joined hosts on EOL operating systems.
ad.laps_coverage_gap
Endpoint
tier-1
Workstations/servers without LAPS enrollment.
ad.empty_ous
Inventory
hygiene
OUs with no children — frequently retain stale ACLs.
ad.gpos_not_linked
Inventory
hygiene
GPOs not linked to any object.
ad.identical_group_memberships
RBAC
hygiene
Same memberOf set, different titles/departments.
ad.human_vs_nonhuman_inventory
Inventory
inventory
Privileged / external / service / standard counts.
entra.mfa_gap_for_privileged
Entra
tier-0
Privileged Entra accounts without enforced MFA.
Architecture

Modular by design. Pluggable forever.

Connectors translate each IDP into a common model. Scanners read the model. Reports read scanner output. Adding a check is a single file.

Connectors
AD live (LDAPS) AD offline (snapshot) Entra ID Okta · soon Ping · soon
Common Model
User Group Computer OU GPO Cert template ACE
Scanners (32)
Account hygiene Password policy Kerberos Delegation ACL drift AD CS Inventory
Reports
HTML exec XLSX CSV PDF Priv-group registry

Ready to see what's hiding in your AD?

Spin it up against the synthetic snapshot in two minutes. Open the live HTML report. Decide if you want it pointed at your real environment.