What problem does it solve?
Audits and strengthens Active Directory identity configuration, privilege delegation, and authentication controls to reduce risk from misconfigurations and attacker methods.
Core Features & Use Cases
- AD Security Posture Assessment: review privileged groups (Domain Admins, Enterprise Admins, Schema Admins), tiering models, and delegation boundaries; detect orphaned permissions, ACL drift, and excessive rights.
- Authentication & Protocol Hardening: enforce Kerberos hardening, LDAP signing, and mitigate NTLM fallback; evaluate legacy trusts and conditional access adoption.
- GPO & Sysvol Security Review: validate restricted groups, local admin enforcement, and SYSVOL permissions; ensure proper delegation and policy enforcement.
- Attack Surface Reduction: identify exposure to DCShadow, DCSync, Kerberoasting; locate stale SPNs and weak service accounts; provide prioritized remediation.
Quick Start
Audit the Active Directory identity configuration, privilege delegation, and authentication policies and return a prioritized hardening plan.