AD Health Check
Audits the security health of your Active Directory environment and shrinks the identity attack surface.
- 194
- control rules
- 7
- scoring categories
- 0–100
- health score
- LDAP/SMB
- remote audit protocol
Most ransomware attacks originate from Active Directory and spread through it.
Modern cyber attacks follow this path: a system is compromised, the attacker enters AD and spreads from there across the network. Antivirus or EDR may catch running malware but the attacker is already inside — they use privilege delegation, forgotten admin accounts, weak Kerberos settings and certificate service flaws to amplify their reach. The problem is blindness: you have hundreds of accounts, groups and policies and nobody continuously measures their consistency and risk.
- How many people are truly in Domain Admin, which groups have nested structures?
- Which attack method does your password policy, certificate service setup or GPO configuration expose?
- Are dormant admin accounts, stale objects and abnormal changes automatically detected?
What it does.
Privileged account analysis
Shows actual membership in Domain Admins and similar groups. Uncovers nested group structures — often the admin doesn't even know who truly has admin rights.
Password and identity policy audit
Password age, reset frequency, history and complexity settings are checked. Weak policy accelerates an attacker's password cracking — risk is scored.
Certificate service and ESC vulnerabilities
Active Directory Certificate Services are examined: templates, enrollment privileges, key strength, Kerberos certificate abuse (ESC3 etc) are flagged.
Kerberos hardening and protocol
DES encryption, pre-auth bypass, protocol transition, ARMOR support are checked. Abnormal Kerberos activity is automatically flagged.
Trust relationship audit
Domain-to-domain, forest and external trusts are examined: one-way or two-way, encryption level, legacy compatibility risk.
Stale object and anomaly detection
Unused accounts (90+ days), old computers, schema changes and unexpected group changes are automatically flagged. Hourly critical audit sends alerts on change.
Category-based health score
Report shows 7 categories (privilege, trust, stale objects, anomaly, hardening etc). Each category scored 0–100; the weakest emerges first — tells you where to invest.
Audit scope report
Every scan reports which rule families were fully, partially or unable to audit. Does not assume no problems in 'unable to audit' areas — clearly states risk may be missed.
From setup to report.
- 01
Add domain controller connection
Provide a domain controller address, access account (LDAP identity) and password. The account needs at least directory read permissions.
- 02
Define audit scope
Enter the domains to audit, scan frequency (daily full, hourly critical) and optional scope notes (exempt areas).
- 03
Rule engine runs
All 194 rules execute via LDAP, SMB and registry queries. Every finding carries MITRE ATT&CK, ANSSI maturity level and CIS control mapping.
- 04
Category scoring
Findings distributed across 7 categories, each scored 0–100. Overall health score calculated from the highest-risk category (maximum risk model).
- 05
Report and alerting
Findings ordered from critical to acceptable. PDF shows category distribution and closed findings. Hourly critical rules email alerts on change.
The specifics.
- Total rules
- 194 rules — 13 families (privilege, trust, stale, anomaly, hardening, controller, attack surface)
- Audit protocols
- LDAP (directory read), SMB (shares/passwords), registry (system settings) — read-only
- Framework mappings
- MITRE ATT&CK (32 techniques), ANSSI controls (13 maturity levels), CIS Controls (60+ controls)
- Health score
- 0–100 (100 best), segmented by category, letter grade (A–F), trend tracking
- Scan rhythm
- Daily full scan + hourly critical audit (instant alert on new exposure)
- Reporting
- PDF (ISO 27001-aligned), HTML panel, category distribution, dated evidence (180-day retention)
- Audit scope
- Fully audited / Partially audited / Unable to audit (reported)
- Scalability
- Tested on 50,000+ object domains (Ø 974 ms, 188 MB)
Frequently asked questions.
Does it modify AD or change data?
No. The product is read-only — no objects are created, modified or deleted. It only reads the directory and reports status. No impact on users, groups, policies or any other object. This is a written guarantee.
What's the difference from PingCastle and Purple Knight?
We cover 88% of PingCastle's rules. Our differences: (1) we explicitly report audit scope, don't call unmeasurable areas 'safe'; (2) category-based health score reflects the weakest area, not the sum; (3) hourly critical audit alerts on change — not a monthly report.
Isn't 194 rules a small number — don't other products claim 200+?
Finding count is not a sales metric. Our 194 rules are measurable and verified; each maps to MITRE, ANSSI and CIS. A product that claims 'hundreds of findings' often silently skips areas it cannot audit. We write 'unable to audit' — so risk is not missed.
Other CyCastle services.
AD Health Check starts today.
Create a free account and run your first scan within minutes.