Skip to content
Active Directory

AD Health Check

Audits the security health of your Active Directory environment and shrinks the identity attack surface.

194
control rules
7
scoring categories
0–100
health score
LDAP/SMB
remote audit protocol
Why it matters

Most ransomware attacks originate from Active Directory and spread through it.

Modern cyber attacks follow this path: a system is compromised, the attacker enters AD and spreads from there across the network. Antivirus or EDR may catch running malware but the attacker is already inside — they use privilege delegation, forgotten admin accounts, weak Kerberos settings and certificate service flaws to amplify their reach. The problem is blindness: you have hundreds of accounts, groups and policies and nobody continuously measures their consistency and risk.

  • How many people are truly in Domain Admin, which groups have nested structures?
  • Which attack method does your password policy, certificate service setup or GPO configuration expose?
  • Are dormant admin accounts, stale objects and abnormal changes automatically detected?
What it does

What it does.

Privileged account analysis

Shows actual membership in Domain Admins and similar groups. Uncovers nested group structures — often the admin doesn't even know who truly has admin rights.

Password and identity policy audit

Password age, reset frequency, history and complexity settings are checked. Weak policy accelerates an attacker's password cracking — risk is scored.

Certificate service and ESC vulnerabilities

Active Directory Certificate Services are examined: templates, enrollment privileges, key strength, Kerberos certificate abuse (ESC3 etc) are flagged.

Kerberos hardening and protocol

DES encryption, pre-auth bypass, protocol transition, ARMOR support are checked. Abnormal Kerberos activity is automatically flagged.

Trust relationship audit

Domain-to-domain, forest and external trusts are examined: one-way or two-way, encryption level, legacy compatibility risk.

Stale object and anomaly detection

Unused accounts (90+ days), old computers, schema changes and unexpected group changes are automatically flagged. Hourly critical audit sends alerts on change.

Category-based health score

Report shows 7 categories (privilege, trust, stale objects, anomaly, hardening etc). Each category scored 0–100; the weakest emerges first — tells you where to invest.

Audit scope report

Every scan reports which rule families were fully, partially or unable to audit. Does not assume no problems in 'unable to audit' areas — clearly states risk may be missed.

How it works

From setup to report.

  1. 01

    Add domain controller connection

    Provide a domain controller address, access account (LDAP identity) and password. The account needs at least directory read permissions.

  2. 02

    Define audit scope

    Enter the domains to audit, scan frequency (daily full, hourly critical) and optional scope notes (exempt areas).

  3. 03

    Rule engine runs

    All 194 rules execute via LDAP, SMB and registry queries. Every finding carries MITRE ATT&CK, ANSSI maturity level and CIS control mapping.

  4. 04

    Category scoring

    Findings distributed across 7 categories, each scored 0–100. Overall health score calculated from the highest-risk category (maximum risk model).

  5. 05

    Report and alerting

    Findings ordered from critical to acceptable. PDF shows category distribution and closed findings. Hourly critical rules email alerts on change.

Technical details

The specifics.

Total rules
194 rules — 13 families (privilege, trust, stale, anomaly, hardening, controller, attack surface)
Audit protocols
LDAP (directory read), SMB (shares/passwords), registry (system settings) — read-only
Framework mappings
MITRE ATT&CK (32 techniques), ANSSI controls (13 maturity levels), CIS Controls (60+ controls)
Health score
0–100 (100 best), segmented by category, letter grade (A–F), trend tracking
Scan rhythm
Daily full scan + hourly critical audit (instant alert on new exposure)
Reporting
PDF (ISO 27001-aligned), HTML panel, category distribution, dated evidence (180-day retention)
Audit scope
Fully audited / Partially audited / Unable to audit (reported)
Scalability
Tested on 50,000+ object domains (Ø 974 ms, 188 MB)
FAQ

Frequently asked questions.

Does it modify AD or change data?

No. The product is read-only — no objects are created, modified or deleted. It only reads the directory and reports status. No impact on users, groups, policies or any other object. This is a written guarantee.

What's the difference from PingCastle and Purple Knight?

We cover 88% of PingCastle's rules. Our differences: (1) we explicitly report audit scope, don't call unmeasurable areas 'safe'; (2) category-based health score reflects the weakest area, not the sum; (3) hourly critical audit alerts on change — not a monthly report.

Isn't 194 rules a small number — don't other products claim 200+?

Finding count is not a sales metric. Our 194 rules are measurable and verified; each maps to MITRE, ANSSI and CIS. A product that claims 'hundreds of findings' often silently skips areas it cannot audit. We write 'unable to audit' — so risk is not missed.

AD Health Check starts today.

Create a free account and run your first scan within minutes.