Home
Active Directory Security Assessment
See your Active Directory
the way attackers do.
Most Active Directory security assessment tools hand you a list of findings, then leave the real work to you. Insight Recon is different: it shows how each weakness gets exploited, what to fix first, and the exact commands to fix it. Because it runs read-only from a single Windows machine, there's no production impact.
security decisions.
How it works
Point, click, scan.
No console. No scripts.
A Windows app runs the Active Directory security assessment read-only against a domain controller, on demand or on a schedule, then publishes the report to your portal. 135+ checks, the full ESC1–16 ADCS family, tuned to signal, not noise.
Scan
- Run read-only against a DC
- Enumerate users, groups, computers
- Read ACLs, GPO, ADCS, and trusts
- Nothing deployed to your DCs or endpoints
Understand
- Hacker Insight on every finding
- The technique and the tooling
- Where the weakness leads
- Affected objects listed, not counted
Prioritize
- Ranked by exploitability
- Quick Wins by effort vs. risk
- New, modified, and remediated tracked
- Signal, not noise
Remediate
- PowerShell-level fix steps
- MITRE and compliance mapped
- Mark findings remediated
- Posture score trends over time
Coverage
An Active Directory security assessment
that covers your whole domain.
135+ checks, from identity hygiene to the full ADCS certificate-template family, grouped the way your remediation work actually breaks down.
Identity & Accounts
Empty passwords, stale admins, password-not-required, Kerberoastable and AS-REP-roastable accounts.
Privileged Access
Over-permissioned groups, DCSync rights, and dangerous ACLs over privileged objects.
Certificate Services
The full ESC1–16 family of certificate template and CA misconfigurations.
Kerberos & Delegation
Unconstrained and constrained delegation, krbtgt password age, ticket abuse.
Group Policy
Risky GPO settings, SYSVOL scripts, and weak domain password policy.
Domain & Trusts
Trust configuration, SID filtering, and domain controller redundancy.
Public Key Infrastructure
Enrollment rights, trusted roots, and weak certificate mappings.
Configuration & Hygiene
SMBv1, Print Spooler on DCs, LAPS coverage, and legacy protocols.
Inside the report
Every finding tells
the full story.
A severity badge and a name is where other tools stop. Instead, each finding includes attacker context, affected objects, compliance mappings, and step-by-step remediation, specific to your environment.
Every finding explains how a real attacker weaponizes it: the specific tooling, the technique, and where it leads.
Not "update your policy." Exact PowerShell and ADUC steps for the specific finding and your domain, with an effort rating.
Mapped to MITRE, NIST, CIS, and STIG, with the specific users, groups, and computers affected — not just counts.
Password requirement settings are not enforced on the reported accounts. While GPOs may override this setting, there are scenarios where they do not — for example, an empty password set before the policy was applied. Best practice is to enforce it on the account as well as the GPO.
Set-ADUser -Identity "Username" -Clear userAccountControl
Trends
Prove you're actually getting better.
Most scanners hand you a snapshot and forget the last one. Insight Recon instead remembers every scan, so you can watch your score climb, catch anything new, and show leadership or a client that findings really did get fixed.
Risk Posture Score over time
Longest-standing criticals
Most recently fixed
Why it's different
You've seen what other
tools produce. Here's ours.
Same environment, very different output. If you've run an Active Directory security assessment before, you'll recognize the difference right away.
Get started
Fix your Active Directory
before attackers find the way in.
Run a free Active Directory security assessment in minutes. Then get a prioritized report with real attacker context, PowerShell-ready remediation, and a plan your team can actually execute.