Active Directory Security Assessment

See your Active Directory
the way attackers do.

Most Active Directory security assessment tools hand you a list of findings, then leave the real work to you. Insight Recon is different: it shows how each weakness gets exploited, what to fix first, and the exact commands to fix it. Because it runs read-only from a single Windows machine, there's no production impact.

Read-only scan No production impact Prioritized, not noisy
app.insightrecon.com / report / company-2026-05
Insight Recon
SECURITY ASSESSMENT
DOMAIN company.local
GENERATED May 4, 2026
Active Directory Security Assessment
Defensible identity
security decisions.
Where your risk is, which controls are weak, and what to remediate first.
42OF 100
F · Critical Risk
Higher score means a stronger AD posture.
Critical
6Immediate
High
17Priority
Moderate
15Hardening
Low
9Hygiene
Top PrioritiesRanked by exploitability
CritAccounts with no password requirement1 account
CritUnrestricted cert template modification (ESC4)1 template
HighStale krbtgt account password394 days
HighGuest account enabled1 account
Built by The team behind Breach Point Offensive security practitioners 135+ AD checks Mapped to MITRE ATT&CK, NIST, CIS, and STIG

How it works

Point, click, scan.
No console. No scripts.

A Windows app runs the Active Directory security assessment read-only against a domain controller, on demand or on a schedule, then publishes the report to your portal. 135+ checks, the full ESC1–16 ADCS family, tuned to signal, not noise.

STEP 01

Scan

  • Run read-only against a DC
  • Enumerate users, groups, computers
  • Read ACLs, GPO, ADCS, and trusts
  • Nothing deployed to your DCs or endpoints
STEP 02

Understand

  • Hacker Insight on every finding
  • The technique and the tooling
  • Where the weakness leads
  • Affected objects listed, not counted
STEP 03

Prioritize

  • Ranked by exploitability
  • Quick Wins by effort vs. risk
  • New, modified, and remediated tracked
  • Signal, not noise
STEP 04

Remediate

  • PowerShell-level fix steps
  • MITRE and compliance mapped
  • Mark findings remediated
  • Posture score trends over time
Insight Recon · Active Directory Scanner
Scanning company.local
Analyzing access control and delegation rights
55%
Connecting to domain controllerdone
Enumerating users, groups, computers74 users
Analyzing ACLs and delegationworking
Reviewing certificate templates (ADCS)pending
Evaluating Group Policy objectspending
Compiling findings and risk scorepending
Read-only. We only look. Nothing on your network is changed.
Desktop GUI — point, click, scan
Windows PowerShell
PS C:\> insightrecon adcheck --domain company.local ================================================ Insight Recon · Active Directory Assessment v2.4.1 · Breach Point, Inc. ================================================ [preflight] DNS resolution ......... ok [preflight] LDAP connectivity ...... ok [preflight] SYSVOL read ............ ok Ready to scan. All checks passed. Running 135+ AD checks against company.local … Identity & accounts 74 users, 18 computers Certificate services ESC1–16 Group Policy 47 GPOs Scan complete in 3m 12s. CRITICAL 6 HIGH 17 MOD 15 LOW 9 Report uploaded → view it in your Insight Recon portal.
CLI — scriptable, automation-ready

Coverage

An Active Directory security assessment
that covers your whole domain.

135+ checks, from identity hygiene to the full ADCS certificate-template family, grouped the way your remediation work actually breaks down.

Identity & Accounts

Empty passwords, stale admins, password-not-required, Kerberoastable and AS-REP-roastable accounts.

Privileged Access

Over-permissioned groups, DCSync rights, and dangerous ACLs over privileged objects.

Certificate Services

The full ESC1–16 family of certificate template and CA misconfigurations.

Kerberos & Delegation

Unconstrained and constrained delegation, krbtgt password age, ticket abuse.

Group Policy

Risky GPO settings, SYSVOL scripts, and weak domain password policy.

Domain & Trusts

Trust configuration, SID filtering, and domain controller redundancy.

Public Key Infrastructure

Enrollment rights, trusted roots, and weak certificate mappings.

Configuration & Hygiene

SMBv1, Print Spooler on DCs, LAPS coverage, and legacy protocols.

Inside the report

Every finding tells
the full story.

A severity badge and a name is where other tools stop. Instead, each finding includes attacker context, affected objects, compliance mappings, and step-by-step remediation, specific to your environment.

Attacker context, not just a description

Every finding explains how a real attacker weaponizes it: the specific tooling, the technique, and where it leads.

Remediation you can run

Not "update your policy." Exact PowerShell and ADUC steps for the specific finding and your domain, with an effort rating.

Compliance and affected objects

Mapped to MITRE, NIST, CIS, and STIG, with the specific users, groups, and computers affected — not just counts.

Accounts with No Password Requirement
Critical

Password requirement settings are not enforced on the reported accounts. While GPOs may override this setting, there are scenarios where they do not — for example, an empty password set before the policy was applied. Best practice is to enforce it on the account as well as the GPO.

Severity
Critical
Effort
Easy
Affected
1 account
First Seen
Apr 20, 2026
Hacker Insight
Password spraying via SMB with tools like CrackMapExec are commonly used to identify an account with an empty password. Accounts with empty passwords allow a malicious attacker an authenticated position in the network, provide lateral movement, and possibly privilege escalation. Many threat actors will save these accounts for later use to maintain persistence in the environment.
Recommendation
Enable the password requirement for all accounts unless there is a documented business justification. Follow least privilege and review account configurations regularly.
PowerShell · remediateCopy
Set-ADUser -Identity "Username" -Clear userAccountControl
Compliance Mapping
MITRE T1078NIST PR.AC-1CIS Control 5STIG V-243474

Trends

Prove you're actually getting better.

Most scanners hand you a snapshot and forget the last one. Insight Recon instead remembers every scan, so you can watch your score climb, catch anything new, and show leadership or a client that findings really did get fixed.

Why it's different

You've seen what other
tools produce. Here's ours.

Same environment, very different output. If you've run an Active Directory security assessment before, you'll recognize the difference right away.

Other AD Scanners
Typical output
Rule codes and numeric scores with no context on what they mean
No explanation of how an attacker would actually use a finding
Generic remediation advice your team still has to translate
A flat list, so you guess what to fix first
No way to see whether posture is getting better or worse
Insight Recon
What we do differently
Coverage across identities, ACLs, certificate services, trusts, and Group Policy
Attacker context on every finding: the technique, the tooling, where it leads
PowerShell and ADUC fix steps written for your environment
Ranked by exploitability, with a Quick Wins list for the fastest risk cuts
A posture score that trends across scans so you can prove improvement
Founder pricing · first 25 customers
$3,000$1,500/ year
Start on the free tier. Founding customers lock in this rate for good, with remediation assistance available as an add-on.

Get started

Fix your Active Directory
before attackers find the way in.

Run a free Active Directory security assessment in minutes. Then get a prioritized report with real attacker context, PowerShell-ready remediation, and a plan your team can actually execute.