Remediation Assistance

Found the issues.
Now fix them.

Insight Recon surfaces your AD exposure. Our practitioners help you close it: walking your team through the fixes, or getting hands-on ourselves.

Prioritized by severity and effort Advisory or hands-on Breach Point practitioners
Subscriber Rate Discounts
No minimums
Enterprise
Enterprise plan subscribers
40% off
Auditor
Auditor plan subscribers
25% off
Standard
Standard plan subscribers
15% off
Free / No Plan
No active subscription
Base rate
Advisory or hands-on. Advisory guidance starts right away; hands-on implementation is delivered under a scoped statement of work. Billed hourly in 30-minute increments, and your exact rate is included in your quote.

Who this is for

Finding issues is the easy part.
Fixing them is where teams get stuck.

Remediation assistance is for anyone who has Insight Recon findings in front of them and needs help turning a report into a closed ticket.

01 / INTERNAL TEAMS

Security teams that need a second set of eyes

You have the findings, you have the access, but the remediation paths are complex or your team needs validation before making changes to production AD.

02 / CONSULTANTS

MSSPs and consultants delivering to clients

You ran the assessment, the report is ready, and now the client wants help with the actual fixes. We work alongside you or your client directly depending on how you want to structure it.

03 / ANYONE

Anyone who found something they can't close alone

You ran a free scan, saw the risk score, and know something needs to change, but the fixes involve PowerShell, GPOs, or ADCS configuration you haven't touched before.

How it works

From findings to fixed
in four steps.

We start with your Insight Recon report and work through findings in priority order. No generic checklists, no boilerplate guidance.

1

Share your report

We review your Insight Recon findings, risk score, and environment data before the first session.

2

Scope the work

We agree on what to address, in what order, and whether advisory or hands-on is the right approach for each item.

3

Work through findings

Session by session we close findings using specific commands, GPO paths, and ADUC steps for your exact environment.

4

Rescan and verify

Run Insight Recon again after remediation to confirm findings are closed and track posture score improvement.

What we cover

Every finding category
we remediate.

Our practitioners work across all the areas Insight Recon surfaces. All of them.

🔑

Authentication & Credentials

  • Removing PASSWD_NOTREQD flags and enforcing password requirements
  • Resetting and rotating the krbtgt account password safely
  • Disabling or removing stale, legacy, and unnecessary accounts
  • Enforcing password expiry and complexity policies via GPO
🏛️

Privileged Identity & Groups

  • Reducing Domain Admin and Enterprise Admin group membership
  • Cleaning up nested group structures and excessive privilege inheritance
  • Auditing and remediating dangerous ACL delegations
  • Implementing tiered administration and least-privilege models
📜

PKI & ADCS

  • Remediating ESC1 through ESC16 certificate template misconfigurations
  • Tightening certificate template enrollment rights and ACLs
  • Reviewing and hardening Certificate Authority configuration
  • Disabling dangerous enrollment agent permissions
⚙️

Configuration & Infrastructure

  • Enabling and configuring LAPS for local admin password management
  • Enabling AD Recycle Bin and verifying backup currency
  • Hardening Group Policy: SYSVOL, screensaver, firewall, WSUS
  • Kerberos armoring, SID filtering, and trust hardening

How we work

Advisory or hands-on.
Your call.

Some teams need guidance and validation. Others need someone to get in and do the work. We scope each engagement based on what you actually need.

Advisory
We guide. Your team executes. Best for teams that have the access and want expert validation before making changes.
Step-by-step guidance specific to your environment and findings
PowerShell commands and GPO paths reviewed before execution
Live working sessions via screen share
Documentation of what was changed and why
Post-remediation rescan walkthrough
Everything in Advisory
Direct implementation of approved remediation steps
Change documentation and rollback procedures
Coordination with your IT or infrastructure team
Formal remediation report on completion

Who you're working with

Built by hackers.
Delivered by practitioners.

Insight Recon was built by offensive security practitioners who have spent their careers finding these exact vulnerabilities in real environments. That background shapes how we approach remediation. We know how attackers look for these issues, how they test for them, and which fixes actually close the path versus which ones just move the problem.

Remediation assistance is delivered by the same team that built the product. Not a support desk. Not a junior analyst working from a checklist. Practitioners who have run these engagements across industries and know what a real fix looks like in production AD.

OSCP certified CISSP certified PCI QSA Red team experience Enterprise IAM depth
OFFENSIVE BACKGROUND

We know how attackers enumerate AD, which tools they use, and which findings are actually dangerous in combination versus which ones just look bad on paper. That context shapes every remediation recommendation we make.

ENTERPRISE IAM DEPTH

Our team brings hands-on experience with privileged identity management, AD architecture, and ADCS at enterprise scale. We understand how these environments are built and how to fix them without breaking things.

BUILT THE TOOL

The same people who designed Insight Recon's finding logic are the ones delivering remediation assistance. They know exactly what the scanner surfaces and why, and can walk through every finding at a level no third party can match.

Prioritized remediation

We work through findings
in the order that matters.

Not alphabetically. Not by finding ID. By attacker impact and remediation effort, so the most dangerous exposures close first.

Remediation Priority Queue: company.local
Ordered by attacker impact · effort rating shown per finding
Sample from real assessment
#1
Accounts with No Password Requirement
1 account affected · Auth & Authorization · Critical
Effort
#2
Unrestricted certificate template modification (ESC4)
1 template affected · PKI / ADCS · Critical
Effort
#3
Guest Account Enabled
1 account affected · Auth & Authorization · High
Effort
#4
Stale krbtgt Account Password, 394 days old
Domain-wide impact · Auth & Authorization · High
Effort
#5
High Number of Privileged Users: 17 Domain Admins
17 accounts affected · Identity & Groups · High
Effort

Get a quote

Tell us what you're working with.

Share your situation and we'll come back with a scoped estimate covering hours, approach, and timeline. No commitment required.

Response within one business day

We're a small team and we read every submission. You'll hear from a practitioner, not a sales rep.

No minimum engagement size

We work on single findings or full remediation programs. The scope is whatever makes sense for your situation.

Discounted rates for active subscribers

Standard, Auditor, and Enterprise subscribers save 15%, 25%, and 40% off the base hourly rate. If you don't have a plan yet, run a free scan first.

Remediation quote request
We'll respond with a scoped estimate within one business day.

By submitting you agree to our Privacy Policy and Terms of Use. Hands-on implementation is delivered under a separately scoped statement of work.

Request received.
Thanks for reaching out. A practitioner will get back to you, usually within one business day.