About Insight Recon

We built the Active Directory scanner we wanted on engagements.

Insight Recon was built by offensive security practitioners who have spent years finding the same Active Directory weaknesses in real environments. We wanted a scanner that explained how those weaknesses get abused, showed exactly what was affected, and gave defenders enough detail to actually fix them.

Offensive security Active Directory Enterprise IAM experience A Breach Point product

Why we built it

We were already doing this work by hand.

On penetration tests and security assessments, we kept finding the same classes of Active Directory problems: dangerous permissions, weak service accounts, certificate template issues, delegation, stale privileged access, and hybrid identity misconfigurations.

The scanners were useful for finding things, but the output often stopped too early. A finding might be technically correct without explaining how an attacker would use it, which objects were actually exposed, or what a defender should do next.

So we started building the tool around the questions we would ask during an engagement: How can this be abused? What is affected? How serious is it? How do we fix it? How do we verify the fix?

What became Insight Recon

A read-only Active Directory assessment with attacker context, affected objects, practical remediation, validation steps, and scan history built into the report.

How we think about findings

A misconfiguration matters
because of what it enables.

We approach Active Directory the same way we do on an engagement: understand the weakness, figure out how it can be chained or abused, then work backward to the remediation.

Attacker Context

What would we do with this access?

Findings are written around the abuse case. We care about whether a permission leads to privilege escalation, whether an account can be roasted, whether a certificate template can be turned into authentication, and what an attacker gains from the path.

Practical Remediation

What does someone need to actually close it?

The report includes affected objects, remediation paths, validation steps, exceptions, and evidence because identifying the issue is only half the job.

Heath Adams, Co-Founder of Insight Recon
Heath Adams
Co-Founder, Insight Recon

Co-Founder

Heath Adams

Heath's background is offensive security. He spent years performing penetration tests, teaching practical hacking, and showing security practitioners how attackers move through real environments.

He founded TCM Security and created the Practical Network Penetration Tester (PNPT) certification, built around performing and reporting a realistic penetration test rather than answering multiple-choice questions. He has also taught practical security to a large global audience and spoken at security conferences across the United States and internationally.

That experience is most visible inside Insight Recon's attacker context. The goal is not simply to say that an AD configuration is weak. It is to explain how the weakness gets used, what access it can create, and why the finding deserves the priority it received.

Founder, TCM Security Creator of PNPT Penetration testing Security education Conference speaker

Co-Founder

Bradley Thornton

Brad's background is offensive security, with an unusually deep foundation in enterprise identity. Before moving fully into penetration testing and red teaming, he spent nearly six years at GE working in enterprise identity and access management, including privileged identity management.

He later worked as a penetration tester and red team leader against the same kinds of large environments he had previously helped operate and secure. He has also led governance and risk work and now runs Threat Potential.

That combination gives him a strong understanding of both how attackers abuse identity infrastructure and why enterprise Active Directory ends up configured the way it does. Permissions, service accounts, administrative models, and legacy design decisions rarely exist in isolation.

That perspective shows up throughout Insight Recon, especially in privileged access, delegated permissions, hybrid identity, and remediation guidance that has to work in a real production environment.

Enterprise IAM Privileged identity Red teaming Penetration testing Founder, Threat Potential
Bradley Thornton, Co-Founder of Insight Recon
Bradley Thornton
Co-Founder, Insight Recon

What that means for the product

A few things we care about.

These are the questions we come back to when deciding how a finding should work inside Insight Recon.

01 / Explain the abuse

A finding should say why it matters.

If we cannot explain what an attacker can do with a weakness, the finding needs more work. Severity should reflect the impact of the exposure, not just the fact that a setting failed a check.

02 / Make remediation useful

The report should help someone fix it.

That means affected objects, practical remediation paths, validation steps, exceptions, and evidence. Telling someone to "review the configuration" is not enough.

03 / Show what changed

The next scan should tell you something new.

Environments change. New problems appear and old ones get fixed. Scan history should make that visible without forcing a team to compare reports by hand.

See the product

Run it against your own Active Directory.

The Free plan includes the full on-premises Active Directory assessment, with affected objects, attacker context, and remediation guidance.