Comparison · Active Directory Security

Insight Recon vs Purple Knight: which AD security tool fits your team?

Purple Knight is one of the most widely downloaded free AD assessment tools in the industry, and Semperis's research team has earned its reputation. Here's an honest, technical look at how it compares to Insight Recon, and which one fits your environment.

Updated July 2026 11 min read By the Insight Recon team

If you've been evaluating Active Directory security tools or searching for a Purple Knight alternative, you're probably deciding between free point-in-time scanners, and the honest answer is that the differences show up after the scan finishes. This article compares Purple Knight and Insight Recon directly: what each tool checks, what the reports give your team to act on, how each handles tracking improvement over time, and which one makes sense for internal teams versus consultants and MSSPs.

Quick verdict

Purple Knight

A free, widely adopted assessment tool from Semperis covering AD, Entra ID, and Okta with 218+ indicators, including indicators of compromise. Strong choice for a broad hybrid-identity snapshot, especially if Entra ID or Okta is in scope today.

Insight Recon

An AD security assessment tool built by offensive security practitioners, pairing findings with attacker context, command-level remediation, and scan-over-scan trend tracking. Strong choice if the goal is fixing what's found and proving it stayed fixed.

What is Purple Knight?

Purple Knight is a free security assessment tool built by Semperis, the company behind Directory Services Protector. It's downloadable Windows software that runs without elevated privileges and scans your environment against 218+ security indicators: indicators of exposure that reveal exploitable misconfigurations, and indicators of compromise that can signal an attack already in progress.

Its defining strengths are breadth and pedigree. Coverage spans on-premises Active Directory, Entra ID, and Okta in one tool, the indicator library is maintained by a well-regarded identity security research team, and the report grades your environment with a percentage score across categories, maps indicators to MITRE ATT&CK, and includes remediation recommendations. It has been downloaded more than 75,000 times, which makes it one of the most recognizable names in free AD assessment.

Purple Knight is a point-in-time snapshot by design. Each run produces a standalone report, and Semperis positions its paid platform, Directory Services Protector, as the continuous version: monitoring, alerting, change tracking, and automated remediation.

What is Insight Recon?

Insight Recon is a read-only Active Directory security assessment tool built by the offensive security practitioners behind Breach Point. Like Purple Knight, it runs from a single Windows machine with a standard read-level domain account, nothing deployed to your domain controllers, and enumerates users, groups, ACLs, GPOs, ADCS, and trusts across 135+ checks, including the full ESC1 through ESC16 certificate services family.

Where Insight Recon differs is what happens after the scan. Every finding includes a Hacker Insight explaining how an attacker actually weaponizes it, the specific affected objects, a step-by-step remediation path with PowerShell, GPO, or ADUC instructions and an effort rating, and mappings to MITRE ATT&CK, NIST CSF, ANSSI, CIS Controls, and STIG. Reports live in a web portal rather than a standalone file, so scans build a history: a posture trend line, automatic diffs of new, modified, and remediated findings, and a record of your longest-standing criticals.

The complete assessment, every finding included, is free for one domain. Paid tiers add scan history and trend tracking, multi-domain scale, and commercial-use rights for consultants and MSSPs.

The honest framing. Purple Knight optimizes for breadth of snapshot: more platforms, more indicators, including compromise signals. Insight Recon optimizes for the remediation loop: what's exploitable, what to fix first, exactly how, and proof it got fixed. Which one you weight more depends on whether the scan is the end of your job or the start of it.

Comparison at a glance

Category Purple Knight Insight Recon
Scan methodRead-only, no elevated privileges, standalone appRead-only, no elevated privileges, single Windows host
Platforms coveredAD, Entra ID, OktaOn-prem AD only, Entra ID on the roadmap
Indicator / check count218+ indicators (IOEs and IOCs)135+ checks, exposure-focused
Indicators of compromise (IOCs)Yes, attack-in-progress signalsExposure-focused, not an IOC hunter
ADCS / certificate services coverageSelected ADCS indicatorsFull ESC1–16 family
Attacker context per findingIndicator descriptions, likelihood weightingsHacker Insight: tooling and technique explained
Remediation guidanceRecommendations per indicatorPowerShell / GPO / ADUC steps, effort rating, affected objects listed
Scoring modelPercentage score by category0–100 posture score with letter grade, exploitability-ranked
Report formatStandalone report per runInteractive portal report, with export options
Scan history & trend trackingManual rescans; continuous is DSP (paid)Standard tier and above, built in
MITRE ATT&CK mappingYes, per indicatorYes, per finding, all tiers
NIST / CIS / STIG mappingNot a documented featurePer finding, all tiers including Free
SupportCommunity Slack and emailStandard and priority support on paid tiers
CostFreeFree for 1 domain, full findings; paid from $1,500/year founding (Standard)
Multi-client platform for MSSPsNot offered (DSP targets internal enterprise use)Auditor tier: 50 domains, white-label, RBAC

Reflects publicly listed information as of this writing and is subject to change by each vendor. Confirm current details on Semperis's Purple Knight page and our pricing page.

Coverage & platforms

On raw breadth, Purple Knight wins the platform column: one free tool covering AD, Entra ID, and Okta is genuinely useful for hybrid shops, and the indicator library includes compromise signals that Insight Recon deliberately doesn't chase. If you need a cloud identity snapshot today, that's a real advantage, and we say so plainly.

Depth per platform is where the picture changes. Insight Recon's 135+ checks are all on-premises AD, which concentrates coverage where most identity attacks still land: the full ESC1–16 certificate services family, ACL and delegation abuse paths, GPO and SYSVOL risks, Kerberos configuration, and hygiene items like SMBv1 and Print Spooler on domain controllers. Indicator counts between tools aren't directly comparable, since one indicator can be broad or narrow, so the better question is whether the specific attack surfaces you worry about are covered, and how actionable the output is when something fails.

Remediation guidance

Purple Knight

Each indicator includes a description, a likelihood-of-compromise weighting, and remediation recommendations written by Semperis's identity security experts. That's real guidance, not just a rule name. It's written at the recommendation level, though: your team still translates it into the specific commands and change tickets for your environment.

Insight Recon

Every finding pairs a Hacker Insight (how it's actually exploited, with the tooling named) with copy-ready PowerShell, GPO paths, or ADUC steps, the specific affected users, groups, or computers, and an effort rating. The report is built to become a work queue: quick wins first, evidence when each item closes.

Reporting, history & trends

Purple Knight produces a standalone report each run, and Semperis recommends rescanning periodically. That works for an annual or quarterly health check, but comparing runs means keeping old reports and diffing them yourself, and the built-in answer for continuous visibility is Directory Services Protector, which is a different budget conversation entirely.

Insight Recon reports live in a portal by default. From the Standard tier up, every scan is retained: you get a posture score trend line, an automatic diff of new, modified, and remediated findings between scans, and a record of the longest-standing critical issues. For a lot of teams, that's the practical middle ground between "free snapshot" and "enterprise monitoring platform."

Compliance mapping

Purple Knight maps its indicators to MITRE ATT&CK, which is genuinely useful for framing findings in attacker terms. Per-finding mappings to NIST CSF, CIS Controls, or STIG aren't a documented feature, so if your deliverable is audit evidence against those frameworks, you'll be building that crosswalk yourself.

Insight Recon maps every finding to MITRE ATT&CK, NIST CSF, CIS Controls, and STIG on every plan, including Free. For teams that need to hand a report to an auditor or cite a specific control in a risk register, that mapping being included before you've paid anything can shorten the evaluation considerably.

Where Purple Knight fits best

  • You need hybrid identity coverage in one free tool. AD, Entra ID, and Okta in a single scan is a breadth no free competitor matches today.
  • You want compromise signals, not just exposures. The IOC indicators can surface evidence of an attack already underway.
  • You're doing a one-off or periodic health check. A standalone report per run fits an annual assessment cadence fine.
  • You're evaluating the Semperis ecosystem. If Directory Services Protector is on your shortlist anyway, Purple Knight is its natural on-ramp.

Where Insight Recon fits best

  • The scan is the start of your job, not the end. Command-level remediation, effort ratings, and affected-object lists turn findings into closeable tickets.
  • You need to prove improvement over time. Trend tracking and scan-to-scan diffs start at $1,500/yr, not at an enterprise platform conversation.
  • Certificate services keep you up at night. Full ESC1–16 coverage catches template misconfigurations that broader tools check selectively.
  • You need NIST, CIS, or STIG evidence. Per-finding mappings to all four frameworks are on every tier, including Free.
  • You're an MSSP or auditor. The Auditor tier bundles 50 domains, white-label reports, and RBAC; Purple Knight has no multi-client platform.

Which tool fits your workflow?

Internal security / IT team

Securing one domain, want findings you can act on without translating recommendations into commands yourselves.

Insight Recon Free or Standard

Hybrid identity shops

Entra ID or Okta is in scope today and you want one free snapshot across all of it.

Purple Knight, or both tools

MSPs, MSSPs & consultants

Assessing client domains, need white-label reports, commercial rights, and per-client history.

Insight Recon Auditor

Running both costs you nothing but a lunch break. Both tools are free to start, read-only, and run without elevated privileges. A fair evaluation is simply: run both against the same domain and compare what the reports let your team do next.

Frequently asked questions

Is Purple Knight really free?

Yes. Purple Knight is free to download and run, with community support through Slack and email. Semperis's paid product is Directory Services Protector, which adds continuous monitoring, alerting, change tracking, and automated remediation on top of the point-in-time assessment Purple Knight provides.

What is a good Purple Knight alternative?

Insight Recon is built for teams that want the same read-only, no-elevated-privileges assessment model plus attacker context on every finding, command-level remediation steps with effort ratings, and a portal that tracks posture across scans instead of a standalone report per run. The full assessment is free for one domain.

Can I use Insight Recon and Purple Knight together?

Yes. Both are read-only and run without elevated privileges, so there's no operational conflict. Some teams run Purple Knight for its hybrid identity coverage and indicators of compromise, and Insight Recon for exploitability-ranked findings, command-level remediation, and trend tracking.

Does Purple Knight provide remediation guidance?

Yes. Purple Knight's report includes remediation recommendations for its indicators, written by Semperis identity security experts. Insight Recon goes a step further on workflow: each finding includes copy-ready PowerShell, GPO, or ADUC steps, an effort rating, and the specific affected objects, so fixes can be sequenced and closed without translation.

Does Purple Knight track my score over time?

Purple Knight produces a standalone report each run, and Semperis recommends periodic rescans, but built-in history and trending is the job of its paid sibling, Directory Services Protector. Insight Recon retains every scan from the Standard tier up, with a posture trend line and automatic diffs of new, modified, and remediated findings.

How is Insight Recon's scoring different from Purple Knight's?

Both point the same direction: higher is better. Purple Knight grades your environment as a percentage score across categories. Insight Recon's Risk Posture Score runs 0 to 100 with a letter grade, and ranks individual findings by exploitability using severity, privilege tier, and status, so the report doubles as a fix-first priority list.

Does Insight Recon cover Entra ID or Okta?

Not today. Insight Recon focuses on on-premises Active Directory, with Entra ID checks on the roadmap. If hybrid identity coverage in a single free tool is your requirement right now, Purple Knight covers AD, Entra ID, and Okta.

See what your Active Directory looks like to an attacker.

Run a free, read-only scan. Every finding included, with attacker context, PowerShell remediation, and compliance mapping. No credit card, no sales call.

Read-only scan · no production impact · results in minutes

This comparison reflects publicly available information about Purple Knight, including Semperis's product pages and FAQ, current as of July 2026. Feature sets change over time for both products; if you spot something out of date, let us know and we'll correct it. See all our comparisons.