Free Scan

See your AD through an attacker's eyes.

Insight Recon reads your Active Directory environment, analyzes identities, permissions, and configuration, and surfaces a prioritized report of your real exposure in minutes.

Read-only, no changes made No production impact Minutes to complete Report delivered immediately
What the free scan includes
No credit card
Full AD enumerationUsers, groups, permissions, ACLs, DCs, GPOs
Risk posture score with gradeWeighted by attacker impact, not textbook severity
Every finding, with attacker insight & remediationNo cap, no preview, the complete assessment
Quick wins + MITRE & compliance mappingsMapped to MITRE, NIST, CIS, and STIG
Executive summary exportAvailable on Standard and above
Report history & trend trackingAvailable on Standard and above
Multi-domain scale & commercial useAvailable on Auditor and above

What gets scanned

Everything Insight Recon enumerates
and what it surfaces from it.

The scan is read-only and non-destructive. It connects to your AD environment, enumerates the objects and configuration below, and builds the exposure picture your report is based on.

What gets enumerated
Users & accountsAll enabled, disabled, privileged, and service accounts
Groups & nested group membershipsIncluding inheritance chains and privileged group composition
ACLs and delegated rightsGenericAll, GenericWrite, WriteOwner, WriteDACL, and more
Domain ControllersCount, roles, replication state, and configuration
Group Policy ObjectsPassword policy, screensaver policy, firewall, WSUS configuration
ADCS / PKICertificate templates, CAs, enrollment rights, and ESC vulnerabilities
Trust relationshipsForest and external trusts, SID filtering, TGT delegation
Privileged objectsAdminSDHolder state, krbtgt password age, special accounts
Configuration stateLAPS, Recycle Bin, Entra Connect, schema version, backup age
What the report surfaces
Authentication & account risksEmpty passwords, non-expiring credentials, stale and guest accounts
Privileged access & ACL exposureExcessive Domain Admins, non-admin write access on privileged objects
Certificate services (ADCS)ESC1 through ESC16 certificate template and CA misconfigurations
Credential & Kerberos riskStale passwords, krbtgt age, unconstrained and constrained delegation
Identity sprawlOver-provisioned service accounts and nested group risk
Group Policy & configuration gapsMissing LAPS, disabled Recycle Bin, SYSVOL, firewall, backup age
Trust & domain hardeningTrust configuration, SID filtering, domain controller redundancy
Quick winsRanked by impact vs. remediation effort for your team
MITRE ATT&CK + compliance mappingsNIST CSF, CIS Controls, STIG, Microsoft Security Baselines

Prerequisites

What you need to get started.

The scan requires a Windows machine joined to the domain and a read-level domain account. No elevated privileges, no changes to Active Directory, no production impact.

REQ 01

A domain-joined Windows machine

Any Windows workstation or server joined to the domain you want to assess. You install the Insight Recon scanner on it and run your scans from there. Nothing is deployed to your domain controllers or endpoints.

REQ 02

A read-only domain account

A standard domain account with read permissions is enough. The scanner reads Active Directory over LDAP, so Domain Admin is not required and not recommended for the scan account.

REQ 03

Network access to a Domain Controller

The machine running the scanner needs LDAP or LDAPS access to at least one domain controller on the standard ports 389 / 636. Most domain-joined machines already have this by default.

What the scan doesn't do

Read-only. Non-destructive.
No surprises.

We know you're security-conscious. Here's exactly what the scan doesn't do, and what happens to your data when it's done.

No changes to your environment

The scan is entirely read-only. It queries AD using standard LDAP. It does not create, modify, or delete any objects, accounts, policies, or configurations.

No footprint on your DCs or endpoints

You install the scanner on one machine you choose. Nothing is deployed to your domain controllers or across your endpoints, and it runs under an account you control.

No lateral movement or exploitation

The scan does not attempt to exploit any finding, escalate privileges, move laterally, or do anything a vulnerability scanner or pen test tool would do.

Scan data is not used for anything else

Your AD data is used to generate your report and nothing else. We do not mine scan results, use them for advertising, or share them with third parties. See our Privacy Policy.

No excessive network traffic

The scanner makes LDAP queries consistent with normal administrative tools. It does not generate traffic patterns that would trigger security monitoring or impact domain performance.

Data retained only while your account is active

Scan results are retained for the life of your account. On account deletion, scan data is removed within 30 days. You can export or delete your data at any time.

What you'll receive

A real report. Not a score and a list.

Every finding includes attacker context explaining how it would be weaponized, specific remediation steps your team can execute, and the compliance frameworks it maps to.

Risk posture score with grade

A weighted score based on your actual findings, not a textbook formula. Includes a trend comparison against your previous scan if you have one.

Prioritized findings with attacker insight

Each finding explains what an attacker does with it, which real tooling they'd use, and why it matters in your environment specifically.

Quick wins ranked by impact vs. effort

The findings that reduce the most risk with the least remediation effort, so your team knows exactly where to start.

PowerShell-level remediation guidance

Not "review your password policy." Specific commands, GPO paths, and ADUC steps relevant to the exact finding in your domain.

Insight ReconSecurity Assessment
company.local
May 4, 2026
42OF 100
F · Critical Risk
Higher score means a stronger AD posture.
6
Crit
17
High
15
Mod
9
Low
Top Priorities
Ranked by exploitability
Accounts with no password requirementAUTH
Unrestricted cert template modification (ESC4)PKI
Stale krbtgt account password, 394 daysCRED
Guest account enabledAUTH

Get started

Run your free scan today.

Create your account in the Insight Recon portal and download the scanner. You install it on one domain-joined machine, and it reads your AD read-only, with no changes to your environment.

No credit card required

The free scan is genuinely free, with the full assessment for one domain. Upgrade only when it makes sense for your team.

Results in minutes

From account creation to a full report in your browser, no waiting, no scheduling.

Built by offensive security practitioners

The same people who run AD assessments professionally built the tool and wrote the findings.

Your data stays yours

We never mine scan results, sell data, or use your AD environment for anything beyond generating your report.

Create your free account
No credit card. The full assessment for one domain.
Every finding with attacker insight & remediation
Risk posture score and quick wins
MITRE & compliance mappings
Report in your browser in minutes
Create Free Account  →

Already have an account? Sign in. By continuing you agree to our Terms of Use and Privacy Policy.

Common questions

Before you run the scan.

How long does the scan actually take?
Most scans finish in just a few minutes. Larger or more complex environments take a little longer, but even sizable domains typically complete well within half an hour. Your report is available as soon as the scan finishes.
What permissions does the scan account need?
A standard domain user account with read access to AD objects is sufficient. The scanner uses LDAP queries, the same access level as any domain-joined workstation. Domain Admin is not required and we recommend against using it for the scan account.
Will it trigger our security monitoring?
The scan uses standard LDAP enumeration consistent with normal administrative tools like ADUC and the PowerShell AD module. It may appear in AD audit logs as LDAP queries from the account you designate. It does not perform any exploitation, credential attacks, or lateral movement.
What's the difference between the free scan and a paid plan?
The free scan is the complete assessment for one domain: every finding with attacker insight and remediation, your risk posture score, quick wins, and MITRE and compliance mappings. It keeps your latest scan only. Paid plans add scheduled scans, report history, trend tracking, exports, custom branding, multi-domain scale, and commercial use rights. See our pricing page for a full comparison.
Does my data leave my environment?
The scanner transmits enumerated AD metadata to generate your report: object attributes, relationship data, and configuration state. Raw credential material, password hashes, Kerberos tickets, and NTDS data are never collected. Full details are in our Privacy Policy.
Can I run it on a customer environment?
The free scan is for internal use on environments you own or have explicit written authorization to assess. Commercial use, running assessments on client environments, requires an Auditor plan. This is consistent with how tools like PingCastle license commercial use.