Free Scan
Free Scan
See your AD through an attacker's eyes.
Insight Recon reads your Active Directory environment, analyzes identities, permissions, and configuration, and surfaces a prioritized report of your real exposure in minutes.
What gets scanned
Everything Insight Recon enumerates
and what it surfaces from it.
The scan is read-only and non-destructive. It connects to your AD environment, enumerates the objects and configuration below, and builds the exposure picture your report is based on.
Prerequisites
What you need to get started.
The scan requires a Windows machine joined to the domain and a read-level domain account. No elevated privileges, no changes to Active Directory, no production impact.
A domain-joined Windows machine
Any Windows workstation or server joined to the domain you want to assess. You install the Insight Recon scanner on it and run your scans from there. Nothing is deployed to your domain controllers or endpoints.
A read-only domain account
A standard domain account with read permissions is enough. The scanner reads Active Directory over LDAP, so Domain Admin is not required and not recommended for the scan account.
Network access to a Domain Controller
The machine running the scanner needs LDAP or LDAPS access to at least one domain controller on the standard ports 389 / 636. Most domain-joined machines already have this by default.
What the scan doesn't do
Read-only. Non-destructive.
No surprises.
We know you're security-conscious. Here's exactly what the scan doesn't do, and what happens to your data when it's done.
The scan is entirely read-only. It queries AD using standard LDAP. It does not create, modify, or delete any objects, accounts, policies, or configurations.
You install the scanner on one machine you choose. Nothing is deployed to your domain controllers or across your endpoints, and it runs under an account you control.
The scan does not attempt to exploit any finding, escalate privileges, move laterally, or do anything a vulnerability scanner or pen test tool would do.
Your AD data is used to generate your report and nothing else. We do not mine scan results, use them for advertising, or share them with third parties. See our Privacy Policy.
The scanner makes LDAP queries consistent with normal administrative tools. It does not generate traffic patterns that would trigger security monitoring or impact domain performance.
Scan results are retained for the life of your account. On account deletion, scan data is removed within 30 days. You can export or delete your data at any time.
What you'll receive
A real report. Not a score and a list.
Every finding includes attacker context explaining how it would be weaponized, specific remediation steps your team can execute, and the compliance frameworks it maps to.
A weighted score based on your actual findings, not a textbook formula. Includes a trend comparison against your previous scan if you have one.
Each finding explains what an attacker does with it, which real tooling they'd use, and why it matters in your environment specifically.
The findings that reduce the most risk with the least remediation effort, so your team knows exactly where to start.
Not "review your password policy." Specific commands, GPO paths, and ADUC steps relevant to the exact finding in your domain.
May 4, 2026
Get started
Run your free scan today.
Create your account in the Insight Recon portal and download the scanner. You install it on one domain-joined machine, and it reads your AD read-only, with no changes to your environment.
The free scan is genuinely free, with the full assessment for one domain. Upgrade only when it makes sense for your team.
From account creation to a full report in your browser, no waiting, no scheduling.
The same people who run AD assessments professionally built the tool and wrote the findings.
We never mine scan results, sell data, or use your AD environment for anything beyond generating your report.
Already have an account? Sign in. By continuing you agree to our Terms of Use and Privacy Policy.
Common questions