What the AD Audit Checks
Run the export script as a Domain Admin — it reads AD configuration and account metadata only, never passwords, hashes, or file contents.
Privileged Groups
Domain Admins and Enterprise Admins membership size — flags standing over-privileged access that expands your attack surface.
Kerberos Security
krbtgt password age (Golden Ticket risk), Kerberoastable service accounts, and unconstrained delegation exposure.
Password Policy
Minimum length, complexity, lockout threshold, reversible encryption, and accounts with never-expiring or blank passwords.
Stale Accounts
Inactive user and computer accounts (90+ days) left enabled — unmonitored attack surface from former employees and forgotten systems.
Hardening & Recovery
LAPS deployment, AD Recycle Bin, SMBv1 exposure, anonymous LDAP/SAM access, and end-of-life Domain Controllers.
Trusts & GPOs
External/forest trust SID filtering and unlinked/orphaned Group Policy Objects that suggest weak change management.
Common AD Findings We Catch
Fix:
Fix:
Audit Your Active Directory Now
Download the script, run it on a DC, upload the results — get a scored report in 60 seconds.
🔒 Start Free Audit