Read-only collection
AD objects and domain controller events are collected without automatically changing the customer environment.
Local-first · Read-only · Traceable
LAIA helps administrators and security professionals capture complex Active Directory environments in a structured way, evaluate technical anomalies traceably and present results clearly.
Why LAIA?
Active Directory environments often grow over many years. LAIA combines structured data collection, deterministic rules, technical evidence, local knowledge sources and optional local AI assistance without hiding the technical basis.
AD objects and domain controller events are collected without automatically changing the customer environment.
Findings can be traced back to rules, evidence, sources and the underlying data.
Local AI can support explanations, summaries and drafts, but does not independently decide objective security findings.
Who is LAIA for?
Capture and assess complex objects, permissions and activity in a structured way.
FeaturesUse technical evidence, security events and traceable findings for reviews.
SecurityBring account types, groups, activity and identity context together more effectively.
WorkflowKeep technical results and management-oriented outputs clearly separated.
ContactPrepare repeatable and documentable assessment workflows for different customer environments.
ContactSecurity & Privacy
LAIA is designed around local processing, controlled data collection and a clear separation between deterministic results and AI assistance.
AI may explain technical results and create drafts. Critical statements still require reliable technical evidence.
Available features
Users, groups, computers, gMSA/MSA, OUs, ACLs, schema, trusts and deleted objects.
Security, Directory Service and NTLM events from selected domain controllers.
User activity can be correlated with imported AD and event data.
Rule-based identification of technical, administrative and other account types.
Traceable technical checks linked to evidence, rules and sources.
Controlled import of local knowledge packages with integrity and content validation.
Versions & Roadmap
Planned functions are deliberately separated from features that are available today.
Analysis of CAs, certificate templates, permissions and security-relevant PKI configuration.
Analysis of relevant DNS zones, settings and security-relevant anomalies.
Structured collection and analysis of relevant DHCP configurations.
Integration of IP Address Management into infrastructure and security analysis.
Contact
For questions about the project or potential testing, contact us directly by email.