LAIAFeatures

Features

What LAIA can do today – and what is planned

Available, in-development and planned capabilities are deliberately shown separately.

Available

Available

AD object analysis

Users, groups, computers, gMSA/MSA, OUs, ACLs, schema, trusts and deleted objects.

Available

Domain controller security events

Security, Directory Service and NTLM events from selected domain controllers.

Available

Login and event correlation

User activity can be correlated with imported AD and event data.

Available

Account-type classification

Rule-based identification of technical, administrative and other account types.

Available

Rules and findings

Traceable technical checks linked to evidence, rules and sources.

Available

Local knowledge

Controlled import of local knowledge packages with integrity and content validation.

Available

Reporting

Technical outputs and reports in multiple formats.

Available

Identity and administration

Users, roles, MFA, TLS and central system configuration.

Domain controller security events

The current Event Collector processes event sources on selected domain controllers, including Security, Directory Service and Microsoft-Windows-NTLM/Operational. The standard catalogue covers security-relevant logon, authentication, Kerberos, NTLM and directory service events.

Read-only

Event collection does not change domain controller configuration and can be run centrally from a Windows management/export server.

Future analysis areas

Planned

PKI / Active Directory Certificate Services

Analysis of CAs, certificate templates, permissions and security-relevant PKI configuration.

Planned

DNS

Analysis of relevant DNS zones, settings and security-relevant anomalies.

Planned

DHCP

Structured collection and analysis of relevant DHCP configurations.

Planned

IPAM

Integration of IP Address Management into infrastructure and security analysis.

These areas are only marked as “In development” or “Available” once an approved technical implementation exists.