AD object analysis
Users, groups, computers, gMSA/MSA, OUs, ACLs, schema, trusts and deleted objects.
Features
Available, in-development and planned capabilities are deliberately shown separately.
Users, groups, computers, gMSA/MSA, OUs, ACLs, schema, trusts and deleted objects.
Security, Directory Service and NTLM events from selected domain controllers.
User activity can be correlated with imported AD and event data.
Rule-based identification of technical, administrative and other account types.
Traceable technical checks linked to evidence, rules and sources.
Controlled import of local knowledge packages with integrity and content validation.
Technical outputs and reports in multiple formats.
Users, roles, MFA, TLS and central system configuration.
The current Event Collector processes event sources on selected domain controllers, including Security, Directory Service and Microsoft-Windows-NTLM/Operational. The standard catalogue covers security-relevant logon, authentication, Kerberos, NTLM and directory service events.
Event collection does not change domain controller configuration and can be run centrally from a Windows management/export server.
Analysis of CAs, certificate templates, permissions and security-relevant PKI configuration.
Analysis of relevant DNS zones, settings and security-relevant anomalies.
Structured collection and analysis of relevant DHCP configurations.
Integration of IP Address Management into infrastructure and security analysis.
These areas are only marked as “In development” or “Available” once an approved technical implementation exists.