When the print dialog opens: choose "Save as PDF", then uncheck "Headers and footers" under More settings.
Active Directory Assessment
Active Directory — One Honest Domain Posture Grade
RECON measures how exposed your domain is to a climb toward Domain Admin — the depth of a dedicated identity-posture assessment, delivered inside the same platform as your external and internal scanning. It runs agentless, from inside the perimeter, on the same probe that already discovers and scans your network, using a read-only credential that is destroyed at the end of the run. One contract is invariant: it detects, it never exploits.
Key takeaways
- RECON brings a dedicated Active Directory posture assessment inside the platform that already runs your external and internal scanning — one probe, one correlated view, shipping today in the RECON platform with its core checks live; some escalation checks (certain ESC paths, DCSync) are detect-only or still in validation.
- It is agentless and read-only: nothing is installed on your domain controllers, and the collector holds only the rights of an ordinary authenticated domain user.
- A privileged credential, when used at all, is used once to mint a dedicated read-only collector, then destroyed — never stored at rest.
- All dangerous analysis — Tier-0, attack paths, certificate abuse, posture scoring — runs on collected data, server-side, never against the live domain again.
How the Assessment Works
The design is deliberate: read the directory the way a posture tool does, keep every privileged secret off disk, and do all the dangerous thinking on the server — never on the live domain.
No real replication attack, no hash dumping, no forged tickets. The probe reads the directory over an authenticated channel exactly as a posture tool would, and every dangerous inference happens later, server-side, on data already collected.
Who should read this
- CISOs and security leaders who want identity risk expressed as one defensible domain grade, not a wall of directory findings.
- IT and identity teams responsible for Active Directory hygiene, privileged access and certificate services.
- Procurement and compliance functions comparing a consolidated platform against a standalone Active Directory posture tool.
- Incident-response and red teams who need the live paths to Domain Admin ranked, with the single node to break called out.
The Credential Lifecycle — Nothing Privileged Left at Rest
To read Active Directory you need an account, but RECON does not ask you to create a permanent one. In its default mode an administrator credential is used exactly once to mint a dedicated read-only collector, then crypto-shredded. The point of the whole sequence is simple: no privileged secret is ever left at rest, anywhere.
Two Connection Modes — and What Is Never Kept
You choose how the collector is created. Either way, no administrator secret is ever persisted; only the read-only collector is kept, encrypted.
The minted read-only collector is persisted, encrypted with a host-bound seal, so copying a probe’s configuration file alone cannot recover it. The administrator credential has no storage at all: it is request-scoped, sealed, delivered just-in-time, opened in memory, used, and crypto-shredded — never on disk, in a log, or in a permanent field, at any layer.
What It Reads — Read-Only, One Bind
The probe makes a single read pass over the directory — the same material a posture tool reads — and packages it for server-side analysis. Nothing is written; it is only an inventory of the domain’s objects, permissions and configuration weaknesses.
The Identity Inventory
Every user, group, computer, organisational unit and policy object the assessment resolves is presented as a filterable inventory, with privileged and Tier-0 objects flagged, risk markers surfaced and last-logon recency shown — the authoritative operating-system identity here also enriches the internal network asset inventory.
Attack Paths & Tier-0 — Who Can Reach Domain Admin
This is where raw data becomes an answer. The engine computes who — starting from any ordinary user — can climb to Domain Admin, which single node you should guard to break that climb (the chokepoint), and how severe each route is. It turns a list of findings into one clear instruction: fix what sits on a live path first.
The Domain Posture Grade
The same analysis resolves to a single domain grade the board can read — a score from 1 to 100 and a letter from A to F — while the team keeps the weighted findings behind it. A clean domain scores 100; every finding on a live path to Domain Admin pushes the number down.
Every factor, weight and the final aggregation are documented and reproducible. Confirmed findings count for more; candidates and detect-only checks are clearly marked, so you never read an inflated "critical" that was never proven.
Certificate Services — ESC1 to ESC16
Active Directory Certificate Services — the internal PKI — is one of the most abused routes to Domain Admin. RECON reads the certificate templates, certificate authorities and PKI containers with the same least-privilege bind, and classifies the known misconfigurations honestly: what is confirmed, what is only a candidate, and what is detect-only.
Confirmed, Candidate, Detect-Only
The value of the certificate checks is in their honesty. RECON never inflates a finding it has not proven; every template weakness carries an explicit status.
Because status is derived from what was actually read and proven, you never see a padded "critical" that was never demonstrated — the number shown reflects what genuinely fired.
The Controls Catalogue — Counted Honestly
A transparent list of every control RECON runs today and the few still on the roadmap. The counts are not inflated: the console shows only the checks that actually fire, kept separate from the attack-graph views and from planned controls.
Control categories
The counts are computed from the catalogue itself, and the live status of every control is derived from the real results returned to the console — not from a per-scan snapshot — so older probes cannot drift and the number you see stays faithful to what actually runs.
Coverage Tiers — What the Bound Account Unlocks
How much of the catalogue is exercised depends on the rights of the bound account. The baseline needs only an ordinary domain user; two optional read delegations unlock more, and a handful of checks are honestly out of reach for a read-only probe.
Coverage tiers
Each control resolves to a live status — active, locked pending a delegation, out of scope, candidate or planned — computed in the console from the real results of the run, so the coverage you are shown is always what genuinely fired.
The Security Model
RECON is built to assess the most sensitive part of your infrastructure without becoming a risk itself. Four properties are non-negotiable.
The collected directory outlives the probe that gathered it: replacing a probe never loses your domain history, because the collection is retained against the scan, not the hardware.
Why RECON — and What It Replaces
RECON brings a PingCastle- or Purple Knight-class Active Directory assessment inside the same platform as your external and internal scanning, run by a probe already deployed inside the perimeter — with no agent on the endpoints or the domain controller, and without ever exploiting anything.
You get the depth of a dedicated Active Directory posture tool without a second contract, a second console or a second agent — and a single grade your board can act on.
Next steps
- Request a guided walkthrough of the Active Directory assessment on your own domain.
- Deploy the probe in one network to see internal, OT/ICS and Active Directory assessment in a single pass.
- Review your live paths to Domain Admin, with the chokepoint to break called out first.
Contact: [email protected] · orizon.one/services/recon · European sovereign infrastructure.