We have had the chance to try ADscan, built by Yeray Martín, and we find it a genuinely interesting tool for anyone who works with Active Directory security. From a security-audit standpoint, one of its main strengths is getting a fast, complete picture of the security state of an AD environment: it surfaces insecure configurations, exposures and risk vectors that can be hard to catch in a manual review. What we liked most is the practical bent of the tool. It does not stop at collecting information; it helps you prioritise the findings and turn them into concrete points to improve. That is useful both during audits and in periodic security reviews or hardening work. For those of us who work with Active Directory, hardening, audits and security-posture analysis, having tools that cut the analysis time without losing depth is essential, and ADscan adds real value there. In short, a tool I would recommend keeping in the arsenal of any security team that wants to really understand what is happening inside its Active Directory and where its main risks are.


Original (Spanish)
Hemos tenido la oportunidad de probar ADScan, desarrollado por Yeray Martín, y nos parece una herramienta especialmente interesante para cualquier profesional que trabaje con seguridad de Active Directory. Desde el punto de vista de una auditoría de seguridad, uno de sus principales valores es la capacidad de obtener rápidamente una visión global del estado de seguridad de un entorno AD, identificando configuraciones inseguras, exposiciones y vectores de riesgo que pueden ser difíciles de detectar en una revisión manual. Me ha gustado especialmente el enfoque práctico de la herramienta: no se limita solamente a recopilar información, sino que te ayuda a priorizar los hallazgos y convertirlos en puntos concretos de mejora. Esto resulta especialmente útil tanto durante auditorías como en revisiones periódicas de seguridad o trabajos de hardening. Para quienes trabajamos con Active Directory, hardening, auditorías y análisis de postura de seguridad, contar con herramientas que permitan reducir el tiempo de análisis sin perder profundidad es fundamental. Y ahí ADScan aporta bastante valor. En definitiva, una herramienta que recomendaría tener dentro del arsenal de cualquier equipo de ciberseguridad que quiera conocer realmente qué está ocurriendo dentro de su Active Directory y dónde están sus principales riesgos.
Translated from Spanish. The original is below.