AD Attack Surface Mapping
Full inventory of your identity attack surface: users, computers, groups, ACLs, GPOs, ADCS, trusts and delegations.
Learn moreADscan discovers and exploits every supported attack path to Domain Admin, proves the exposure is real, scores it, and maps each finding to DORA, NIS2 and ENS.
Every new account, group change and certificate template can open a fresh path to Domain Admin. A point-in-time test cannot see what changed last Tuesday. ADscan validates the paths that actually exist today, then re-validates as your environment moves.
A full identity attack-surface graph: users, computers, groups, ACLs, GPOs, ADCS, trusts and delegations, modelled the way an attacker sees them.
ADscan walks and exploits each supported path with guardrails and rollback, so the exposure is demonstrated, not assumed.
Every finding is tied to the specific DORA, NIS2 and ENS control, with legal citations, in one audit-ready report.
Every module is a real, audited capability of the ADscan engine, grouped by what it does for you: discover the surface, validate the paths, measure and comply, then operate continuously.
Full inventory of your identity attack surface: users, computers, groups, ACLs, GPOs, ADCS, trusts and delegations.
Learn moreDiscovers and exploits every supported path from a low-privilege user to Domain Admin, proving the exposure is real.

Kerberoasting, AS-REP roasting and spraying, plus which password hashes ADscan actually cracked.
Learn moreValidates ESC1 to ESC15 certificate-template attack paths against your own PKI.
Learn moreRBCD, constrained and unconstrained delegation, and ACL or object-control abuse.
Learn moreKnown AD CVEs and misconfigurations, validated against your environment, not just flagged.
Learn moreExposure Score, identity hygiene, trust topology and ADCS posture in one dashboard.
Learn moreEvery finding mapped to the specific DORA, NIS2, ENS Alto and ISO 27001 control.
Learn moreScheduled re-validation, drift detection and finding lifecycle. Enterprise tier.
Learn moreSIEM, webhooks, notifications and PDF or JSON export. Works with your stack.
Learn moreof the regulated environments we ran ADscan in had a live path to Tier 0.
ADscan PoV results to dateof human-operated ransomware attacks breach a domain controller.
Microsoft Security, Apr 2025maps every finding to DORA, NIS2 and ENS, with legal citations.
ADscan reportNative, agentless collection of users, computers, ACLs, GPOs, ADCS, trusts and delegations.
Build the identity attack graph and surface every route toward Tier 0.
Walk each supported path with guardrails and rollback, proving it reaches Domain Admin.
Quantify how reachable Tier 0 is, weighting proven paths over theoretical ones.
Tie each finding to the specific DORA, NIS2 and ENS control in the report.
On the Enterprise platform, re-run on a schedule and track drift over time.
Exploit and Revalidate are where ADscan goes beyond detection: it proves the path, then keeps proving it as your environment changes.
ADscan delivers a standalone report on day one and feeds your existing tooling on the Enterprise platform.
Splunk, Microsoft Sentinel
Webhooks, notifications
Jira, ServiceNow
PDF, JSON, CSV evidence bundle
SIEM, ticketing and webhook connectors ship with the Enterprise platform. Every tier exports the full report and evidence bundle.
ADscan does not list a wall of frameworks it half-supports. It maps every finding to the specific control, with the legal article, for the four that matter to regulated Spanish entities.
Regulation (EU) 2022/2554. ICT risk, resilience testing, incident windows.
Directive (EU) 2022/2555. Risk-management measures for essential entities.
Esquema Nacional de Seguridad, CCN-STIC controls for the high category.
ISO/IEC 27001:2022, Annex A control evidence.
A proven exposure picture and a compliance-mapped report you can take to the board and the supervisor, not a list of theoretical findings.
Request a PoVRoot-cause remediation per path, prioritised by what actually reaches Tier 0, so you close the real exposure before the auditor arrives.
See a sample reportThe same engine, in your hands, producing client-ready AD exposure reports in a fraction of the manual time. Free PRO beta in exchange for feedback.
Get PRO accessStart free on the command line, deliver board-ready reports with PRO, run it continuously on the Enterprise platform.
The full ADscan engine on the command line. Discover and validate paths to Domain Admin, free and open source.
Get it on GitHubPremium PDF report, attack-path narrative and compliance mapping. Free beta for consultancies and MSSPs in exchange for feedback.
Request beta accessOn-prem platform with scheduled re-validation, the exposure dashboard, finding lifecycle, monitoring and integrations.
Request a PoV“In every regulated environment where we have run ADscan, there was a live, exploitable path to Domain Admin. One had gone two years of annual pentests without it being found.”
It is the practice of not just detecting Active Directory misconfigurations but proving they are exploitable. ADscan walks and exploits each supported attack path from a low-privilege user to Domain Admin, so you know which exposures are real, today, in your environment.
A single ADscan run against a typical mid-sized domain completes in hours, not weeks. Collection is native and agentless, and exploitation is automated per path. On the Enterprise platform, scans run on a schedule.
Yes, safely. A readiness gate refuses unreachable or unsupported paths, dangerous CVEs are policy-blocked, and every change ADscan makes registers a cleanup and rollback step. It is designed to run against live Active Directory.
DORA (Regulation EU 2022/2554), NIS2, ENS Alto and ISO 27001:2022. Each finding is mapped to the specific control with the legal citation, in a single report. We map the frameworks that matter to regulated Spanish entities deeply, rather than a long list shallowly.
A pentest is a point-in-time engagement that covers one day of the year and depends on the tester. ADscan validates the paths that exist today, repeatably, and on the Enterprise platform re-validates continuously as your Active Directory changes.
LITE is the open-source ADscan engine on the command line: discover and validate paths, free. PRO adds the board-ready PDF report, the attack-path narrative and compliance mapping, and is free in beta for consultancies and MSSPs in exchange for feedback.
Continuous, scheduled re-validation and drift detection are part of the Enterprise platform. LITE and PRO are run on demand. The same engine underpins all three tiers.
Request a proof of value and we will run ADscan against your Active Directory, then deliver the compliance-mapped report.