Run fact-based audits for on-prem and cloud identity from the same workflow.
275 Active Directory detections and 144 Entra ID detections. Keep data local in standalone mode, or connect a SaaS daemon for centralized follow-up.
Read-only audits for Active Directory and Entra ID with structured output, repeatable workflows, and deployment modes that match local-only or centrally managed teams.
Aligned with industry frameworks
Audit what exists today, keep the collector close to the environment, and make the results usable for remediation and follow-up.
Collect from Active Directory over LDAP/LDAPS and SYSVOL, and from Entra ID over Microsoft Graph, without deploying an agent on domain controllers.
Benchmark runs complete in seconds, which makes recurring audits practical after every remediation or privilege change.
Map findings to attacker techniques so teams can explain why a control matters, not just that it failed.
Move from raw detections to prioritized fixes, exports, and follow-up reviews without rebuilding the audit from scratch.
A repeatable workflow for AD and Entra ID audits
Install ETC Collector on Linux, macOS, Windows or Docker with the published installer or package guides, then configure the Active Directory and Entra ID providers.
Run the audit in standalone mode or through the SaaS daemon. The engine checks named detections across AD and Entra ID.
Review prioritized findings, MITRE ATT&CK mapping, exports and remediation guidance from the same workflow.
For isolated networks, keep the standalone server local or export JSON results for downstream review without exposing the collector to the public internet.
A cross-platform Go collector for Active Directory and Entra ID. Community covers 264 AD and 134 Entra detections. Pro / Full covers 275 AD and 144 Entra detections, with broader ADCS, attack-path and advanced operating workflows.
curl -fsSL https://get.etcsec.com/install.sh | sudo bashFrom password exposure and Kerberos abuse to Conditional Access drift, PIM, app permissions and guest exposure, the detections stay tied to named findings.
Weak password policy, reversible encryption, password-not-required flags and cleartext attributes.
AS-REP roasting, Kerberoasting, unconstrained delegation and protocol transition risk.
ADCS ESC paths, weak certificate mapping and web enrollment exposure.
GenericAll, WriteDACL, AdminSDHolder backdoors, replication rights and RBCD paths.
Missing MFA, legacy auth drift and policy exclusions that weaken tenant protection.
PIM configuration, excessive admin roles, foreign principals and stale privileged accounts.
Service principal permissions, stale credentials, multi-tenant apps and guest user exposure.
Read-only collector, standalone mode, SaaS daemon workflow, and detailed coverage pages linked below.
Mapped to 28+ MITRE ATT&CK techniques across Credential Access, Persistence, Privilege Escalation and Lateral Movement.
Click technique IDs to view details on MITRE ATT&CK
Review the documented coverage, runtime, and test conditions for PingCastle and Purple Knight on the dedicated comparison pages.
Today the live audit providers are Active Directory and Microsoft Entra ID. Both run through the same collector workflow, local GUI/API, and recurring audit model.
Current live audit scope: Active Directory and Microsoft Entra ID.
Start with our free collector. Upgrade when you need advanced features like scheduling, compliance reports, and SIEM integration.
Beta — Premium 149€/mo · 449€ list price
One plan, full access. 20% lifetime discount for beta users.
Use our pricing calculator to add extra users, sites, collectors, compliance packs, and more.
Open Pricing CalculatorExplore detailed pages for Active Directory, Entra ID, ETC Collector deployment, and side-by-side product comparisons.
Review the landing page focused on Tier 0, Kerberos, delegation, ADCS, and remediation priorities.
See the Entra ID page covering Conditional Access, MFA, PIM, app permissions, and guest exposure.
Compare PingCastle with ETC Collector for recurring AD audits and standalone collection workflows.
Compare Purple Knight with ETC Collector for AD plus Entra ID reviews and recurring follow-up.
Review ETC Collector, its local deployment modes, and how teams run standalone or recurring audits.
Run a read-only audit for Active Directory or Entra ID, then choose the local or SaaS workflow that fits your team.