Read-only collector · standalone or SaaS daemon

Identity Security Audits for
Active Directory and Entra ID

Run fact-based audits for on-prem and cloud identity from the same workflow.
275 Active Directory detections and 144 Entra ID detections. Keep data local in standalone mode, or connect a SaaS daemon for centralized follow-up.

275 AD + 144 Entra detections
Standalone + SaaS daemon
Read-only collector · API + GUI
Live Analysis
84/ 100
B
GOOD
Security Posture
42
Findings
178
Types
592
Users
686
Computers
345
Groups
Critical1
High4
Medium15
Low22
Generated in 6s
|etcsec.com|AD + Entra ID audit

Read-only audits for Active Directory and Entra ID with structured output, repeatable workflows, and deployment modes that match local-only or centrally managed teams.

EtcSec
Open-source collector and SaaS workflow
419
Pro / Full detections
28+
MITRE techniques
<8s
Benchmark scan time
2
Operating modes
3
Supported operating systems

Aligned with industry frameworks

NIST
GDPR
MITRE ATT&CK
CIS
ANSSI

Why teams use EtcSec

Audit what exists today, keep the collector close to the environment, and make the results usable for remediation and follow-up.

Read-only by design

Collect from Active Directory over LDAP/LDAPS and SYSVOL, and from Entra ID over Microsoft Graph, without deploying an agent on domain controllers.

Fast, repeatable runs

Benchmark runs complete in seconds, which makes recurring audits practical after every remediation or privilege change.

MITRE ATT&CK context

Map findings to attacker techniques so teams can explain why a control matters, not just that it failed.

Structured remediation workflow

Move from raw detections to prioritized fixes, exports, and follow-up reviews without rebuilding the audit from scratch.

How It Works

A repeatable workflow for AD and Entra ID audits

STEP 01

Deploy the Collector

Install ETC Collector on Linux, macOS, Windows or Docker with the published installer or package guides, then configure the Active Directory and Entra ID providers.

STEP 02

Run the Audit

Run the audit in standalone mode or through the SaaS daemon. The engine checks named detections across AD and Entra ID.

STEP 03

Get Actionable Report

Review prioritized findings, MITRE ATT&CK mapping, exports and remediation guidance from the same workflow.

etcsec.com
$
Auto-replay

Air-gapped environment?

For isolated networks, keep the standalone server local or export JSON results for downstream review without exposing the collector to the public internet.

Open-source collector

ETC CollectorStandalone or SaaS daemon

A cross-platform Go collector for Active Directory and Entra ID. Community covers 264 AD and 134 Entra detections. Pro / Full covers 275 AD and 144 Entra detections, with broader ADCS, attack-path and advanced operating workflows.

Read-only collection
Collects AD data over LDAP/LDAPS and SYSVOL, and Entra ID data over Microsoft Graph, then emits structured JSON for the local GUI, API or downstream automation.
Two operating modes
Use a fully local standalone server with embedded GUI and REST API, or enroll a SaaS daemon for centrally managed recurring audits.
Cross-platform and lightweight
Single static binary for Linux, macOS and Windows, around 20 MB with zero runtime dependencies, plus Docker and service-install workflows.
One-line install
curl -fsSL https://get.etcsec.com/install.sh | sudo bash
One-line install for Linux, plus macOS, Windows and Docker guides
Embedded REST API and local web GUI on port 8443
Community: 264 AD + 134 Entra detections. Pro / Full: 275 AD + 144 Entra detections
Free for personal, educational, and non-commercial use. Commercial use requires a license — [email protected]
264+134
Community edition
2
Operating modes
3
OS targets
~20MB
Static binary
Comprehensive Coverage

What the platform looks for in AD and Entra ID

From password exposure and Kerberos abuse to Conditional Access drift, PIM, app permissions and guest exposure, the detections stay tied to named findings.

CRITICAL

Password and credential exposure

Weak password policy, reversible encryption, password-not-required flags and cleartext attributes.

CRITICAL

Kerberos and delegation abuse

AS-REP roasting, Kerberoasting, unconstrained delegation and protocol transition risk.

HIGH

ADCS and certificate services

ADCS ESC paths, weak certificate mapping and web enrollment exposure.

HIGH

Dangerous ACLs and DCSync

GenericAll, WriteDACL, AdminSDHolder backdoors, replication rights and RBCD paths.

HIGH

Conditional Access gaps

Missing MFA, legacy auth drift and policy exclusions that weaken tenant protection.

HIGH

Privileged access drift

PIM configuration, excessive admin roles, foreign principals and stale privileged accounts.

HIGH

Apps and external identities

Service principal permissions, stale credentials, multi-tenant apps and guest user exposure.

FULL CATALOGUE

Explore the full detection catalogue

Browse the public catalogue and the detailed AD and Entra coverage pages.

Browse all checks
Start Your Audit

Read-only collector, standalone mode, SaaS daemon workflow, and detailed coverage pages linked below.

Industry Standard Framework

MITRE ATT&CKCoverage Built-In

Mapped to 28+ MITRE ATT&CK techniques across Credential Access, Persistence, Privilege Escalation and Lateral Movement.

6Credential Access techniques detected
5Persistence techniques detected
4Privilege Escalation techniques detected
3Lateral Movement techniques detected
Learn about MITRE ATT&CK

Sample Findings with ATT&CK Mapping

Kerberoastable Accounts
Credential Access
T1558.003
AS-REP Roastable Users
Credential Access
T1558.004
DCSync Rights
Credential Access
T1003.006
Unconstrained Delegation
Credential Access
T1558.001
Dangerous GPO Permissions
Persistence
T1484.001
SID History and Trust Abuse
Persistence
T1134.005

Click technique IDs to view details on MITRE ATT&CK

Comparative benchmarks

Published methods, results, and full side-by-side detail

Review the documented coverage, runtime, and test conditions for PingCastle and Purple Knight on the dedicated comparison pages.

Benchmark notes

  • Both comparisons were run on the same 546-user, 100-computer AD test domain in February 2026.
  • ETC Collector was executed with network probes enabled when the methodology required it.
  • Detailed caveats, uncovered edge cases and screenshots stay on the dedicated comparison pages.
  • The dedicated comparison pages include the full rule breakdown, screenshots, and remaining gaps from the documented runs.
Simple, Transparent Pricing

Choose Your Plan

Start with our free collector. Upgrade when you need advanced features like scheduling, compliance reports, and SIEM integration.

Beta — Premium 149€/mo · 449€ list price

One plan, full access. 20% lifetime discount for beta users.

AVAILABLE NOW

Free

0€/forever
  • Active Directory today
  • Community edition: 264 AD + 134 Entra detections
  • 1 collector, 1 site
  • Up to 50 users
  • 1 audit/week, 30-day history
  • JSON/CSV export
  • Basic scheduling (1/week)
Download Collector

Premium

179€/month
  • Pro / Full edition: 275 AD + 144 Entra detections
  • 2 collectors, 3 sites
  • Up to 500 users
  • 1 audit/day, 90-day history
  • Scheduling and email alerts
  • MITRE ATT&CK mapping
  • PDF/CSV export
Get Started
POPULAR

Elite

449€/month
  • Pro / Full edition with ADCS and attack paths
  • 5 collectors, 10 sites
  • Up to 2,000 users
  • 4 audits/day, 1-year history
  • API access and webhooks
  • Trend analysis
  • 3 environments
Get Started

Enterprise

899€/month
  • Pro / Full edition at enterprise scale
  • 15 collectors, 25 sites
  • Up to 5,000 users
  • Unlimited audits, 2-year history
  • SIEM integration
  • SSO / SAML
  • SLA 99.5%, 10 environments
Contact sales
MSSP

Partner

1,499€/month
  • MSSP delivery for AD + Entra ID
  • Unlimited collectors and sites
  • Up to 15,000 users
  • Unlimited audits, 3-year history
  • White-label reports
  • Client portal and revenue share
  • Dedicated CSM
Explore MSSP program

Need Custom Add-ons?

Use our pricing calculator to add extra users, sites, collectors, compliance packs, and more.

Open Pricing Calculator
Start with the open-source collector

Ready to secure youridentity infrastructure?

Run a read-only audit for Active Directory or Entra ID, then choose the local or SaaS workflow that fits your team.

Identity Security Audits for Active Directory and Entra ID | EtcSec