Read-only collector · standalone or SaaS daemon

Identity Security Audits for
Active Directory and Entra ID

Run fact-based audits for on-prem and cloud identity from the same workflow.
500+ security checks, one edition, everything included. Keep data local in standalone mode, or connect a SaaS daemon for centralized follow-up.

500+ security checks · single editionStandalone + SaaS daemonRead-only collector · API + GUI

See the platform in action

cloud.etcsec.com › nordis-industries.demo
Live analysis
0
B
Good
218
Findings
178
Types
592
Users
686
Computers
345
Groups
47
OUs

Critical Open

Unresolved critical findings

Critical
12

↓ 6 since last audit

MFA Coverage

462 of 592 users enrolled

Fair
78%

recommended ≥ 95%

Privileged Admins

Tier-0 admin accounts

Good
8

recommended ≤ 20

Compliance

7 frameworks below threshold

Critical
47%

avg across 9 frameworks

Last Audit

Most recent collector run

Good
1dago

+8vs previous

Risk burndown90d
+2 new-140 period
358
Feb 1May 1
Top business risks5/15
FILTER
#FrameworkCodeControlFindings
#1NIS2 (FR)Art.21(2)(e)Sécurité de l'acquisition et du développement
10
#2ANSSI PA-099R52Privilèges Tier-0 nominatifs
6
#3CIS v8.1§1.1Inventaire des actifs autorisés
6
#4NIS2 (FR)Art.21(2)(h)Chiffrement et authentification
6
#5ANSSI PA-099R72Surveillance des comptes privilégiés
4
Security Alerts
4 config1 warning31 accounts

31 accounts with CRITICAL risk scores (50+). Immediate action required.

wilson.olivia8719 issues
luo.lan8417 issues
jackson.john8216 issues
shimizu.hana7815 issues
thompson.naomi7614 issues
Machine Account Quota50

Tout utilisateur du domaine peut joindre jusqu'à 50 machines - passer ms-DS-MachineAccountQuota à 0.

KRBTGT Password Age412 jours

Rotation à effectuer tous les 90-180 jours pour mitiger les Golden Ticket.

Anonymous LDAPAutorisé

Reconnaissance LDAP non-authentifiée possible - désactiver.

Pre-Win2000 Compatible AccessActivé

Groupe legacy qui donne un accès lecture étendu à tous les utilisateurs authentifiés.

Last AD Backupil y a 28 jours

L'Active Directory devrait être sauvegardé régulièrement.

Trend vs. Previous Audit
+8 pts
Score: 7684 (+8 pts)
Critical:18126
High:45387

Category Breakdown

Permissions
18246
Account Status
62653
Group Analysis
6161Unchanged
Network Security
43474
Service Accounts
67643
Advanced Security
4646Unchanged
Computer Security
5959Unchanged
Kerberos Security
4949Unchanged
Password Security
4545Unchanged
Privileged Accounts
57592

No signup. No connector to install. Click, explore.

Read-only audits for Active Directory and Entra ID with structured output, repeatable workflows, and deployment modes that match local-only or centrally managed teams.

EtcSec-Open-source collector and SaaS workflow
500+
Security checks
49
MITRE techniques
<8s
Benchmark scan time
2
Operating modes
3
Supported operating systems
Aligned with industry frameworksNISTGDPRMITRE ATT&CKCISANSSI

Why teams use EtcSec

Audit what exists today, keep the collector close to the environment, and make the results usable for remediation and follow-up.

Read-only by design

Collect from Active Directory over LDAP/LDAPS and SYSVOL, and from Entra ID over Microsoft Graph, without deploying an agent on domain controllers.

Fast, repeatable runs

Benchmark runs complete in seconds, which makes recurring audits practical after every remediation or privilege change.

MITRE ATT&CK context

Map findings to attacker techniques so teams can explain why a control matters, not just that it failed.

Structured remediation workflow

Move from raw detections to prioritized fixes, exports, and follow-up reviews without rebuilding the audit from scratch.

How It Works

A repeatable workflow for AD and Entra ID audits

[STEP 01]

Deploy the Collector

Install ETC Collector on Linux, macOS, Windows or Docker with the published installer or package guides, then configure the Active Directory and Entra ID providers.

[STEP 02]

Run the Audit

Run the audit in standalone mode or through the SaaS daemon. The engine checks named detections across AD and Entra ID.

[STEP 03]

Get Actionable Report

Review prioritized findings, MITRE ATT&CK mapping, exports and remediation guidance from the same workflow.

etcsec.com
$
Auto-replay
Air-gapped environment?

For isolated networks, keep the standalone server local or export JSON results for downstream review without exposing the collector to the public internet.

Open-source collector

ETC CollectorStandalone or SaaS daemon

A cross-platform Go collector for Active Directory and Entra ID. A single edition covers 500+ security checks, Active Directory checks across 14 categories and Microsoft Entra ID checks across 9 categories, including ADCS ESC1-ESC11 and attack path analysis.

Read-only collection
Collects AD data over LDAP/LDAPS and SYSVOL, and Entra ID data over Microsoft Graph, then emits structured JSON for the local GUI, API or downstream automation.
Two operating modes
Use a fully local standalone server with embedded GUI and REST API, or enroll a SaaS daemon for centrally managed recurring audits.
Cross-platform and lightweight
Single static binary for Linux, macOS and Windows, around 20 MB with zero runtime dependencies, plus Docker and service-install workflows.
One-line install
VERSION=3.2.0 && curl -LO https://github.com/etcsec-com/etc-collector-com/releases/download/v${VERSION}/etc-collector-${VERSION}-linux-amd64.tar.gz && tar -xzf etc-collector-${VERSION}-linux-amd64.tar.gz && sudo install -m 0755 etc-collector-${VERSION}-linux-amd64/etc-collector /usr/local/bin/etc-collector && sudo etc-collector install --mode server
One-line install for Linux, plus macOS, Windows and Docker guides
Embedded REST API and local web GUI on port 8443
Single edition: Active Directory checks across 14 categories, Microsoft Entra ID checks across 9 categories
FSL-1.1-ALv2: free for everyone including commercial use; the only restriction is reselling it as a competing hosted service
2
Operating modes
3
OS targets
~20MB
Static binary
Comprehensive Coverage

What the platform looks for in AD and Entra ID

From password exposure and Kerberos abuse to Conditional Access drift, PIM, app permissions and guest exposure, the detections stay tied to named findings.

CRITICAL

Password and credential exposure

Weak password policy, reversible encryption, password-not-required flags and cleartext attributes.

CRITICAL

Kerberos and delegation abuse

AS-REP roasting, Kerberoasting, unconstrained delegation and protocol transition risk.

HIGH

ADCS and certificate services

ADCS ESC paths, weak certificate mapping and web enrollment exposure.

HIGH

Dangerous ACLs and DCSync

GenericAll, WriteDACL, AdminSDHolder backdoors, replication rights and RBCD paths.

HIGH

Conditional Access gaps

Missing MFA, legacy auth drift and policy exclusions that weaken tenant protection.

HIGH

Privileged access drift

PIM configuration, excessive admin roles, foreign principals and stale privileged accounts.

HIGH

Apps and external identities

Service principal permissions, stale credentials, multi-tenant apps and guest user exposure.

FULL CATALOGUE

Explore the full detection catalogue

Browse the public catalogue and the detailed AD and Entra coverage pages.

Browse all checks
Start Your Audit

Read-only collector, standalone mode, SaaS daemon workflow, and detailed coverage pages linked below.

Industry Standard Framework

MITRE ATT&CKCoverage Built-In

Mapped to 49 MITRE ATT&CK techniques across Credential Access, Persistence, Defense Evasion, Lateral Movement and Discovery.

21Credential Access techniques detected
12Persistence techniques detected
8Defense Evasion techniques detected
6Lateral Movement techniques detected
2Discovery techniques detected
Learn about MITRE ATT&CK

Sample Findings with ATT&CK Mapping

Kerberoastable Accounts
Credential Access
T1558.003
DCSync Rights
Credential Access
T1003.006
Certificate Template Escalation
Credential Access
T1649
Dangerous GPO Permissions
Persistence
T1484.001
Rogue Domain Controller (DCShadow)
Defense Evasion
T1207
Unconstrained Delegation
Lateral Movement
T1550
Conditional Access Bypass
Credential Access
T1556
Domain Trust Abuse
Discovery
T1482

Click technique IDs to view details on MITRE ATT&CK

Comparative benchmarks

Published methods, results, and full side-by-side detail

Review the documented coverage, runtime, and test conditions for PingCastle and Purple Knight on the dedicated comparison pages.

Benchmark notes

  • Both comparisons were run on the same 546-user, 100-computer AD test domain in February 2026.
  • ETC Collector was executed with network probes enabled when the methodology required it.
  • Detailed caveats, uncovered edge cases and screenshots stay on the dedicated comparison pages.
  • The dedicated comparison pages include the full rule breakdown, screenshots, and remaining gaps from the documented runs.
Simple, Transparent Pricing

Choose Your Plan

Start with our free collector. Upgrade when you need advanced features like scheduling, compliance reports, and SIEM integration.

Waitlist - Premium at 349€/moJoin the waitlist to be notified as soon as accounts open.
AVAILABLE NOW

Free

0€/forever
  • Free forever, no asset limit, fully local
  • 500+ Active Directory and Entra ID checks, attack paths, AD CS
  • 9 frameworks scored: ANSSI, HDS, NIS 2, CIS, NIST, GDPR
  • Local web interface, REST API, JSON export
  • Free online account up to 750 assets, 30-day history
Download Collector

Premium

179€/month
  • Everything in Free, plus: 1,250 assets, 90-day history
  • PDF export in EtcSec format
  • Audit-to-audit comparison, changes highlighted
  • Coming soonAudit scheduling and email alerts
  • Coming soonGoogle Workspace, Intune and Exchange Online connectors, roles and permissions
Join Waitlist
POPULAR

Elite

649€/month
  • Everything in Premium, plus: 5,000 assets, 4 audits/day, 1-year history
  • Coming soonAll 9 compliance reports per framework included
  • Coming soonPlatform API and webhooks
  • Priority support in French included
  • Coming soonOptional dedicated instance
Join Waitlist

Enterprise

1 299€/month
  • Everything in Elite, plus: 12,500 assets, on-demand audits, 2-year history
  • Coming soonSSO and SAML
  • Coming soonSIEM connector (Splunk, Sentinel)
  • 24/7 support included
  • Coming soonYour cloud or on-premises, annual commitment
Contact sales
MSSP

Partner

129€per managed client
  • €129 per managed client per month, decreasing from the 11th, minimum 5 clients
  • 1,250 pooled assets per managed client
  • Coming soonMulti-tenant console, white-label, client portal
  • Auditing your clients authorized under the FSL-1.1-ALv2 license
  • Resale: your price, your invoice, your margin
Explore MSSP program

Need Custom Add-ons?

Use our pricing calculator to add extra users, sites, collectors, compliance packs, and more.

Open Pricing Calculator
Start with the open-source collector

Ready to secure youridentity infrastructure?

Run a read-only audit for Active Directory or Entra ID, then choose the local or SaaS workflow that fits your team.

Latest research

Attack chains, compliance mapping and AD/Entra hardening guides

New posts from the EtcSec security team - every finding backed by MITRE ATT&CK and ANSSI mapping.

Browse all articles →