Active Directory assessment

Active Directory security assessment scanner

PrivLens is a local, read-only Active Directory security assessment scanner. Run it on a domain-joined Windows machine, review high-impact identity risks, and share a client-ready PDF — no install, no cloud, no directory changes.

What is an Active Directory security assessment scanner?

An Active Directory security assessment scanner reviews your directory for identity weaknesses that enable privilege escalation and lateral movement — excessive admin membership, stale accounts, weak password policy baselines, risky delegation, and related misconfigurations.

It is not a generic vulnerability scanner. It focuses on how authentication and authorization actually look in your domain today, so you can remediate with a short, actionable list instead of a wall of noise.

Why that matters. Most environments accumulate leftover privilege and forgotten accounts over time. Regular assessments are how you catch that drift before an attacker does. See why Active Directory security matters for the broader case.

Risks these assessments typically surface

Privilege and identity

  • Excessive Domain Admin and other privileged membership
  • Service accounts with administrative rights
  • Inactive or stale privileged accounts
  • Password-never-expires on privileged users

Policy and attack paths

  • Weak domain password policy baselines
  • Kerberoastable / AS-REP roastable exposure where present
  • Unconstrained or risky delegation patterns
  • High-risk operator groups that should stay empty

Manual review vs a focused scanner

Manual AD reviews can be thorough, but they are slow to repeat and easy to drift. Broad automated tools often dump hundreds of findings that need a specialist to interpret. PrivLens sits in the middle: repeatable, read-only checks that prioritize high-impact issues and explain each finding in plain language with a concrete fix.

What PrivLens checks for

  • Privileged group exposure and privilege creep
  • Password policy hygiene on the domain
  • Stale, dormant, and never-expire account patterns that raise risk
  • Service account and SPN-related attack surface
  • Delegation configurations that widen blast radius

Community and paid editions differ in how many catalog rules run and how wide the scan scope goes — see pricing. Every edition stays offline and local.

How PrivLens fits

Download a single Windows executable, run it with your current credentials, and open privlens-report.pdf. Nothing is uploaded. The report groups issues by severity, lists which checks passed or failed, and includes remediation-oriented wording you can hand to a client or internal stakeholder.

Run an Active Directory assessment locally

Start with Community, or compare Professional, Enterprise, and MSP when you need broader coverage.

Frequently asked questions

Does PrivLens modify Active Directory?

No. Scans are read-only. It uses your Windows login against a domain controller and writes findings only to a local PDF report.

How often should assessments be performed?

Quarterly is a practical baseline, plus after major privilege-model changes, domain migrations, or MSP onboarding for a new client.

How is this different from a vulnerability scanner?

Vulnerability scanners target software and patch posture. An Active Directory security assessment scanner evaluates identity posture — who has power, which accounts are soft targets, and which policies leave the door open.