Skip to main content

Limited Beta

Identity and Active Directory Risk

Identity is the dominant attack vector in modern breaches. ARGUS maps your Active Directory attack surface, identifies privilege escalation paths, and surfaces credential exposures that enable lateral movement — before adversaries leverage them.

Assessment coverage

  • Active Directory Configuration

    Review AD settings for dangerous configurations: unconstrained delegation, weak password policies, legacy protocols, and insecure trust relationships.

  • Privilege Escalation Paths

    Map attack paths from low-privilege accounts to Domain Admin using relationships in AD structure, GPO, and ACL configurations.

  • Kerberos Attack Surface

    Identify Kerberoastable service accounts, AS-REP roasting candidates, and delegation misconfigurations.

  • Credential Exposure

    Detect accounts with compromised credentials in breach data, accounts without MFA, and over-privileged service accounts.

  • Azure AD and Hybrid Identity

    Assess Azure AD / Entra ID configurations, sync relationships, conditional access gaps, and application permissions in hybrid environments.

  • Privileged Access and PAM

    Evaluate privileged account management, administrative tier separation, and high-value account exposure.

Access requirements

Identity assessments are conducted with read-only domain-user credentials and BloodHound-compatible collection tools run by you within your environment. LawKade analysts review the collected data within ARGUS — no persistent domain access is retained.

  • Read-only domain user credentials provided by you
  • Collection run in your environment under your control
  • No persistent access — credentials revoked after collection
  • All attack paths reviewed by analyst before delivery
  • Remediation guidance prioritized by exploitability