This website uses cookies

Read our Privacy policy and Terms of use for more information.

Tools are a means to an end. If you only have a hammer, everything looks like a nail. Pick the right tool for the job.

As you know my day job is pentesting. Internal pentesting specifically with a passion for Active Directory and the Microsoft stack.

So when it comes to securing Active Directory you might think I would be recommending that you use “offensive” tools like BloodHound and Certify and others.

But I’m also a former sysadmin. I did IT for 10+ years. So I know what it’s like to be pulled in 100 different directions, working on 7 projects at a time, putting out fires and having to patch and fix pentest findings and do everything else that comes with a IT job.

While those “offensive” tools are great, they don’t come without some drawbacks. Namely, they are harder to use when you’re getting started. Bloodhound for example is more difficult to get setup and running and then to learn how to use it.

And when you’re already stressed and on the clock you need tools that are going to provide you value quicker and easier.

That’s not to say there’s anything wrong with BloodHound or other more complex tools. They are great and necessary and I’d encourage you to learn them in time.

But if you’re after quick-wins, low hanging fruit and security hygiene-related items, these are some great tools to start with.

PingCastle - 170+ rules related to Active Directory security misconfigurations and hygiene issues. They call it a “health check.” Free & commercial. Used to be a solo business made by Vincent Le Toux but is now owned by Netwrix.

PurpleKnight - Similar to PingCastle. AD security health check and hygiene. Free & commercial but it goes by a different name I believe. Made by Semperis, who has an all star team of Microsoft MVPs. Some I even call friends.

Locksmith - hands down the best AD CS auditing tool there is. It shows you what’s wrong and gives you powershell snippets to fix the issues. Free. Made by Jake Hildreth.

ADeleginator - a wrapper around a tool called ADeleg, a AD delegation management tool. Use this to find where unsafe groups and unsafe permissions. Like Everyone with FullControl over the root of the domain. Free. Made by me.

NetTools - The AD Swiss Army knife. Can do a ton of things. But it can be used to audit permissions extremely well. It highlights dangerous permissions so you know exactly what to review. Free. Made by Gary Reynolds.

There are no silver bullets in security, no one tool to rule them all. Every tool has its place. Every tool has pros and cons. Tools only get you so far.

It’s still up to you to read and internet and fix the issues you find, which as you know, is why security is so hard.

Lastly, I want this to serve as a reminder to myself and to all of us that many if not all of these tools would not exist without the countless hours and research and effort of those who have created and shared open source tools. Now and in the past.

We all stand on the shoulders of giants. Recommending one tool doesn’t in any way invalidate the effectiveness of any other tool.

Use the right tool for the job.

All the best
Spencer

PS - I did a webinar on how to harden Active Directory. If you haven’t seen it, I think you’d really get value from it. Watch it here.