> For the complete documentation index, see [llms.txt](https://docs.forestall.io/forestall/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.forestall.io/forestall/introduction/forestall.md).

# Forestall ISPM - Active Directory Security Assessment

Disrupt the Adversaries' Active Directory Kill Chain

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-fc5e80d731a69be82abf59913a1ade568c5fea93%2Fforestall_logo.jpg?alt=media" alt=""><figcaption></figcaption></figure>

`Forestall` reveals organizations’ Active Directory security posture before the attacker and enables you to quickly take the necessary precautions with the on-demand or periodic vulnerability assessment.

## Active Directory Inventory Mapping

Forestall collects in-depth information and relationships of Active Directory objects and endpoints with the proprietary algorithms. Some of the analyzed objects can be seen below.

* Users
* Computers
* Groups
* Group Policy Objects
* Organization Units
* Service Accounts / Managed Service Accounts
* Service Principle Names
* Access Control Entries
* Local Groups
* Local Users
* Network Shares

It presents this information in a form that can be easily searched, filtered, and exported in CSV format on the web interface. For example, the following information can be easily obtained through this interface.

* Privileged User and Groups
* Disabled/Locked Users
* Service Users
* Organizational Units with No Members
* User with Local Administrator Privileges
* Computers/Users with Most Sessions
* Group Policies with No Linked Entities

## Active Directory Vulnerability Assessment

Forestall continuously detects Active Directory Specific vulnerabilities with no false positives thanks to its Vulnerability Detection Engine. In addition, custom tags are added to vulnerabilities for easier categorization.

Vulnerability documentation contains the information below to accelerate vulnerability identification, remediation, detection, and prioritization process.

* Severity, Ease of Mitigation and Ease of Detection metrics for prioritization
* Vulnerability description, impact, and references
* Manual vulnerability identification methods
* Detailed mitigation plans and scripts for automatized remediation
* Exploitation detection methods with event log ids and attributes
* MITRE ATT\&CK matrix mapping for suitable vulnerabilities

## Actionable Remediation Roadmaps against Impacts

Forestall generates a remediation roadmap by aggregating the vulnerabilities that create critical attack vectors under Impacts and reveals which attacks the organization can be affected by. In this way, measures can be taken not only against vulnerabilities but also against emerging Active Directory threats.

## Active Directory Security Graph

Forestall creates an organizational Active Directory Security graph when the scan is finished. This graph contains all domain inventory and their relationships in one interface. Using manual or built-in queries in the graph module, abnormal relationships, shortest lateral movement, privilege escalation paths and misconfigured access control entries can be easily detected.

Some of the Built-in Queries in the Graph Module

* Object with DCSync Rights
* Non-built-in Admin Objects with WriteDACL Rights
* Administrator Sessions to Non-Domain Controllers
* Groups with Local Administrator Rights
* Shortest Path to Admin Groups
* Abnormal Rights which Domain User shouldn’t have

## Automatized Reporting

Forestall generates detailed, user-friendly, easy to understand, and instantly downloadable HTML and PDF reports when the scan is finished.

## REST API Interface

Forestall provides the REST API interface for automation and extensibility needs.

### Azure / Entra ID Security Assessment

In addition to on-premise Active Directory environments, Forestall also provides security assessment capabilities for **Microsoft Entra ID (Azure Active Directory)**.\
It enables organizations to identify cloud identity risks, excessive privileges, and misconfigurations before they can be exploited by attackers.

#### Azure / Entra ID Inventory Mapping

Forestall collects in-depth information and relationships of **Azure / Entra ID objects** using proprietary analysis algorithms.\
Some of the analyzed Azure entities include:

* Azure Tenants
* Users
* Groups
* Devices
* Applications
* Service Principals
* Roles (Built-in and Custom Roles)
* Administrative Units
* Conditional Access Policies

This information is presented in a searchable, filterable, and exportable format through the web interface, similar to Active Directory inventory analysis.

Using this interface, organizations can easily identify:

* Privileged and risky Azure users
* Inactive or unmanaged devices
* Applications without certificates or client secrets
* Over-privileged roles and service principals
* Misconfigured or risky identity settings

#### Azure / Entra ID Vulnerability Assessment

Forestall continuously detects **Azure / Entra ID–specific security issues** using built-in assessment rules.\
Detected issues are enriched with metadata to accelerate prioritization and remediation, including:

* Severity levels
* Exploitation certainty
* Impact analysis
* MITRE ATT\&CK® technique mapping
* Actionable remediation guidance

By correlating Azure identity findings with potential attack paths, Forestall helps organizations reduce cloud-based identity attack surfaces and improve their overall security posture.
