“We were able to harden our Active Directory like never before – making sure it’s absolutely secure.” – VP of IT at AMOCO
Active Directory, Azure AD (now called Entra ID), and Okta vulnerabilities can give attackers virtually unrestricted access to your organization’s network and resources. Semperis built Purple Knight—a free AD, Azure AD, and Okta security assessment tool—to help you discover indicators of exposure (IoEs) and indicators of compromise (IoCs) in your hybrid AD environment. Let us help you run Purple Knight and dramatically reduce your AD attack surface today. Questions? info@mobiuspartners.com
Purple Knight provides valuable insight into your AD security posture. It runs as a standalone utility that queries your AD environment and performs a set of tests against many aspects of AD’s security posture, including AD Delegation, Account security, AD Infrastructure security, Group Policy security, and Kerberos security. See full list here. Purple Knight is intended to augment your security team with know-how from a community of security researchers to minimize your attack surface and stay ahead of the ever-changing threat landscape.
Common vulnerabilities uncovered in report:
• Non-default principals with DC Sync rights on the domain
• Privileged users with weak passwords
• Anonymous access to Active Directory enabled
• Unprotected accounts with admin rights
• User & admin accounts with old passwords
• Azure AD privileged users that are also privileged in AD
Click here to see the report.
“We were able to harden our Active Directory like never before – making sure it’s absolutely secure.” – VP of IT at AMOCO
During internal risk assessments, AMOCO realized they some work to do to secure Active Directory. Möbius Partners helped deploy the Semperis Purple Knight tool to identify vulnerabilities on AD in less than 15 minutes. They worked with AMOCO to remediate the vulnerabilities and introduced Directory Services Protector (DSP) to further protect their AD giving AMOCO peace of mind that everything is secure. Purple Knight is a security vulnerability scanning engine to quickly find all “Indicators of Exposure” & “Indicators of Compromise” within AD.
What’s in the report?
This example report summarizes the Active Directory security assessment results performed by the Semperis Purple Knight tool. The assessment performed includes querying your AD environment and running a series of security indicator scripts against domains in the selected forest. This assessment represents opportunities for enhancing this AD environment from a security perspective in accordance with industry best practices. Click here for a sample Purple Knight report.
Use Cases:
Tool Auditing Overview
Tool Highlights
To get started, chat in the lower right or email info@mobiuspartners.com. We have an entire podcast episode dedicated to this topic: mobiuspartners.com/podcast. To see an overview of our Security expertise, please visit here.
get started today
Cookie | Duration | Description |
---|---|---|
cookielawinfo-checkbox-analytics | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics". |
cookielawinfo-checkbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional". |
cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
cookielawinfo-checkbox-others | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other. |
cookielawinfo-checkbox-performance | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance". |
viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |
"*" indicates required fields