#pingcastle
Most breaches walk straight through misconfigured Active Directory.

7 free tools that find the holes first: PingCastle (start here), BloodHound CE, Purple Knight, Certipy, Snaffler, and ADeleg.

Your own domain, with authorisation.

https://app.stationx.net/book
September 23, 2026 at 12:01 PM
Netwrix enhances cloud security by introducing AI agent identity visibility in Microsoft Entra ID across PingCastle and Threat Manager.

https://pcmasterinsider.com/netwrix-microsoft-entra-id-ai-agent-visibility/

#Netwrix #EntraID #AISecurity #CloudSecurity
Netwrix Updates Microsoft Cloud Security with AI Agent Visibility
Netwrix introduces AI agent visibility in Microsoft Entra ID across PingCastle and Threat Manager to improve non-human identity security.
pcmasterinsider.com
August 19, 2026 at 3:03 PM
Think I might have to stop recommending PingCastle
@Netwrix
I am such a big fan. Please change your mind on this. Release the risk indicators with ALL versions.

🔁 RT @techspence | reposted by @HackingLZ
https://x.com/techspence/status/2087238423572550125
August 12, 2026 at 2:05 AM
📢 ADhammer v1.3.3 : toolkit offensif Active Directory en Rust avec audit et exploitation intégrés

Publié sur GitHub (icedracon/adhammer), ADhammer est présenté comme un toolkit de sécurité Active Directory développé en Rust…

🟡 vérification factuelle moyenne
#ADhammer #ActiveDirectory #Cyberveille
ADhammer v1.3.3 : toolkit offensif Active Directory en Rust avec audit et exploitation intégrés
Publié sur GitHub (icedracon/adhammer), ADhammer est présenté comme un toolkit de sécurité Active Directory développé en Rust dans le cadre d'une recherche académique (ITMO). Il se positionne comme un outil combinant audit passif (classe PingCastle) et validation offensive (classe impacket/Rubeus), distribué sous forme de binaire statique unique fonctionnant sous Kali/Linux et Windows.
cyberveille.ch
August 10, 2026 at 6:00 PM
I’m a pentester, so why do I always recommend tools like PingCastle, Locksmith, ADeleginator, PurpleKnight, etc.

Shouldn’t I be telling defenders to use BloodHound because it’s amazing and can find all t…

🔁 RT @techspence | reposted by @arekfurt
https://x.com/techspence/status/2086833770678694054
August 12, 2026 at 7:01 AM
adhammer - Active Directory security-assessment toolkit in Rust
https://t.co/kuieuBDAuL

— from @ipurple (https://x.com/ipurple/status/2084873925914202467)
GitHub - icedracon/adhammer: Active Directory security-assessment toolkit in Rust — PingCastle-cl...
t.co
August 5, 2026 at 5:43 AM
PingCastle, Purple Knight, BloodHound : aucun ne détecte une ACL LAPS posée directement sur un objet ordinateur.

Résultat : mot de passe admin local lisible en clair. Escalade immédiate.

LegacyLapsAudit comble cet angle mort 👇
www.it-connect.fr/audit-laps-d...

#activedirectory
July 9, 2026 at 3:00 PM
PingCastle generates detailed HTML reports on AD domain controller security. Learn how to parse, automate, and integrate these reports into your security workflows. Full guide at

https://www.valtersit.com/vault/pingcastle-domain-controller-html-report-79df6e/
June 20, 2026 at 6:21 PM
Anonymized PingCastle report from a nonprofit AD environment: risk score 100/100. Here's what we found and how to fix it.

nonprofittechsupport.ca/blog/f/nonpr...

#cybersecurity
March 21, 2026 at 7:54 PM
SMB Auditing Made Easy: Ditch PingCastle and Use This PowerShell Script for Dialect and Signing Reports + Video

Introduction: Server Message Block (SMB) is the backbone of file sharing in Windows networks, but its legacy dialects and misconfigured signing requirements create massive security blind…
SMB Auditing Made Easy: Ditch PingCastle and Use This PowerShell Script for Dialect and Signing Reports + Video
Introduction: Server Message Block (SMB) is the backbone of file sharing in Windows networks, but its legacy dialects and misconfigured signing requirements create massive security blind spots. Security teams often rely on heavy tools like PingCastle to audit these settings, but running them across every domain in a large forest is inefficient and noisy. A new lightweight PowerShell script offers a streamlined way to extract SMB dialect and signing data directly, enabling faster reporting without the bloat.
undercodetesting.com
March 13, 2026 at 10:28 AM
Active Directory’s Dirty Secret: How a Post-It Note Brought Down an 80% Secure Domain + Video

Introduction In a recent Active Directory audit at a law firm, commercial scanners like PingCastle and Purple Knight returned an "acceptable" score of 80%. No critical CVEs, no glaring…
Active Directory’s Dirty Secret: How a Post-It Note Brought Down an 80% Secure Domain + Video
Introduction In a recent Active Directory audit at a law firm, commercial scanners like PingCastle and Purple Knight returned an "acceptable" score of 80%. No critical CVEs, no glaring misconfigurations—on paper, the domain appeared healthy. Yet within hours, a red teamer compromised the entire domain using nothing more than a sticky note, an old network share, and the mundane trust relationships that every administrator overlooks.
undercodetesting.com
March 3, 2026 at 3:57 PM
Sure Pentest one a year, but also, don’t wait until your next pentest to:

Run Locksmith
Run ADeleginator
Run PingCastle/PurpleKnight
Check shares, sharepoint, wikis for creds
March 3, 2026 at 3:36 PM
0xdf shows the exploitation in his HTB write-up.[1] I reviewed various PingCastle reports, and this privilege was explicitly set only on a small subset of networks, typically on accounts associated with SQL servers.
October 25, 2025 at 7:32 AM
I strongly recommend running Maester periodically to secure your Microsoft 365 tenant, in addition to running PingCastle in your On-Prem AD environment.

[1] maester.dev
Maester
Your Microsoft Security test automation framework!
maester.dev
October 23, 2025 at 6:14 AM
🔟 Internal misconfigs map your own downfall

Too many orgs never run BloodHound on themselves but attackers do.

It maps privilege paths in AD and reveals who can become what, and how.

✅ Run tools like BloodHound and PingCastle internally before attackers do it for you.
October 2, 2025 at 2:11 PM
1/ PingCastle now highlights when no policy is in place to prevent scripting files (such as .js) from being executed via double-click.
September 21, 2025 at 11:06 AM
I love using PingCastle, but this script is just fantastic. If you have AD, run it and find out what you need to improve 😎
3/3
July 23, 2025 at 8:00 PM
💡 Auditer soi-même son annuaire Active Directory en quelques minutes, c'est possible grâce à deux outils gratuits :

✅ PingCastle : www.it-connect.fr/comment-audi...

✅ Purple Knight : www.it-connect.fr/comment-audi...

#audit #activedirectory #sysadmin #infosec #microsoft #pingcastle #purpleknight
PingCastle, un outil pour auditer son Active Directory
Comment auditer un annuaire Active Directory ? Comment améliorer la sécurité d'un AD ? PingCastle est un outil abouti et qui apporte une réponse pertinente.
www.it-connect.fr
June 27, 2025 at 1:45 PM
💡 Auditer soi-même son annuaire Active Directory en quelques minutes, c'est possible grâce à deux outils gratuits

✅ Découvrir 𝗣𝗶𝗻𝗴𝗖𝗮𝘀𝘁𝗹𝗲 : www.it-connect.fr/comment-audi...

✅ Découvrir 𝗣𝘂𝗿𝗽𝗹𝗲 𝗞𝗻𝗶𝗴𝗵𝘁 : www.it-connect.fr/comment-audi...

#audit #activedirectory #sysadmin #microsoft #tools #tuto #it
May 7, 2025 at 11:10 AM
How do you meaningfully improve the security of your AD environment?

Run these free tools quarterly:

- PingCastle
- ScriptSentry
- Locksmith
- ADeleginator
April 21, 2025 at 6:40 PM
Pingcastle (as you know) is such a great start.
Working with an org right now, getting them down from 100 to < 20.
April 11, 2025 at 3:51 PM
Un nouveau venu aux côtés de PingCastle et PurpleKnight pour évaluer la sécurité de l’AD, multiplateforme écrit en Python >
« ADcheck: Assess the security of your Active Directory with few or all privileges. »
GitHub - CobblePot59/ADcheck: Assess the security of your Active Directory with few or all privileges.
Assess the security of your Active Directory with few or all privileges. - CobblePot59/ADcheck
github.com
March 31, 2025 at 9:18 AM