License & Deployment Mix: 12 tools – 7 OSS, 1 free vendor download, 4 commercial.
Color: Both (offensive AD pentest + defensive posture monitoring).
What Is This Category?
Almost every enterprise breach passes through Active Directory. AD / identity security is the specialty – distinct from general IAM governance – that focuses on the attack-path graph: who can reach Domain Admin from where, what credentials grant what lateral movement, what kerberoastable service accounts exist, what ACL misconfigurations open back doors.
The category covers three operational modes: pentest (offensive tools used during engagements), audit (one-shot risk scoring of an AD environment), and continuous defense (managed platforms for ongoing posture monitoring).
Distinct from neighbouring categories
- IAM & Identity Governance (IGA) – IAM / IGA is governance and provisioning (who should have access); AD security is attack-path / pentest / posture (who can get there)
- Privileged Access Management – PAM is privileged- access vaulting and session brokering; AD security is the analysis layer that says “this tier-1 admin has a kerberos chain to tier-0”
- Reconnaissance & Asset Discovery – recon is external; AD security is internal, post-foothold
The information on these pages was researched by a combination of human review and large language models. To suggest an addition or correction, please contact us. Prepared by Rhodium Systems Inc., author of the ResorsIT platform — a unified IT operations management platform for IT teams and MSPs that integrates a curated suite of open-source, commercial, and SaaS applications into a single system with shared identity, single sign-on, access control, and a common audit trail. Use this catalogue only as a starting point for your own research, and review any tool carefully against your own requirements before relying on it. Catalogue data version 2026.197.
Comparison
AD / identity security splits into three operational modes: pentest (BloodHound CE + NetExec + Impacket
- Rubeus + Kerbrute + Certipy – the offensive operator’s toolkit for engagements), audit (PingCastle
- Purple Knight – one-shot or scheduled risk-scoring deliverables), and continuous defense (BloodHound Enterprise, Semperis DSP, Tenable Identity Exposure, Defender for Identity – managed platforms for ongoing attack-path monitoring).
Operational Mode
What each tool is for.
| Tool | Pentest | Audit | Continuous Defense | Recovery |
|---|---|---|---|---|
| BloodHound CE | yes | partial | – | – |
| NetExec | yes | – | – | – |
| Impacket | yes | – | – | – |
| Rubeus | yes | – | – | – |
| Kerbrute | yes | – | – | – |
| Certipy | yes (AD CS) | partial | – | – |
| PingCastle | – | yes | partial (Enterprise) | – |
| Purple Knight | – | yes | – | – |
| BloodHound Enterprise | – | yes | yes | – |
| Semperis DSP | – | yes | yes | yes (ADFR) |
| Tenable Identity Exposure | – | yes | yes | – |
| Defender for Identity | – | – | yes | – |
License Comparison
| Tool | License | OSI | Type |
|---|---|---|---|
| BloodHound CE | Apache-2.0 | yes | OSS web + collector |
| NetExec | BSD-2-Clause | yes | OSS CLI |
| Impacket | Apache-2.0 | yes | OSS Python library + CLI |
| Rubeus | BSD-3-Clause | yes | OSS Windows .NET |
| Kerbrute | Apache-2.0 | yes | OSS Go binary |
| Certipy | MIT | yes | OSS Python CLI |
| PingCastle | NPOSL-3.0 | yes | OSS desktop (commercial Enterprise) |
| Purple Knight | Proprietary | – | Free vendor download |
| BloodHound Enterprise | Proprietary | – | Commercial SaaS (SpecterOps) |
| Semperis DSP | Proprietary | – | Commercial platform |
| Tenable Identity Exposure | Proprietary | – | Commercial platform |
| Defender for Identity | Proprietary | – | Commercial (Microsoft E5) |
SSO / OIDC
Most pentest tools are CLI / desktop with no auth surface. Commercial defense platforms have full SSO.
| Tool | OIDC | SAML | SCIM | Authentik Notes |
|---|---|---|---|---|
| BloodHound CE | plugin | plugin | – | Reverse-proxy auth (Authentik forward-auth) |
| Pentest CLI tools (NetExec, Impacket, Rubeus, Kerbrute, Certipy) | n/a | n/a | n/a | Cred-based; no service auth |
| PingCastle | n/a | n/a | n/a | Desktop CE; Enterprise tier has SSO |
| Purple Knight | n/a | n/a | n/a | Local Windows tool |
| BloodHound Enterprise | paid | paid | paid | Enterprise tier |
| Semperis DSP | paid | paid | paid | Enterprise tier |
| Tenable Identity Exposure | paid | paid | paid | Enterprise tier |
| Defender for Identity | native | native | native | Entra-native |
Deployment Comparison
| Tool | Deployment | Resources | Notes |
|---|---|---|---|
| BloodHound CE | Docker Compose | 8 GB / Neo4j | Self-hosted |
| NetExec | pipx / Docker | Trivial | Operator workstation |
| Impacket | pip / apt | Trivial | Operator workstation |
| Rubeus | C# binary | Trivial | Run on Windows host |
| Kerbrute | Single Go binary | Trivial | Operator workstation |
| Certipy | pipx / Docker | Trivial | Operator workstation |
| PingCastle | Windows .NET binary | Trivial | Domain-joined Windows host (audit user) |
| Purple Knight | Windows .NET binary | Trivial | Domain-joined Windows host |
| BloodHound Enterprise | SaaS + on-prem collectors | – | Vendor-managed |
| Semperis DSP | SaaS + per-DC agents | – | Vendor-managed |
| Tenable Identity Exposure | SaaS + on-prem collectors | – | Vendor-managed |
| Defender for Identity | SaaS + per-DC sensors | – | M365-native |
Composition Patterns
1. Pentest engagement
Kerbrute -- day-1 user enumeration + password spray NetExec -- multi-protocol lateral movement BloodHound CE -- attack-path graphing Certipy -- AD CS attack Rubeus -- Kerberos abuse (from a Windows foothold) Impacket -- low-level protocol operations
Output: full AD-pentest toolkit at zero license cost.
2. AD audit deliverable (one-shot)
PingCastle (CE) -- risk-scored HTML report Purple Knight -- Semperis IOE assessment (complement)
Output: customer-deliverable AD audit at near-zero cost.
3. Continuous AD posture management
BloodHound Enterprise -- continuous attack-path monitoring
+ pentest toolkit -- on-demand engagement coverageOutput: ongoing AD-security posture for customers wanting more than one-shot audits.
4. AD defense + recovery (high-stakes customers)
Semperis DSP + ADFR -- continuous defense + forest-wide recovery
+ Defender for Identity -- M365-aligned detection layer
+ pentest toolkit -- validation engagementsOutput: deep AD defense-in-depth for ransomware- prone or regulated customers.
Cost Tier
Annual TCO for a customer with ~5,000 AD users.
| Tier | Tooling | Approx Cost |
|---|---|---|
| Free | BloodHound CE + pentest CLIs + PingCastle CE + Purple Knight | $0 + engagement time |
| Mid | BloodHound Enterprise OR Tenable Identity Exposure | $30,000-100,000 / year |
| High | Semperis DSP + ADFR | $100,000-300,000 / year |
| M365 included | Defender for Identity via E5 | (included in M365 E5) |
Tools
12 tools.
BloodHound CE
Open-source AD / Entra ID attack-path graphing platform; Neo4j-backed, SpecterOps-maintained, the de-facto standard for AD pentest.
License: Apache-2.0 (OSS) · Kind: web · Deploy: docker, native · SSO: OIDC, SAML
BloodHound Enterprise
SpecterOps’s commercial managed BloodHound; continuous AD/Entra attack-path monitoring; ticketing + remediation workflow on top of the OSS CE graph.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: OIDC, SAML
Certipy
Python tool for Active Directory Certificate Services (AD CS) attack and enumeration; covers the ESC1-ESC15 attack patterns.
License: MIT (OSS) · Kind: cli · Deploy: native, docker · SSO: none
Impacket
Python library of Windows network protocol implementations from Fortra (formerly SecureAuth Labs); the low-level building blocks of AD pentest tooling.
License: Apache-2.0 (OSS) · Kind: library · Deploy: native, docker, package · SSO: none
Kerbrute
Fast Go-based user enumeration and password spraying tool against Kerberos pre-authentication; the canonical AD username discovery utility.
License: Apache-2.0 (OSS) · Kind: cli · Deploy: native, docker · SSO: none
Microsoft Defender for Identity
Microsoft’s commercial AD/Entra security product (formerly Azure ATP); Entra-native integration; sensor-on-DC architecture.
License: Proprietary (proprietary) · Kind: web · Deploy: saas, native · SSO: OIDC, SAML
NetExec
Successor to CrackMapExec; community-maintained network execution / lateral-movement tool for Windows AD; the canonical AD pentest swiss-army knife.
License: BSD-2-Clause (OSS) · Kind: cli · Deploy: native, docker, package · SSO: none
PingCastle
Free AD security-audit tool from Vincent Le Toux; ranks AD risk against well-known misconfiguration patterns; widely used by auditors.
License: LicenseRef-NPOSL-3.0 (OSS) · Kind: desktop · Deploy: native · SSO: none
Purple Knight
Free Semperis-provided AD/Entra security assessment tool; covers 100+ AD/Entra security indicators of exposure.
License: Proprietary (proprietary) · Kind: desktop · Deploy: native · SSO: none
Rubeus
C# toolset for Windows Kerberos abuse and ticket manipulation; the canonical Kerberos pentest tool on Windows.
License: BSD-3-Clause (OSS) · Kind: cli · Deploy: native · SSO: none
Semperis DSP
Semperis Directory Services Protector; commercial AD/Entra security + recovery platform; IR-focused with attack-path + remediation tooling.
License: Proprietary (proprietary) · Kind: web · Deploy: saas, native · SSO: OIDC, SAML
Tenable Identity Exposure
Tenable’s AD/Entra security platform (formerly Alsid then Tenable.ad); continuous AD/Entra exposure monitoring; integrates with Tenable.io vulnerability mgmt.
License: Proprietary (proprietary) · Kind: web · Deploy: saas, native · SSO: OIDC, SAML