A lightweight Docker container with enterprise-grade security. Multi-platform support for AD, Azure, Intune, and Exchange with one-command installation.
Multiple layers of security ensure your identity data stays protected across all platforms.
Tokens are limited to a configurable number of uses (3-100). Once exhausted, the token is invalidated - preventing theft and unauthorized sharing.
Default expiry of 1 hour (not 365 days like legacy systems). Automatic cleanup runs every 5 minutes to remove expired tokens from the database.
Built-in protection against abuse with 100 requests/minute per client. Prevents brute-force attacks and resource exhaustion.
RATE_LIMIT env varBinds to localhost (127.0.0.1) by default. Your collector is never exposed to the internet unless explicitly configured.
Three deployment modes for principle of least privilege:
Runs as non-root user (UID 1001) with minimal attack surface. LDAP injection prevention through parameter escaping and validation.
Our interactive installer handles everything: OS detection, Docker installation, LDAP configuration, token generation, and Azure setup. No manual configuration files needed.
For air-gapped environments or maximum security requirements, use our local export workflow. Generate reports without ever exposing your collector to the network.
Set your token to single-use or limited uses for maximum security.
Execute the audit directly on the server with no network exposure.
Transfer the JSON file via your secure channel (USB, SFTP, encrypted email).
Upload the JSON to EtcSec for analysis and PDF report generation.
Collector never needs to be accessible from outside the server
Single-use tokens expire immediately after the audit
Complete JSON export with all 150+ vulnerability checks
Complete REST API for security auditing across all identity platforms and management operations.
Token usage, expiration, quota status
CRUD operations, password reset, group membership, enable/disable accounts
Create, delete, add/remove members, list groups and memberships
Organizational units CRUD, health check, connection test
47 total endpoints for complete identity management and security auditing across all platforms
Deploy the collector in minutes and start your first security audit today.