# EtcSec > EtcSec is a SaaS identity security audit platform for Active Directory and Microsoft Entra ID, built on ETC Collector, an open-source collector. The catalogue covers 504 detections (346 Active Directory, 158 Microsoft Entra ID), mapped to MITRE ATT&CK, ANSSI, and NIS2. ## Core Pages - [Homepage](https://etcsec.com/): Product overview and positioning. - [Active Directory security audit](https://etcsec.com/active-directory-security-audit): AD audit landing page - Tier 0, Kerberos, delegation, ADCS, privileged access. - [Microsoft Entra ID security audit](https://etcsec.com/entra-id-security-audit): Entra ID / Azure AD audit landing page - Conditional Access, MFA, PIM, app permissions, external identities. - [Free audit](https://etcsec.com/audit): Run the 504-detector audit across AD and Entra ID. - [ETC Collector](https://etcsec.com/collector): Open-source collector - deployment modes, read-only collection, REST API, Community vs Pro. - [Downloads](https://etcsec.com/downloads): Get ETC Collector Community (Apache 2.0) or Pro. - [Vulnerability catalogue](https://etcsec.com/vulnerabilities): Every identity security check, filterable by severity - 504 detections (346 AD, 158 Entra ID). - [Security advisories](https://etcsec.com/security-advisories): Tracked CVE and zero-day advisories for AD, Entra ID, authentication, certificates, and identity infrastructure. - [Pricing](https://etcsec.com/pricing): SaaS pricing and plans, including MSSP volume tiers. - [MSSP program](https://etcsec.com/mssp): Multi-tenant management, white-label reports, recurring AD/Entra audits for consultants and channel partners. ## Comparisons - [PingCastle alternative](https://etcsec.com/pingcastle-alternative): ETC Collector positioned against PingCastle for Active Directory audits. - [Purple Knight alternative](https://etcsec.com/purple-knight-alternative): ETC Collector positioned against Purple Knight for AD and Entra ID audits. ## Active Directory Attack Techniques - [Kerberoasting](https://etcsec.com/blog/kerberoasting-service-account-attacks): Requesting service tickets for SPN accounts to crack password hashes offline. - [AS-REP Roasting](https://etcsec.com/blog/as-rep-roasting-kerberos-preauth): Targeting accounts without Kerberos pre-authentication to recover crackable hashes. - [Golden Ticket](https://etcsec.com/blog/golden-ticket-attack): Forging Kerberos TGTs with a compromised krbtgt hash for persistent domain-wide access. - [Silver Ticket](https://etcsec.com/blog/silver-ticket-attack-active-directory): Forging service tickets with a compromised service account hash. - [ACL abuse & DCSync](https://etcsec.com/blog/acl-abuse-and-dcsync-active-directory): Abusing directory replication rights to extract every password hash in the domain. - [DCShadow](https://etcsec.com/blog/dcshadow-attack-rogue-domain-controller): Registering a rogue domain controller to push malicious replication changes. - [Pass-the-Hash](https://etcsec.com/blog/pass-the-hash-active-directory): Authenticating with a stolen NTLM hash without cracking the password. - [NTLM relay](https://etcsec.com/blog/ntlm-relay-attacks-active-directory): Relaying captured NTLM authentication to impersonate the victim on a second target. - [ADCS ESC1–ESC8](https://etcsec.com/blog/adcs-certificate-attacks-esc1-esc8): Certificate template misconfigurations that let low-privilege users mint admin certificates. - [ADCS ESC9–ESC11](https://etcsec.com/blog/adcs-esc9-esc10-esc11-certificate-escalation): Later-generation AD CS escalation paths beyond the original ESC1–ESC8 set. - [BadSuccessor / dMSA](https://etcsec.com/blog/badsuccessor-dmsa-privilege-escalation-active-directory): Abusing delegated Managed Service Account migration to escalate to Domain Admin. - [Kerberos delegation attacks](https://etcsec.com/blog/kerberos-delegation-attacks): Unconstrained and constrained delegation misconfigurations that let a compromised service impersonate any user. ## AD Hardening, Audit & Compliance - [AD hardening priorities](https://etcsec.com/blog/hardening-active-directory-priorities): What to fix first when triaging a fresh Active Directory audit. - [GPO misconfigurations](https://etcsec.com/blog/gpo-misconfigurations-active-directory): Common Group Policy mistakes that expose credentials or weaken defenses. - [How to audit Active Directory security](https://etcsec.com/blog/how-to-audit-active-directory-security): Methodology for a structured AD security audit end to end. - [AD/Azure compliance mapping](https://etcsec.com/blog/ad-and-azure-compliance-nis2-iso-27001-cis-controls): Mapping identity security controls to NIS2, ISO 27001, and CIS Controls. ## Microsoft Entra ID / Azure AD - [Conditional Access gaps](https://etcsec.com/blog/azure-conditional-access-gaps): Common Conditional Access policy holes that leave sign-ins unprotected. - [Privileged Identity Management (PIM)](https://etcsec.com/blog/azure-privileged-access-pim): Auditing PIM role assignments and activation settings. - [App registration Graph API permissions](https://etcsec.com/blog/entra-app-registration-dangerous-graph-api-permissions): Over-privileged app registrations and dangerous Microsoft Graph API grants. - [MFA alone is not enough](https://etcsec.com/blog/azure-identity-security-mfa-alone-not-enough): Why MFA coverage metrics hide real identity risk in Entra ID. - [How to audit Microsoft Entra ID security](https://etcsec.com/blog/how-to-audit-microsoft-entra-id-security): Methodology for a structured Entra ID security audit end to end. ## Recent Vulnerabilities - [Zerologon (CVE-2020-1472) enforcement](https://etcsec.com/blog/zerologon-cve-2020-1472-enforcement-active-directory): Where Zerologon enforcement mode still gets missed years after the patch. - [August 2026 Patch Tuesday - domain controller RCE](https://etcsec.com/blog/august-2026-patch-tuesday-active-directory-domain-controller-rce): Domain controller remote code execution flaws from the August 2026 Patch Tuesday. ## Company - Legal entity: EtcSec is operated by ETCSEC, a French société par actions simplifiée à associé unique (SASU), RCS Evry 108 548 074. - Trademark: EtcSec™ - French trademark n° 5277825 (figurative mark, class 42), filed 13/07/2026, published in the BOPI (Bulletin officiel de la propriété industrielle) n° 26/32 of 07/08/2026; opposition period open until 07/10/2026. - [About](https://etcsec.com/about): Company overview. - [Founder - Younes Azabar](https://etcsec.com/team/yazabar): Founder of EtcSec and ETC Collector, infrastructure & automation engineer specializing in identity security. - [Roadmap](https://etcsec.com/roadmap): Public feature roadmap - vote on features, suggest ideas. - [Contact](https://etcsec.com/contact): Sales and support contact. - [Blog](https://etcsec.com/blog): Identity security articles and guides - ~123 published posts per locale.