Is EtcSec really free?
Yes. The trial is fully free - no credit card, no signup, no hidden limits on the audit itself. Join the waitlist to be notified as soon as accounts open.
Free · No signup · 7-day expiry
Run an anonymous, browser-based audit across 500+ security checks covering Active Directory and Microsoft Entra ID. No credit card, no tenant changes.
Connects to your AD (LDAP/LDAPS) or Entra ID (Graph API) in read-only, collects findings in 60-120 seconds.
Drop your ad_hc_*.xml file. Optionally add the HTML report for affected entity lists.
Pick the XML report above.
Everything a PingCastle or Purple Knight report gives you - plus Entra ID coverage, MITRE mapping and remediation previews, rendered in your browser.
Weighted score based on critical and high-severity findings across AD and Entra ID, comparable to your peers.
Every detected weakness, sorted by severity and exploitability, with affected users / computers / groups.
Each finding mapped to tactics and techniques so you can brief a SOC or red team in plain language.
Copy-ready PowerShell / Graph scripts for the top findings so you can fix the obvious ones before the meeting.
Executive-ready PDF with severity breakdown, top findings and compliance mapping - no watermark.
ANSSI, NIS2, HDS, ISO 27001 mappings on every finding so you can feed audit files without re-keying.
One-shot AD + Entra ID audits - what the market looks like today
| Feature | EtcSec Trial | PingCastle | Purple Knight | Semperis DSP |
|---|---|---|---|---|
| Active Directory support | Yes | Yes | Yes | Yes |
| Entra ID support | Yes | No | Yes | Partial |
| Agent-less | Yes | Yes | Yes | No |
| Browser-native (no install) | Yes | No | No | No |
| Time to report | < 2 min | 5–15 min | 10–30 min | 15–60 min |
| License | Free | Free | Free (download) | Commercial |
| Signup required | No | No | Form | Contact sales |
Yes. The trial is fully free - no credit card, no signup, no hidden limits on the audit itself. Join the waitlist to be notified as soon as accounts open.
Credentials are encrypted in memory during the audit and wiped immediately after. They are never written to disk. The collector is read-only and open source - you can audit what it does.
PingCastle is a free AD-only scanner you download and run locally. EtcSec Trial runs in the browser, covers Entra ID as well, produces a ranked report with MITRE ATT&CK mapping and compliance annotations, and needs no install. You can also import an existing PingCastle XML/HTML into the trial if you already ran one.
A read-only Microsoft Graph application with Directory.Read.All and UserAuthenticationMethod.Read.All. No password-reset, no write scopes, no Conditional Access changes.
Yes - PDF export is available on trial reports. Join the waitlist to be notified as soon as accounts open.
7 days. After that, all trial data is auto-purged and the share link stops working. Join the waitlist to be notified as soon as accounts open.