ACTIVE DIRECTORY & ENTRA IDscanning…

Your directory is a graph.Attackers already walk it.

GrexID maps identity risk, shows which permission to remove first, and previews the impact before production changes.

0/10
ransomware attacks target Active Directory
Semperis, 2024
0%
of breaches involve stolen credentials
Verizon DBIR, 2025
0%
of attacks compromise a domain controller
Microsoft, 2025
$0
average global cost of a breach ($4.44M)
IBM, 2025
/ 02HOW IT WORKS

Close the loop on identity risk.

A continuous workflow for defining the desired state, understanding exposure, improving safely and watching for privilege abuse.

01DESIRED STATE

Define the target

Agree what healthy privilege, ownership and access should look like across AD and Entra ID.

02COLLECT

Gather the evidence

Collect identity, relationship and permission data without changing production.

03ANALYZE

Find risk and escalation

Map risky permissions, attack paths and escalation routes to the assets that matter.

04IMPROVE

Choose the right fix

Propose improvements with security impact and operational impact shown before teams act.

05MONITOR

Keep the loop closed

Monitor change continuously and detect privilege abuse before it becomes a new path.

/ 03SAFE REMEDIATION

Simulate the fix. Protect production.

Before removing a permission, GrexID shows which attack paths disappear and whether legitimate access keeps working.

RISK PATHBefore
svc_backup
IT-Admins
DC-01$
Domain Admin
Permission to reviewGenericAll on DC-01$
IMPACT PREVIEWAfter
Risk reduction-63%
Paths blocked03
Broken dependencies0
The escalation route is removed while production dependencies stay intact.
/ 04CAPABILITIES

Seven capabilities. One remediation workflow.

The core product surface: quantify identity risk, understand the path, simulate safe fixes and monitor privilege abuse after the change.

NEW
AI LAYER · ON TOP OF THE HEURISTICS

Does this privilege actually make sense?

Heuristics find what's dangerous. The AI layer reasons about your roles and ownership model to find what's unjustified — the access nobody can explain, the rights that drifted, the privilege no role should hold.

RISK.SCORE

Risk on every identity

Score users, groups and permissions by exposure, scope and proximity to Domain Admin so teams know what matters first.

PATH.MAP

Attack-path priority

Map how privilege escalates across AD and Entra ID, then rank the routes that create real identity risk.

SIM.IMPACT

Safe change simulation

Preview the security gain and operational blast radius before a permission is removed from production.

DIRSYNC

Privilege abuse monitoring

Watch permission, group and descriptor changes in near real time and catch escalation from its first hop.

ACE.SCAN

Permission audit

Inspect dangerous rights such as GenericAll, WriteDACL and DCSync with risk classification and remediation guidance.

API + HOOKS

Risk events where you work

Push scored risk and change events into SIEM, ticketing or automation when another system needs to act.

Want to see which permissions GrexID would remove first in your directory?

Show me my paths
/ 05SEE IT IN ACTION

Start with risk. Drill into the path.

Move through the product the way teams use it: prioritize identity risk, inspect the path, prove controls and show progress.

SCREEN 01

Find the path

Walk the graph from any low-privileged account to Domain Admin, hop by hop.

GrexID Attack Path Explorer — graph view of an escalation path from a low-privileged account to Domain Admin
/ 06100% EUROPEAN BY DESIGN

Choose the model. Keep control.

GrexID runs where your security and compliance model needs it: on-premise, SaaS, or an agentless first assessment that scales into continuous monitoring.

GrexID is a European company, built and supported by a team inside the EU and running end to end on European infrastructure — hosting, email, analytics and backups included. Risk scoring and semantic analysis execute within your perimeter, so no directory data and no prompts ever reach a third-party AI API. Data sovereignty here is architecture, not a hosting region you pick at checkout.

European companyEU-only infrastructureEU development & supportNo third-party AI APIs
01

On-premise

Deploy inside your infrastructure with Docker Compose. Directory data stays under your control.

02

SaaS

Use a managed service when speed matters, with European hosting and the same identity-risk workflow.

03

Agentless first

Start with an assessment and get results in hours, then add live monitoring when you need it.

04

Local AI

Run risk scoring and semantic analysis inside your perimeter so prompts and directory data do not leave.

SEE YOUR DIRECTORY

Which permissions would GrexID remove first?

Request a guided demo and we'll walk through the attack paths, safe-remediation preview and environment model that match your directory.

We use these details only to answer your request and arrange a demo. They are handled by GrexID and its EU-based email provider, never sold or shared for other purposes. See the Privacy Policy.