Forestall
Forestall maps the identity attack surface across your directory and your clouds, the way an attacker maps it.
The alternative
Semperis and Tenable Identity Exposure at the enterprise end, both built around Active Directory. Purple Knight is free and runs once.
At a glance
- Delivery
- Agentless. Read-only connectors, no endpoint agent
- Privileges
- No Domain Admin or equivalent required
- Coverage
- Active Directory, Entra ID, Azure, Microsoft 365, AWS IAM, Google Cloud IAM, Google Workspace
- Standards
- CIS, STIG, Microsoft baselines, MITRE ATT&CK
- Outputs
- Attack path graphs, prioritised findings, PDF and CSV reports per audience
A configuration that was correct yesterday can be wrong today, and the path that matters usually crosses from the directory into a cloud.
A directory drifts through ordinary administration rather than through mistakes. A group gains a member. A delegation is granted for a migration and never withdrawn. A service account is given rights it needed once. Each change is defensible on its own, and the privilege path they add up to is invisible from the admin console. That is why continuous assessment and a point-in-time scan are different products rather than different schedules.
The second difference is where it looks. Active Directory, Entra ID, Azure, Microsoft 365, AWS IAM, Google Cloud IAM and Google Workspace are assessed together. Almost no organisation keeps identity in one place any more, and the useful attack paths run through the seam between two of them, which is exactly the part reviewed by different people at different times. The same applies to the accounts that are not people. Service accounts, tokens and the identities now being issued to automated agents outnumber staff in most estates and get reviewed least, and they are assessed alongside human accounts rather than in a separate exercise.
The third difference is what it asks for before it can start. Collection is read-only and runs through connectors rather than an endpoint agent, and it does not need Domain Admin or an equivalent. That sounds like a deployment detail and it is actually the commercial one. A product that asks for privileged access to the directory it is auditing goes into a security review that takes a quarter. One that asks for read-only goes in the same week.
How it works
- Connects read-only to the directory and to the cloud identity providers in use
- Maps accounts, groups, policies and the relationships between them
- Surfaces privilege escalation paths, shadow admins and rights nobody needs
- Checks group policy against CIS, STIG and Microsoft baselines
- Searches file shares for credentials left in the open
- Reports arrive per audience, with the remediation step attached
Who it is for
- Any organisation whose access model runs on Active Directory
- Estates where identity is split across a directory and one or more clouds
- Security teams preparing for ransomware rather than responding to it
- Regulated finance and public sector organisations under periodic audit
What we can point to
- Presented to regional security leaders at the event ICM led in Dubai, September 2025
Where it sits
Identity security. Privileged access management and multi-factor authentication belong in the same area, and we do not carry a product for either yet.
