Real attack paths, not just findings. TealHound builds an actual attack-path graph from your domain's own group memberships and ACLs, then searches it - arbitrary depth, not a fixed 2-hop check - for every route a low-privilege account has to Domain Admins. Map the way in before someone else does.
Active Directory Security Posture already scans for the misconfigurations attackers exploit, with a bounded check for escalation paths reachable in a couple of hops. TealHound is the deeper option above it: a real in-memory attack-path graph built from every group membership and every dangerous ACL across your domain, searched hop by hop - up to six hops deep - toward Domain Admins, Enterprise Admins, Schema Admins, and Administrators, the way an attacker's own reconnaissance tooling would. On top of that graph search, TealHound carries a broader Purple Knight-style indicator library than Standard AD scanning covers: Kerberoastable and AS-REP-roastable accounts, dangerous delegation, DCSync rights, GPO delegation, ADCS (ESC1-style) vulnerable certificate templates, a stale krbtgt password, Pre-Windows 2000 Compatible Access, and LAPS coverage gaps - every finding, indicator or full attack path alike, in one unified list with one Domain Risk Score. Export to CSV, Excel, HTML, XML, or the clipboard, and schedule any of it to run - and email itself to you - unattended.
The real app. Click to zoom in, hover the markers to see what each part does.
Hover a marker for details, or click the screenshot to zoom in.
Builds a real in-memory graph from group memberships and dangerous ACLs across every group and computer in your domain, then runs a breadth-first search - up to 6 hops, not a fixed 2-hop check - from every node toward Domain Admins, Enterprise Admins, Schema Admins, and Administrators.
Every finding - indicator or full attack path - rolls up into one 0-100 score, graded A-F, with a diminishing-returns weighting so one Critical path matters more than a pile of Low-severity noise.
Finds service accounts with an SPN set (and flags weak RC4-only encryption specifically) and accounts with Kerberos preauthentication disabled - the two most common offline password-cracking footholds in AD.
ESC1-style certificate template misconfigurations, GPO delegation, a stale krbtgt password, Pre-Windows 2000 Compatible Access, and LAPS coverage gaps - on top of DCSync rights and the same bounded escalation check Active Directory Security Posture offers.
Build your own filters against any attribute - including Path Summary and Hop Count on graph-search results - or drive it all from scripts with TealHound.exe --run-report ... and --run-query ....
Save any query - including a full graph search - as a recurring report via Windows Task Scheduler, with the result optionally emailed to you the moment a new path to Domain Admins appears.
Pick how much automation you need, then choose once-off or monthly billing. TealHound licenses per machine, not by domain size.
One-time payment - yours to keep, no subscription.
For the quick wins.
Kerberoastable/AS-REP-roastable/delegation findings, krbtgt password age, Pre-2000 Compatible Access, and the Domain Risk Score, on screen, free at every tier.
For account & hygiene checks.
Everything in Standard, plus privileged-group/trust/hygiene, LAPS-coverage, and GPO-delegation findings, and CSV/Text export.
Matches ASP's full feature set.
Everything in Standard+, plus DCSync-rights and the bounded 2-hop escalation check, custom queries, and richer export formats.
For the real attack paths.
Everything in Advanced, plus the full arbitrary-depth attack-path graph search, ADCS ESC1 detection, scheduled & emailed reports, and a headless CLI.
All plans are billed in USD. Prices in other currencies are an approximate conversion for your reference, based on indicative exchange rates - your invoice will be issued in USD.
Standard covers the cheap, high-signal checks: Kerberoastable and AS-REP-roastable accounts, unconstrained/constrained delegation, krbtgt password age, Pre-Windows 2000 Compatible Access, and the overall Domain Risk Score - all on screen. No privileged-group/trust findings, graph search, or export at this tier, by design.
Best for: A fast first answer to "how exposed are we, right now?"
Standard+ adds privileged-group/trust/hygiene findings, LAPS coverage gaps, GPO delegation findings, plus CSV/Text report export. Everything from Standard is included.
Best for: Regular hygiene reviews of who's actually still privileged.
Advanced adds DCSync-rights findings and the same bounded 2-hop escalation check Active Directory Security Posture offers - by itself, Advanced already matches ASP's entire feature set - plus custom queries and richer export formats. Everything from Standard+ is included.
Best for: Teams who want ASP-equivalent coverage inside TealHound's broader indicator set.
Professional unlocks the real differentiator: the full, arbitrary-depth attack-path graph search to Domain Admins (not bounded to 2 hops), and ADCS (ESC1-style) certificate template findings - plus scheduled/emailed reports and a headless CLI (TealHound.exe --run-report, --run-query, --run-custom-query). Everything from Advanced is included.
Best for: Security teams who need the real map of every route to Domain Admins, not just a bounded sample of it.
Prices shown are a suggested starting point, not final quotes - contact us to confirm your plan.