7 Minute Security

← 7 Minute Security7. Aug. · 32 Min.

7MS #734: Insight Recon

7MS #734: Insight Recon7. Aug.32 Min.

Hey friends! Today's episode is a two-parter: some security stuff up front, and then a big ol' personal celebration on the back half. If you're strictly here for the security bits, I love you and you're free to bail after the first half. If you're here for both, God bless you.

Part 1: Kicking the tires on Insight Recon

What it is: Insight Recon is an Active Directory security assessment tool out of Heath Adams' new venture, Breach Point. I signed up for early access a while back, finally got a login, and took it for a spin this week in my GOAD lab. Not a sponsor, not an ad — just a tool I was curious about. Watch it in action: I covered the install, a couple of hiccups I hit, and some of the report output in this week's TuesdayTOOLSday video over at 7MinSec.club. The setup: Log into the portal, grab the installer, run it on a domain-joined box, then pick whether you want to scan as your current user or specify creds. Say go, wait a few minutes, and your report card shows up on the dashboard. My two nitpicks (and they're mine, not necessarily yours): The download does a full-blown install with an install footprint, and the raw scan data gets shipped back up to Insight Recon so you can view your report. I can't help but compare everything in this space to PingCastle, where you unzip, run the EXE, and your HTML report is sitting right there on the C drive — nothing leaves the building. As someone who tries to be a good data janitor and nuke assessment data after reports go out, cloud storage is just one more place I've got to remember to go scrub. What I really liked: The remediation guidance is legit. I clicked into a few of the critical findings — some ESC/ADCS stuff especially — and it walked me through exactly what to change, why an attacker cares, how to verify the fix afterward, and where to go read more. There's also a "quick wins" view that pares the big list down to the biggest security impact for the least effort. The dashboard and the slide-out detail panes are genuinely pleasant to use. Why this matters even for offense-only folks: We're mostly on the offensive side with a little blue team consulting — we don't do hands-to-keyboard remediation. But I think you become a better pentester when you can speak confidently at delivery time about not just what to fix, but the gotchas that might bite them along the way. Pricing: On the podcast I guessed "a few thousand a year" and admitted that number may have come straight out of my bum cheeks. Turns ou