Source-Available AD & Entra ID
Security Auditor
ETC Collector is a source-available (FSL-1.1-ALv2) security auditor for Active Directory and Microsoft Entra ID, written in Go. Multiplatform (Linux, Windows, macOS, Docker), with over 450 security checks, ADCS ESC1-ESC11 detection, and attack path graphs. Converts to Apache 2.0 automatically two years after each release.
Community: free for everyone, including companiesPro: adds advanced detectors and Azure Risk detections — included with the ETCSec SaaS subscription
Why ETC Collector
Built for speed & coverage
Everything you need for AD & Entra ID identity security auditing
Security Checks
AD + Entra ID
Active Directory checks across 14 categories · Entra ID checks across 9 categories
Concurrent By Design
Concurrent LDAP and Microsoft Graph API queries via a goroutine pool — no sequential bottlenecks
Attack Path Analysis
Identify privilege escalation vectors
Source-Available License
FSL-1.1-ALv2 — free for everyone, including companies. Every version becomes Apache 2.0 two years after it is published.
Quick Start
Up & running in one command
Single static binary — no runtime dependencies
# Download from https://etcsec.com/downloads etc-collector audit ad --ldap-url ldaps://dc.example.com
Install
One-liner script or grab the binary for your OS
Configure
Set your AD/Azure credentials in config.yaml or via flags
Audit
Run and get structured JSON results in seconds
Frequently Asked Questions
Common questions
Pro Edition
Go further with Pro
The Community Edition is source-available (FSL-1.1-ALv2), free for everyone — individuals and enterprises. It converts automatically to Apache 2.0 two years after each release. Pro unlocks advanced detectors, ADCS full taxonomy, additional Azure Risk detections, and an AI-native MCP server integration. Included with the ETCSec SaaS subscription.
ETCSec SaaS
Multi-tenant platform
Dashboards, historical trending, automated scheduling, and team collaboration — all backed by ETCSec SaaS.
Explore ETCSec SaaS