← Back to catalog
Security

HERALD

AD account roster & access-level review.

Answers the two questions a customer security review asks — what authentication controls are in place, and who has an account and what can each of them do? Scores the domain password and lockout policy (and any fine-grained PSOs) as Strong / Acceptable / Weak in paste-ready prose, expands effective nested group membership, and classifies every account as Domain Administrator, Delegated Administrator, Elevated (custom group), or Standard User with review flags. Exports HTML plus a review CSV the customer can mark up. Read-only.

Quick Launch

Run HERALD

Run in an elevated PowerShell window. Downloads herald.ps1 from CursedTechnocrat/TechnicianToolkit and executes it.

Set-ExecutionPolicy Bypass -Scope Process -Force; $f="$(Get-Location)\herald.ps1"; irm https://raw.githubusercontent.com/CursedTechnocrat/TechnicianToolkit/main/herald.ps1 -OutFile $f; [IO.File]::WriteAllText($f,[IO.File]::ReadAllText($f,[Text.Encoding]::UTF8),[Text.UTF8Encoding]::new($true)); & $f
Category
Security
Identifier
HERALD
Tags
active-directory, access-review, audit