Health Check Rules
Bulwark evaluates over 100 built-in security rules against collected AD data. Each rule checks for a specific misconfiguration, vulnerability, or hygiene issue and produces a finding with a severity level and affected objects.Rule Categories
Functional Level
Checks whether the domain and forest functional levels are current. Outdated levels miss security features available in newer AD versions.Domain Controller Health
- OS version currency (end-of-life detection)
- FSMO role holder identification
- Reachability and SMB/Kerberos settings
- Print spooler exposure
- LDAP signing and channel binding
Account Hygiene (Stale Objects)
Privileged Account Hygiene
Trust Relationships
- Trust type and transitivity analysis
- SID filtering status
- Cross-forest trust risks
- Reachable domain enumeration
Anomalies
GPO Analysis
- Audit policy settings (simple and advanced)
- LSA policy configuration
- WSUS settings
- Defender ASR rules
- Screen saver lock-out policies
- Firewall rules
- Event forwarding subscriptions
- UNC path hardening
- Terminal Services configuration
DNS
- AD-integrated DNS zone enumeration
- Zone configuration analysis
Rule Evaluation
Rules are evaluated in sequence after data collection completes:RuleAnalysisResult containing:
Scoring Algorithm
The global score is calculated from four category scores, each representing a dimension of AD security:
Each triggered rule contributes its
points value to the appropriate category. The global score is derived from the weighted combination of category scores, normalized to 0–100.
