Skip to main content

Health Check Rules

Bulwark evaluates over 100 built-in security rules against collected AD data. Each rule checks for a specific misconfiguration, vulnerability, or hygiene issue and produces a finding with a severity level and affected objects.

Rule Categories

Functional Level

Checks whether the domain and forest functional levels are current. Outdated levels miss security features available in newer AD versions.

Domain Controller Health

  • OS version currency (end-of-life detection)
  • FSMO role holder identification
  • Reachability and SMB/Kerberos settings
  • Print spooler exposure
  • LDAP signing and channel binding

Account Hygiene (Stale Objects)

Privileged Account Hygiene

Trust Relationships

  • Trust type and transitivity analysis
  • SID filtering status
  • Cross-forest trust risks
  • Reachable domain enumeration

Anomalies

GPO Analysis

  • Audit policy settings (simple and advanced)
  • LSA policy configuration
  • WSUS settings
  • Defender ASR rules
  • Screen saver lock-out policies
  • Firewall rules
  • Event forwarding subscriptions
  • UNC path hardening
  • Terminal Services configuration

DNS

  • AD-integrated DNS zone enumeration
  • Zone configuration analysis

Rule Evaluation

Rules are evaluated in sequence after data collection completes:
Each triggered rule produces a RuleAnalysisResult containing:

Scoring Algorithm

The global score is calculated from four category scores, each representing a dimension of AD security: Each triggered rule contributes its points value to the appropriate category. The global score is derived from the weighted combination of category scores, normalized to 0–100.