Open-source project
netwrix/pingcastle avatar
netwrix/pingcastle

PingCastle: Active Directory Risk Scoring Without the Full Audit

PingCastle - Get Active Directory Security at 80% in 20% of the time

2,954 stars352 forksC#NOASSERTION

At a glance

What is it?
PingCastle is a C# tool that scores the risk of an Active Directory domain and produces a report in minutes. It is built for internal IT and security teams, and its Non-Profit OSL licence shapes who can use it.
Who is it for?
Adopt PingCastle if you own an Active Directory domain and need a repeatable risk score you can hand to management or an auditor, and if your use is internal. Do not adopt it if you intend to resell the assessment or embed it in a paid product without a commercial licence, and do not treat the healthcheck score as a full audit.
Can I use it commercially?
Check first. The repository uses a licence we do not classify automatically, so read its LICENSE file before any commercial use.
Is it still maintained?
Yes. The repository last received commits 50 days ago.
What is it written in?
Mainly C#, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 27, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What PingCastle scores, and who the score is for

PingCastle answers one question: how risky is this Active Directory domain right now? The README frames the design goal as identifying 80% of critical security issues in 20% of the time a traditional assessment would take. That trade-off is the whole product. It is not a vulnerability scanner that enumerates every misconfiguration; it is a scoring instrument that ranks a domain against a risk assessment methodology and a maturity framework.

The intended reader is the person who has to answer for the domain: an IT admin, a security professional, or a CISO who needs a number and a report rather than a raw dump. The topics attached to the repository (CISO, NIST, HIPAA, SOX, STIG, DoD) show the audience it is aimed at. Those are compliance and governance labels, not technical features. If your job is to explain Active Directory risk to people who do not read LDAP output, that framing is the point.

The healthcheck, the trust map, and the other modes

The tool is driven from an interactive menu, and the README prints it. The first entry, healthcheck, scores the risk of a domain. The conso mode aggregates multiple reports into a single one, which is how you get a domain-wide or estate-wide view instead of one report per domain. The carto mode builds a map of all interconnected domains, and the README notes that a report can be generated on other domains by using the existing trust links. That is the mechanism that makes the tool useful in a forest rather than a single domain: it walks trust relationships.

The remaining modes are narrower. entraid scores the risk of Entra ID, scanner performs specific security checks on workstations, and export dumps users or computers. The export mode is the one people overlook. It turns the tool into a directory inventory utility, which is a different job from scoring risk.

plain
  1-healthcheck-Score the risk of a domain
  2-entraid    -Score the risk of Entra ID
  3-conso      -Aggregate multiple reports into a single one
  4-carto      -Build a map of all interconnected domains
  5-scanner    -Perform specific security checks on workstations
  6-export     -Export users or computers
  7-advanced   -Open the advanced menu

Two things about that menu are worth flagging. The banner in the README shows an end-of-support date of 2027-08-31 for the version it was captured from. That is a hard planning constraint, not a footnote. And the menu itself says other command line switches exist, with --help as the entry point. The README does not enumerate them, so the CLI surface is only partially documented in the repository.

Installing PingCastle and running a first report

PingCastle is a C# project, and the README gives the build path plainly: it can be built from Visual Studio 2012 to Visual Studio 2022. The repository root holds PingCastle.sln, so the solution file is the entry point for a build. There is no package manager install documented in the README, and no dotnet CLI install command is given there. If you want the built tool rather than a build from source, the README points to https://www.pingcastle.com for documentation and to the Netwrix community and GitHub issues for support.

If you are building from source, open the solution and build it:

bash
git clone https://github.com/netwrix/pingcastle.git
cd pingcastle

Then open PingCastle.sln in Visual Studio (2012 through 2022 are the stated range) and build. The output is the PingCastle executable, which is what the interactive menu belongs to. The README does not document a published binary name or a download URL beyond the project homepage, so treat the homepage as the place to check for a release build.

Once you have the executable, run it with no arguments to get the interactive menu, then pick healthcheck. The README's own example of the menu is what you should see:

plain
What do you want to do?
=======================
Using interactive mode.
Do not forget that there are other command line switches like --help that you can use
  1-healthcheck-Score the risk of a domain

Select 1 and the tool scores the risk of the domain you point it at. The README says the report is produced in a matter of minutes. For a first run, do it against a non-production domain or a lab, because the healthcheck reads directory configuration and you want to see the report shape before it lands in front of an auditor.

The README also shows --help as the way to discover the non-interactive switches. If you need to script the run, that is where to look, because the repository does not list the flags in the README.

Where PingCastle is the wrong tool

The 80/20 promise is also the limitation. By design the tool does not pursue exhaustive evaluation, so a clean PingCastle score is not evidence that a domain is secure. It is evidence that the issues the methodology checks for were not found. Anything outside that methodology is invisible to the score, and the README does not publish the full check list in the repository. If your requirement is a complete configuration audit with evidence per control, this is the wrong instrument.

The second limitation is licensing, and it is stricter than the word open source suggests. The Open Source Edition is under the Non-Profit Open Software License 3.0. The README states that organisations may use it internally without purchasing a licence, including for-profit companies and their contracted IT service providers. What you cannot do is monetize PingCastle or offer it as a paid service to others. If you are a consultancy that wants to sell Active Directory assessments, the open source edition is not the licence you need.

The third is the support boundary. The README splits the audience: open source users go to the Netwrix community or GitHub issues, while customers of the commercially available edition go to Netwrix technical support. If you need a response-time commitment, the open source path does not carry one. And the end-of-support date shown in the banner means a version you standardise on today has a shelf life you have to track.

How it compares with a general-purpose vulnerability scanner

The obvious alternative is a general vulnerability management platform that also covers Active Directory. The difference is in what each one optimises. A vulnerability scanner enumerates findings across hosts, operating systems and applications, and its Active Directory coverage is one module among many. PingCastle does one subject and does it as a scored assessment: healthcheck produces a risk score for a domain, conso merges reports across domains, and carto maps trust relationships between them.

That means the two tools answer different questions. A scanner tells you what is wrong on each machine. PingCastle tells you how risky a domain is as a whole, and it follows trust links to reach domains you did not point it at directly. If you already run a scanner and get a list of Active Directory findings, PingCastle does not replace it; it gives you a domain-level score and a maturity view on top. If you have no scanner and no budget, PingCastle covers the domain-level question and nothing else.

The practical difference in effort is also real. A scanner deployment means agents or credentialed scans across the estate. PingCastle is a single executable you run against a domain, and the README describes the result as arriving in minutes. That is a much smaller footprint, and a correspondingly narrower answer.

Licence, upgrade and maintenance cost

The repository is not archived and the last push was on 2026-08-11, the same date as the 4.0.0.20 release. Previous releases came on 2026-06-09 and 2026-05-20, so the project is shipping on a cadence of roughly one to three months. That is a real upgrade cost: a 4.0.0.20 release in August 2026, a 3.5.1.33 in June, and a 3.5.1.31 in May means you should expect to test new builds rather than pin one and forget it.

On licence, the split is clear in the README and worth restating because it decides adoption. Internal use, including in a for-profit company and by its contracted IT service providers, is permitted under the Non-Profit OSL 3.0 without a purchase. Incorporating PingCastle into commercial services or products, or generating revenue by providing PingCastle-based services to other organisations, requires a commercial licence. The repository's LICENSE.md and license.rtf are the authoritative files; the README is a summary and not legal advice. If your use sits anywhere near the commercial line, read the licence text itself.

The bundled components are all MIT licensed (Bootstrap, JQuery, vis.js, popper.js, Bootstrap Table, Bootstrap Table Export, Table Export, Font Awesome), which keeps the dependency side simple. The licence risk is in PingCastle itself, not its libraries.

Editorial conclusion

Adopt PingCastle if you own an Active Directory domain and need a repeatable risk score you can hand to management or an auditor, and if your use is internal. Do not adopt it if you intend to resell the assessment or embed it in a paid product without a commercial licence, and do not treat the healthcheck score as a full audit. Before rolling it out, verify the end-of-support date printed in the banner, confirm the report output with your own eyes on a test domain, and check whether your organisation's use falls under the Non-Profit OSL or needs the commercial licence.

Frequently asked questions

Is PingCastle still free?

The Open Source Edition is licensed under the Non-Profit Open Software License 3.0. Organisations may use it internally without purchasing a licence, even in for-profit companies, including through contracted IT service providers. You cannot monetize PingCastle or offer it as a paid service to others under that licence.

How do I install PingCastle?

The README describes PingCastle as a C# project that can be built from Visual Studio 2012 to Visual Studio 2022, using PingCastle.sln at the repository root. The README does not document a package manager install, and points to https://www.pingcastle.com for documentation.

How do I run a PingCastle report?

Run the executable with no arguments to get the interactive menu, then choose 1-healthcheck to score the risk of a domain. The README states the report is produced in a matter of minutes, and that reports can be generated on other domains by using the existing trust links.

What is PingCastle used for?

It scores the risk of an Active Directory domain using a risk assessment methodology and maturity framework. The README states the goal is identifying 80% of critical security issues in 20% of the time traditional assessment methods take. Other modes cover Entra ID, report aggregation, trust mapping, workstation checks and user or computer export.

What is Netwrix PingCastle?

It is the Netwrix-maintained edition of PingCastle, published at github.com/netwrix/pingcastle. The README directs open source users to the Netwrix community or GitHub issues, and customers of the commercially available edition to Netwrix technical support.

Official sources

  1. Issues
  2. netwrix/pingcastle on GitHub
  3. Project website
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/netwrix-pingcastle.svg)](https://hysenlabs.com/projects/netwrix-pingcastle)