@@ -37,7 +37,7 @@ be extended by purchasing additional support.
3737The PingCastle tool is just one part of a global methodology aiming at
3838securing Active Directories.
3939
40- ![ ] ( /img/product_docs/pingcastle/basicuser/image1.png )
40+ ![ ] ( /img/product_docs/pingcastle/basicuser/image1.webp )
4141
4242You can get more information about this methodology by visiting the
4343website https://www.pingcastle.com/methodology/
@@ -46,7 +46,7 @@ website https://www.pingcastle.com/methodology/
4646
4747The following sections describe how to use PingCastle.
4848
49- ![ https://www.pingcastle.com/wp/wp-content/uploads/2018/09/pingcastle_dezipped-1.png ] ( /img/product_docs/pingcastle/basicuser/image2.png )
49+ ![ https://www.pingcastle.com/wp/wp-content/uploads/2018/09/pingcastle_dezipped-1.webp ] ( /img/product_docs/pingcastle/basicuser/image2.webp )
5050
5151## Requirements
5252
@@ -96,14 +96,14 @@ run under the .Net framework where it has been compiled (and not the
9696other .Net framework). Windows does show a popup to suggest the
9797installation of the missing framework.
9898
99- ![ ] ( /img/product_docs/pingcastle/basicuser/image3.png )
99+ ![ ] ( /img/product_docs/pingcastle/basicuser/image3.webp )
100100
101101## How it works
102102
103103PingCastle is a standalone program (not requiring installation) which
104104produces reports for human or machine.
105105
106- ![ ] ( /img/product_docs/pingcastle/basicuser/image4.png )
106+ ![ ] ( /img/product_docs/pingcastle/basicuser/image4.webp )
107107
108108PingCastle reads its own machine readable reports to build analysis or
109109dashboard.
@@ -114,7 +114,7 @@ PingCastle Basic Edition is provided in a zip file. You need a program
114114such as 7zip or the native unzip program to decompress the file.
115115
116116![ A screenshot of a computer Description automatically
117- generated] ( /img/product_docs/pingcastle/basicuser/image5.png )
117+ generated] ( /img/product_docs/pingcastle/basicuser/image5.webp )
118118
119119For the most operating systems, PingCastle does not need any more
120120actions.
@@ -129,7 +129,7 @@ PingCastle.exe.config
129129
1301301 . The best way is just to double click on PingCastle.exe
131131
132- ![ https://www.pingcastle.com/wp/wp-content/uploads/2018/09/quickstart.png ] ( /img/product_docs/pingcastle/basicuser/image6.png )
132+ ![ https://www.pingcastle.com/wp/wp-content/uploads/2018/09/quickstart.webp ] ( /img/product_docs/pingcastle/basicuser/image6.webp )
133133
134134This run the program in a mode called the "interactive mode.
135135
@@ -144,7 +144,7 @@ other files ending with ".exe"
144144
145145PingCastle can display its help on a command line.
146146
147- ![ https://www.pingcastle.com/wp/wp-content/uploads/2018/09/cmd-pingcastle-help.png ] ( /img/product_docs/pingcastle/basicuser/image7.png )
147+ ![ https://www.pingcastle.com/wp/wp-content/uploads/2018/09/cmd-pingcastle-help.webp ] ( /img/product_docs/pingcastle/basicuser/image7.webp )
148148
149149Indeed PingCastle has a lot of switches which can be displayed using the
150150command line:
@@ -174,7 +174,7 @@ The report can be generated in the interactive mode by choosing
174174"healthcheck" or just by pressing Enter. Indeed it is the default
175175analysis mode.
176176
177- ![ ] ( /img/product_docs/pingcastle/basicuser/image8.png )
177+ ![ ] ( /img/product_docs/pingcastle/basicuser/image8.webp )
178178
179179It can be run using the command:
180180
@@ -193,7 +193,7 @@ active directories. It is designed to be computer read (PingCastle).
1931932 . The xml file is required for all analysis, including global overview
194194 or cartography.
195195
196- ![ https://www.pingcastle.com/wp/wp-content/uploads/2018/09/img1.png ] ( /img/product_docs/pingcastle/basicuser/image9.png )
196+ ![ https://www.pingcastle.com/wp/wp-content/uploads/2018/09/img1.webp ] ( /img/product_docs/pingcastle/basicuser/image9.webp )
197197
198198The report is divided in 3 parts:
199199
@@ -212,17 +212,17 @@ The Score is computed by the maximum of the 4 sub scores:
212212- Security anomalies -- Everything that doesn't fit into the previous
213213 categories and related to security checks
214214
215- ![ ] ( /img/product_docs/pingcastle/basicuser/image10.png )
215+ ![ ] ( /img/product_docs/pingcastle/basicuser/image10.webp )
216216
217217The details of the rules triggered is shown with some indication and the
218218number of points calculated (the total cannot be above 100).
219219
220- ![ ] ( /img/product_docs/pingcastle/basicuser/image11.png )
220+ ![ ] ( /img/product_docs/pingcastle/basicuser/image11.webp )
221221
222222When the rule is clicked, a short explanation of the rule is shown with
223223some indication on how to solve the situation.
224224
225- ![ ] ( /img/product_docs/pingcastle/basicuser/image12.png )
225+ ![ ] ( /img/product_docs/pingcastle/basicuser/image12.webp )
226226
227227** 2 -- General information**
228228
@@ -233,12 +233,12 @@ some indication on how to solve the situation.
233233- The Detail zone shows general information about users, computers,
234234 trusts, group policies, ...
235235
236- ![ ] ( /img/product_docs/pingcastle/basicuser/image13.png )
236+ ![ ] ( /img/product_docs/pingcastle/basicuser/image13.webp )
237237
238238Some information can be seen in detail by clicking on the associated
239239link. It contains data to help identify the underlying objects.
240240
241- ![ ] ( /img/product_docs/pingcastle/basicuser/image14.png )
241+ ![ ] ( /img/product_docs/pingcastle/basicuser/image14.webp )
242242
243243## Perform domain discovery
244244
@@ -250,7 +250,7 @@ All reachable domains will be scanned, the reachable mode will be
250250activated and the consolidation report will be made automatically. This
251251takes from a few minutes to one hour.
252252
253- ![ ] ( /img/product_docs/pingcastle/basicuser/image15.png )
253+ ![ ] ( /img/product_docs/pingcastle/basicuser/image15.webp )
254254
255255Then open the cartography reports (see below).
256256
@@ -262,17 +262,17 @@ Then open the cartography reports (see below).
262262"conso".** This mode performs the consolidation report and build the
263263maps.
264264
265- ![ https://www.pingcastle.com/wp/wp-content/uploads/2018/09/pingcastle-consolidation-process.png ] ( /img/product_docs/pingcastle/basicuser/image16.png )
265+ ![ https://www.pingcastle.com/wp/wp-content/uploads/2018/09/pingcastle-consolidation-process.webp ] ( /img/product_docs/pingcastle/basicuser/image16.webp )
266266
267267Option 3: perform a quick domain exploration (fastest but not scalable)
268268
269269If you need only a quick map (\< 5 minutes of execution), enter "carto"
270270when using the interactive mode or run the program with the switch
271271\- -carto.
272272
273- ![ https://www.pingcastle.com/wp/wp-content/uploads/2018/09/pingcastle-carto-process.png ] ( /img/product_docs/pingcastle/basicuser/image17.png )
273+ ![ https://www.pingcastle.com/wp/wp-content/uploads/2018/09/pingcastle-carto-process.webp ] ( /img/product_docs/pingcastle/basicuser/image17.webp )
274274
275- ![ ] ( /img/product_docs/pingcastle/basicuser/image18.png )
275+ ![ ] ( /img/product_docs/pingcastle/basicuser/image18.webp )
276276
277277The program discovers all the reachable domains, does a light scan and
278278produce the same map than in the health check consolidation mode. The
@@ -300,7 +300,7 @@ Each map is a dynamic map. Each node can be moved.
300300
301301** Example of graph produced by the tool**
302302
303- ![ https://www.pingcastle.com/wp/wp-content/uploads/2018/09/img3.png ] ( /img/product_docs/pingcastle/basicuser/image19.png )
303+ ![ https://www.pingcastle.com/wp/wp-content/uploads/2018/09/img3.webp ] ( /img/product_docs/pingcastle/basicuser/image19.webp )
304304
305305The colored circles are the domain on which the reports have been run.
306306The color depends on the score. The purple bordered circles are the
@@ -313,18 +313,18 @@ Legend:
313313
314314When the mouse is on a circle, the full name of the domain appears:
315315
316- ![ https://www.pingcastle.com/wp/wp-content/uploads/2016/12/fullzomm.png ] ( /img/product_docs/pingcastle/basicuser/image21.png )
316+ ![ https://www.pingcastle.com/wp/wp-content/uploads/2016/12/fullzomm.webp ] ( /img/product_docs/pingcastle/basicuser/image21.webp )
317317
318318If the mouse is hold on a trust, the detail is shown in a popup:
319319
320- ![ ] ( /img/product_docs/pingcastle/basicuser/image22.png )
320+ ![ ] ( /img/product_docs/pingcastle/basicuser/image22.webp )
321321
322322### Simple domain map
323323
324324The simple domain map is represented by the files
325325xxx_simple_node_map.html.
326326
327- ![ https://www.pingcastle.com/wp/wp-content/uploads/2018/09/pingcastle-carto-simplified.png ] ( /img/product_docs/pingcastle/basicuser/image23.png )
327+ ![ https://www.pingcastle.com/wp/wp-content/uploads/2018/09/pingcastle-carto-simplified.webp ] ( /img/product_docs/pingcastle/basicuser/image23.webp )
328328
329329This is the same map except that a domain is present only one time in
330330the graph and connected with only one trust. The domain which has the
@@ -359,7 +359,7 @@ There is a mouse over popup which gives you detail about a select IP
359359(and the networks where it does belong) and a search function can be use
360360to find a specific IP address.
361361
362- ![ ] ( /img/product_docs/pingcastle/basicuser/image24.png )
362+ ![ ] ( /img/product_docs/pingcastle/basicuser/image24.webp )
363363
364364## Deploying PingCastle
365365
@@ -370,7 +370,7 @@ To be the most effective, PingCastle needs to have the risk reports for
370370all domains. Because PingCastle doesn't need an account in the domain to
371371audit, you can take benefits of trusts to perform this task.
372372
373- ![ https://www.pingcastle.com/wp/wp-content/uploads/2016/12/pingcastle-consolidation-process.png ] ( /img/product_docs/pingcastle/basicuser/image25.png )
373+ ![ https://www.pingcastle.com/wp/wp-content/uploads/2016/12/pingcastle-consolidation-process.webp ] ( /img/product_docs/pingcastle/basicuser/image25.webp )
374374
375375## Involvement of the management
376376
@@ -660,7 +660,7 @@ and the previous flags can be combined.
660660
661661PingCastle can send the report (encrypted or not) using an API.
662662
663- ![ https://www.pingcastle.com/wp/wp-content/uploads/2018/09/pingcastle-swagger.png ] ( /img/product_docs/pingcastle/basicuser/image26.png )
663+ ![ https://www.pingcastle.com/wp/wp-content/uploads/2018/09/pingcastle-swagger.webp ] ( /img/product_docs/pingcastle/basicuser/image26.webp )
664664
665665You can query a PingCastle API server or build a client or server from
666666[ Swagger] ( https://editor.swagger.io/?url=https://gist.githubusercontent.com/vletoux/c6c565c8af07b4df5df65ed01ffeb917/raw/fca7a288050b7b17ba6024f2a23ef8c4d46fd813/pingcastle-swagger.json ) .
@@ -686,11 +686,11 @@ consolidation report. By default, the files are picked in the directory
686686(or sub directory) where the program is run. If there are duplicate
687687reports, only the most recent is used.
688688
689- ![ https://www.pingcastle.com/wp/wp-content/uploads/2018/09/pingcastle-consolidation-process.png ] ( /img/product_docs/pingcastle/basicuser/image16.png )
689+ ![ https://www.pingcastle.com/wp/wp-content/uploads/2018/09/pingcastle-consolidation-process.webp ] ( /img/product_docs/pingcastle/basicuser/image16.webp )
690690
691691To generate the report, enter "conso" in the interactive mode.
692692
693- ![ ] ( /img/product_docs/pingcastle/basicuser/image27.png )
693+ ![ ] ( /img/product_docs/pingcastle/basicuser/image27.webp )
694694
695695Or type the following command line:
696696
@@ -707,7 +707,7 @@ The consolidation report is a concatenation of all data contained in the
707707report, without the detail. It follows the same plan than a simple
708708report.
709709
710- ![ ] ( /img/product_docs/pingcastle/basicuser/image28.png )
710+ ![ ] ( /img/product_docs/pingcastle/basicuser/image28.webp )
711711
712712When the consolidation is made, 3 html files are generated.
713713
@@ -739,7 +739,7 @@ These programs are called \"scanners\" and are accessible from the
739739When selected, a menu is displayed to select the program. At the bottom,
740740a scanner description is shown.
741741
742- ![ ] ( /img/product_docs/pingcastle/basicuser/image29.png )
742+ ![ ] ( /img/product_docs/pingcastle/basicuser/image29.webp )
743743
744744** Here are the main scanners**
745745
@@ -820,7 +820,7 @@ enumeration.
820820First, enter the domain to enumerate (eg: the bastion or a domain which
821821is very far)
822822
823- ![ ] ( /img/product_docs/pingcastle/basicuser/image30.png )
823+ ![ ] ( /img/product_docs/pingcastle/basicuser/image30.webp )
824824
825825Then enter the domain which will be used as a pivot
826826
@@ -1165,31 +1165,31 @@ Important setting: check \"run whether user is logged on or not\" and
11651165choose a service account running under the domain (not a local account).
11661166Check hidden to hide the console.
11671167
1168- ![ ] ( /img/product_docs/pingcastle/basicuser/image31.png )
1168+ ![ ] ( /img/product_docs/pingcastle/basicuser/image31.webp )
11691169
11701170Set the schedule:
11711171
1172- ![ ] ( /img/product_docs/pingcastle/basicuser/image32.png )
1172+ ![ ] ( /img/product_docs/pingcastle/basicuser/image32.webp )
11731173
1174- ![ ] ( /img/product_docs/pingcastle/basicuser/image33.png )
1174+ ![ ] ( /img/product_docs/pingcastle/basicuser/image33.webp )
11751175
11761176Set the command line:
11771177
1178- ![ ] ( /img/product_docs/pingcastle/basicuser/image34.png )
1178+ ![ ] ( /img/product_docs/pingcastle/basicuser/image34.webp )
11791179
1180- ![ ] ( /img/product_docs/pingcastle/basicuser/image35.png )
1180+ ![ ] ( /img/product_docs/pingcastle/basicuser/image35.webp )
11811181
11821182Be sure that the service account has the right to write the report in
11831183the current directory.
11841184
11851185If you get the following message, be sure that the user as the right to
11861186logon as batch job.
11871187
1188- ![ ] ( /img/product_docs/pingcastle/basicuser/image36.png )
1188+ ![ ] ( /img/product_docs/pingcastle/basicuser/image36.webp )
11891189
11901190This can be modified in the security policies:
11911191
1192- ![ ] ( /img/product_docs/pingcastle/basicuser/image37.png )
1192+ ![ ] ( /img/product_docs/pingcastle/basicuser/image37.webp )
11931193
11941194** Select \" Local Policies\" in MSC snap in**
11951195
@@ -1199,7 +1199,7 @@ Right click on \"Log on as batch job\" and select Properties
11991199
12001200Click \" Add User or Group\" , and include the relevant user.
12011201
1202- ![ ] ( /img/product_docs/pingcastle/basicuser/image38.png )
1202+ ![ ] ( /img/product_docs/pingcastle/basicuser/image38.webp )
12031203
12041204If the button \" Add User or Group\" is grayed, that means that the
12051205setting is overridden by a GPO (by default, the Domain Controller
0 commit comments