Overview
Overview
Identity security assessment using a single Falcon Identity sensor on one domain controller. Covers Active Directory hygiene, identity attack path discovery, conditional access policy validation, and privileged account exposure. Initial findings produced inside 24 to 48 hours of sensor deployment. Especially valuable for organizations with hybrid Active Directory and Entra environments, complex group policy histories, or accounts identified as targets in past incidents. Deliverables include attack path visualizations, prioritized identity exposures, and remediation recommendations.
What's included
- Attack path visualizations — graphical maps of how an attacker could escalate from a standard account to domain admin
- Active Directory hygiene report — misconfigured accounts, stale permissions, Kerberoastable SPNs, and delegation issues
- Privileged account exposure analysis — accounts with excessive rights, shared credentials, and inadequate MFA coverage
- Conditional access policy review — gaps in Entra/AAD policy coverage that leave hybrid identity paths unprotected
- Prioritized remediation recommendations — ranked by attack path severity, with clear next steps
Why Max Technologies
Delivered by a CrowdStrike Services Partner founded by a former early CrowdStrike employee. As an authorized AWS Marketplace seller, Max Technologies enables frictionless procurement through your existing AWS committed spend (EDP).
Engagement details
- Duration: 2-3 weeks
- Engagement model: Fixed fee (milestone-based)
- Pricing: starts at $20,500 USD (final price via private offer)
AWS Marketplace products and services this relates to
This engagement is delivered using the CrowdStrike Falcon platform (Falcon Identity Protection), which is available in AWS Marketplace, and assesses identity security posture across your hybrid Active Directory/Entra and AWS IAM identities.
- Platform: customer receives full Falcon Identity Protection platform access at no platform cost for the duration of the engagement.
Highlights
- Initial attack path findings delivered within 24-48 hours of sensor deployment — one domain controller, no widespread rollout required.
- Exposes the exact attack paths from standard user to domain admin in your Active Directory — not generic hygiene scores, but exploitable routes.
- Delivered by a CrowdStrike Services Partner — procure via AWS Marketplace using your EDP committed spend.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Pricing
Custom pricing options
How can we make this page better?
Legal
Content disclaimer
Support
Vendor support
For support, contact Max Technologies at support@maxtechnologies.ca . Customers receive direct access to their assigned security engineer throughout the engagement for technical assistance, troubleshooting, and guidance, with a response within two business days.