Semperis(iSecurity)

Semperis(iSecurity)

Semperis DSP & ADFR Product Line Overview

Semperis provides enterprise-grade identity resilience through two core, complementary solutions: Directory Services Protector (DSP) and Active Directory Forest Recovery (ADFR). Together, they safeguard hybrid Active Directory environments before, during, and after severe cyberattacks.

Directory Services Protector (DSP) DSP is an advanced Identity Threat Detection and Response (ITDR) platform engineered to continuously uncover vulnerabilities, detect active attacks, and autonomously remediate malicious changes across hybrid AD and Microsoft Entra ID environments.

  • Replication-Based Monitoring: Unlike traditional SIEMs or auditing utilities that rely on Windows Event Logs—which attackers routinely clear, disable, or bypass—DSP monitors the directory replication stream directly. This provides unalterable visibility into modifications across all domain controllers.
  • Continuous Exposure & Threat Detection: DSP continuously evaluates directory configurations against hundreds of Indicators of Exposure (IOEs) and Indicators of Compromise (IOCs), pinpointing misconfigurations, unauthorized privilege escalation, and risky delegations.
  • Autonomous Remediation: When unauthorized or suspicious changes occur—such as GPO modifications, rogue administrative assignments, or ACL tampering—DSP automatically alerts security teams and can instantly roll back modifications to an uncompromised state.
  • Hybrid Defense: It bridges security across on-premises Active Directory and cloud-native Microsoft Entra ID tenants, stopping adversaries from moving laterally between cloud and on-prem infrastructures.

Active Directory Forest Recovery (ADFR) ADFR is an automated, cyber-first disaster recovery solution purpose-built to restore an entire Active Directory forest safely and rapidly following catastrophic incidents, including wipers and massive ransomware campaigns.

  • Automated Orchestration: Manual forest recovery involves dozens of complex, error-prone administrative tasks that can take weeks. ADFR automates the entire orchestration process—domain controller sequencing, metadata cleanup, RID pool allocation, and trust resets—slashing downtime from days to hours.
  • Malware-Free Recovery: Standard bare-metal or system-state backups preserve dormant rootkits, scripts, and backdoors within the operating system. ADFR decouples directory data from the underlying OS, restoring clean directory databases onto newly provisioned, untainted virtual machines, cloud instances, or alternate hardware.
  • Heterogeneous & Cloud Agnostic: Recovery does not require identical target hardware. ADFR allows cross-platform restoration across diverse hypervisors and public clouds (such as Azure, AWS, and GCP), enabling rapid rebuilds during active breach isolation.

Combining DSP’s proactive threat mitigation with ADFR’s cyber-resilient disaster recovery establishes an end-to-end defense strategy that keeps identity services continuously operable.

 

Semperis official website: https://www.semperis.com/