Skip to content

Identity resilience for Active Directory and Entra ID.

Built to assess., harden., detect., recover.

Protection, detection and recovery for the identity infrastructure — before, during and after an attack. The Semperis platform, implemented and operated by the Shore team in Portugal.

PartnershipSemperis

  • Shore · Semperis partnership
  • AD · Entra ID · Okta
  • Before · During · After the attack

The problem

When identity fails, the business stops.

Active Directory is the backbone of authentication and authorisation in most organisations — and, for that reason, the vector most exploited by ransomware and advanced threats.

  • 9/10

    of the attacks Mandiant investigates involve Active Directory

    Mandiant

  • 88%

    of breaches in basic web application attacks use stolen credentials

    Verizon DBIR 2025

  • 76%

    of ransomware victims took more than a day to restore operations

    Semperis, Ransomware Risk Report

  • 241

    days, on average, to identify and contain a data breach

    IBM, Cost of a Data Breach 2025

Public sources, verified in July 2026.

  • AD is the way in

    Once the directory is compromised, the attacker moves laterally, escalates privileges and reaches full control of the infrastructure — and of everything that authenticates against it.

  • Traditional backups do not protect AD

    According to the Microsoft Digital Defense Report 2024, 40% of organisations have no AD-specific backup. Generic system backups can reintroduce malware and do not guarantee a clean recovery.

  • Manual recovery takes days or weeks

    Without purpose-built automation, recovering an AD forest is a manual, error-prone process — capable of stopping the business for weeks.

  • Hybrid environments widen the attack surface

    On-premises AD, Entra ID and Okta create an ever-changing attack surface. Every risky account or configuration is a potential vulnerability.

The platform

End-to-end identity resilience.

An integrated platform that protects the entire identity infrastructure — Active Directory, Entra ID and Okta — before, during and after an attack.

Implemented and operated by Shore in Portugal.

  1. Before the attack

    Assess & Harden

    Continuous identification of vulnerabilities, attack paths and risky configurations in Active Directory and Entra ID — to reduce the attack surface before it is exploited.

    • Continuous monitoring of indicators of exposure and compromise
    • Attack-path analysis for Tier 0 assets
    • Continuous security posture assessment
    • Guided, prioritised remediation
  2. During the attack

    Detect & Respond

    Threat detection with tamper-resistant tracking of directory changes, and automatic rollback of malicious activity in real time.

    • AI-assisted attack pattern detection
    • Monitoring of the AD replication stream
    • Automatic rollback of malicious changes
    • Protection of service accounts and non-human identities
  3. After the attack

    Recover & Restore

    Cyber-first recovery of the entire AD forest, with immutable, malware-free backups, and post-incident identity forensics to eliminate persistence.

    • Automated recovery of the entire AD forest
    • Up to 90% reduction in recovery time
    • Immutable, malware-free backups
    • Identity forensics and incident response

The capabilities and figures in this section and the next are those published by Semperis for its products (semperis.com, July 2026). The concrete scope of each implementation is defined in a proposal.

Products

Solutions for every phase of the cycle.

A portfolio covering initial assessment through post-incident recovery — implemented and supported by Shore within the cybersecurity service.

  • Detection & Response

    Directory Services Protector

    AD and Entra ID protection with tamper-resistant change tracking, automatic rollback of malicious changes and AI-assisted attack pattern detection.

  • Cyber-first recovery

    Active Directory Forest Recovery

    Automated recovery of the entire AD forest, with immutable, malware-free backups, to virtual or physical hardware — according to Semperis, cutting recovery time by up to 90%.

  • Continuous assessment

    Lightning Intelligence

    Continuous SaaS security posture assessment for AD and Entra ID: attack path management and real-time monitoring of indicators of exposure.

  • Assessment

    Purple Knight

    Semperis’s free security assessment tool for AD, Entra ID and Okta, with over 200 indicators. The usual entry point for an initial diagnosis.

  • Cloud identity

    Disaster Recovery for Entra Tenant

    Backup and recovery for the Entra ID tenant: continuous protection of cloud identity, with granular restore and recovery automation.

  • Crisis management

    Ready1

    Cyber crisis response platform: team coordination, secure communication and incident management during active attacks.

Delivery model

From diagnosis to operations.

Shore implements and operates the platform in a three-phase model, with clear deliverables in each.

  1. Phase 01

    Assessment

    Diagnosis and planning

    typically 1–2 weeks

    • Purple Knight run for the initial diagnosis
    • AD / Entra ID security posture assessment
    • Attack-path mapping for Tier 0 assets
    • Report with priorities and roadmap
    • Implementation proposal
  2. Phase 02

    Implementation

    Deploy and configuration

    typically 2–4 weeks

    • Platform installation and configuration
    • Integration with the existing SIEM
    • Detection and rollback policies
    • Immutable backups and disaster recovery plan
    • Internal team training
  3. Phase 03

    Operations

    Continuous monitoring

    continuous

    • Security indicator monitoring
    • Alert and incident response
    • Continuous tuning of rules and policies
    • Periodic security posture reports
    • Disaster recovery exercises

Indicative timelines — the plan, the calendar and the operation’s coverage windows are defined in each project’s proposal.

Start with a Purple Knight assessment — no commitment.

Schedule an assessment

Why Shore

The Semperis platform, delivered by a local team.

Implemented by a team that knows the Portuguese market, speaks your language and works in your time zone.

  • A published partnership

    Semperis is one of the partner platforms of the Shore · Secnora cybersecurity service — implemented and operated within that catalogue.

  • A team dedicated to identity

    Consultants specialised in Active Directory, Entra ID and identity security, integrated in the partnership’s cybersecurity team.

  • A structured methodology

    Three phases with clear deliverables — assessment, implementation, operations — and a plan defined in a proposal before starting.

  • Local proximity

    A team in Portugal, in the same time zone and in Portuguese — response without communication barriers.

  • Integration with what exists

    The platform ships native integrations with Microsoft Sentinel and Splunk — alerts and events reach the SIEM and security operation already in use.

  • A complete solution, not just software

    Assessment, implementation, internal team training and continuous operations — with a single point of coordination.

FAQ

Frequently asked questions

Have another question? Talk to us

It is an integrated set of solutions that protects the identity infrastructure — Active Directory, Entra ID and Okta — across every phase of an attack: assessment and hardening before, detection and response during, and recovery and restore after. Unlike generic backup tools or a SIEM, it is built specifically for identity.

Typically, the initial assessment takes 1–2 weeks and the full implementation — including SIEM integration and policy configuration — 2–4 weeks; continuous operations start right after the deploy. These are indicative timelines: the concrete calendar is defined in each project’s proposal.

Traditional backups (system-state or bare-metal) capture the whole operating system, including potential malware, and recovery is manual and slow. Semperis’s approach separates AD from the operating system, guarantees malware-free backups, automates forest recovery and allows restore to any hardware — cutting, according to Semperis, recovery time by up to 90%.

Yes. The platform was designed for hybrid environments: it offers a unified view of vulnerabilities and changes across on-premises AD and Entra ID in the cloud, and detects attacks that move between the two — something separate tools can hardly do.

Purple Knight is Semperis’s free security assessment tool for AD, Entra ID and Okta, with over 200 security indicators. Shore runs the tool and interprets the results as the entry point of the assessment — talk to us to get started, with no commitment.

Shore acts as an extension of the client’s team, within its cybersecurity service: it runs the initial assessment, implements and configures the platform, integrates it with the existing infrastructure, trains the internal team and can operate the solution continuously. All in Portuguese and in the same time zone.

Yes. Semperis ships native integrations for Microsoft Sentinel and Splunk, including dashboards, alerts and data connectors; events can also be sent via Windows Event Logs and Syslog/CEF to other SIEMs.

It depends on the size of the environment — number of users, domains and domain controllers — and on the selected modules. We publish no prices: contact us for a proposal based on your specific environment.

Shall we assess your identity resilience?

Talk to us to schedule an initial Purple Knight assessment, or to discuss your AD / Entra ID environment.

The button opens Shore’s secure contact form. We reply by email to schedule.

See all cybersecurity services