Andy Thompson presented on how the zBang tool can be used to discover hidden risks in an Active Directory environment. The tool detects shadow admins, checks for skeleton key malware infections, analyzes SID history for privilege escalation risks, identifies risky SPNs, and allows querying Active Directory to find unusual configurations. zBang scans can be run from any domain-joined machine with read-only access to domain controllers and typically completes within 7-10 minutes for an environment with 1000 machines.