Softwr
Semperis logo

Semperis

Identity threat detection and Active Directory forest recovery for AD, Entra ID and Okta, from a privately held US vendor.

As of 30 August 2026, Semperis's pricing is not published; the vendor quotes on request. A single-purpose vendor for the problem of Active Directory being compromised or destroyed. Softwr lists it under Cybersecurity.

Overview

What Semperis does

Semperis is a private company founded in 2014, headquartered in Hoboken, New Jersey, with substantial engineering in Israel, and backed by a growth investment led by KKR in 2022. It sells two main products. Directory Services Protector monitors Active Directory, Entra ID and Okta for dangerous changes and misconfigurations, scores the environment against known attack techniques, and can automatically roll back specific changes. Active Directory Forest Recovery automates the rebuild of a compromised or destroyed AD forest to clean operating systems. The company also publishes two free tools that are widely used well beyond its customer base: Purple Knight, a security assessment for AD and Entra ID, and Forest Druid, which maps attack paths into Tier 0. The distinguishing capability is forest recovery, and it matters because of how bad the alternative is. Microsoft's documented forest recovery procedure is long, manual, and full of steps that are easy to get wrong under pressure, and restoring domain controllers from system-state backup restores the operating system too, which can reintroduce the malware you are recovering from. Semperis restores the directory itself onto clean instances, including different hardware or a cloud target, and can do it without the original operating system images. Directory Services Protector adds a detection layer with a genuinely useful property: it reads changes from the AD replication stream rather than only from domain controller security logs, so changes made directly against the directory database, which bypass logging, are still captured. The buyer is an organisation whose entire authentication estate hangs off on-premises Active Directory, which is still most large enterprises, and the purchase is usually triggered by a ransomware incident elsewhere in the sector, a cyber insurance question, or an auditor asking how long AD recovery would take when nobody can answer. The trade-offs are scope and rehearsal. It addresses one dependency, so its value falls in proportion to how much identity you have genuinely moved off AD, and the licence buys tooling rather than a tested runbook. A recovery plan that has never been executed end to end in a lab is an assumption with an invoice attached.

What people use it for

  • An organisation that cannot answer an auditor or insurer asking how long it would take to rebuild Active Directory after a destructive attack
  • Post-incident recovery where domain controllers are compromised and restoring from system-state backup would reintroduce the attacker's foothold
  • Continuous detection of privileged group changes and directory-level tampering that domain controller security logs miss
  • Hybrid estates where AD, Entra ID and Okta all matter and no single tool currently shows changes across the three

The honest half

Where it falls short

Concrete and checkable, so you can decide whether any of them matter to you. This is the half of a review a vendor will not write about Semperis.

  • Scope is limited to Active Directory, Entra ID and Okta, so an organisation whose critical identity lives elsewhere gets little from it, and the recovery value declines in direct proportion to how much has already moved off on-premises AD.
  • The licence buys tooling, not a proven runbook: forest recovery is only worth what your last rehearsal demonstrated, and a plan that has never been executed end to end in a lab is an untested assumption regardless of what was purchased.
  • It overlaps with backup and directory management products from Quest, Veeam, Commvault and others, so the buyer must argue internally why a dedicated product is needed alongside a backup contract that already claims to protect Active Directory.
  • Running Directory Services Protector well requires someone who understands AD internals, replication metadata and Tier 0 attack paths, and without that person the alerts on privileged changes are either ignored or auto-reverted in ways that break legitimate administration.
  • Licensing is driven by identity object counts, so directories carrying years of stale user accounts and service principals pay for objects that should have been deleted, and the cleanup project that would reduce the bill is the one nobody has time for.

Cross-shopped

What people choose instead of Semperis

Each pairing was judged by two reviewers asking whether a buyer would genuinely weigh the two against each other. The ones that failed were deleted rather than published.

Capabilities

Features

  • Active Directory Forest Recovery

    Automates the full forest rebuild to clean operating system instances, including to different hardware or a cloud target

  • Malware-free restore

    Restores the directory itself rather than domain controller system state, so a compromised operating system is not reintroduced

  • Replication-stream monitoring

    Captures directory changes from AD replication rather than only security logs, so changes made directly to the database are still seen

  • Automated rollback

    Reverses specific dangerous changes, such as an addition to a privileged group, without restoring anything else

  • Attack indicator scoring

    Continuously assesses AD and Entra ID against a catalogue of known indicators of exposure and compromise

  • Entra ID and Okta coverage

    Extends change tracking and posture assessment to cloud identity providers alongside on-premises AD

  • Purple Knight

    Free standalone assessment tool that scores an AD and Entra ID environment against security indicators

  • Forest Druid

    Free tool that maps attack paths inward towards Tier 0 assets rather than outward from every account

  • Recovery testing

    Rehearsal of forest recovery into an isolated environment so the runbook can be proven before it is needed

  • Post-breach forensics

    Timeline of directory changes to establish what an attacker altered and when

Answered, with sources

Questions people ask

Each answer names the page it came from, so you can check it rather than take our word for it.

Does this replace my backups?

No. It replaces the Active Directory recovery procedure specifically. You still need backups for everything else, and the point of Semperis is that a generic system-state backup of a domain controller is a poor way to recover a forest because it restores the operating system along with whatever compromised it.

Is it useful if we are cloud-only on Entra ID?

Partly. Directory Services Protector covers Entra ID and Okta for change tracking and posture, but the forest recovery product, which is the strongest reason to buy, applies to on-premises Active Directory. A genuinely cloud-only organisation should weigh it against Microsoft's own tooling.

Are Purple Knight and Forest Druid really free?

Yes, both are free downloads with no licence requirement, and they are widely used by organisations that are not Semperis customers. They are also, transparently, the top of the sales funnel.

How long does forest recovery actually take?

The honest answer is whatever your rehearsal took. The vendor's case is hours instead of days, and automation genuinely removes most manual steps, but the number that matters for your board is the one from a test in your own environment.

Does it require agents on domain controllers?

It collects directory changes from the AD replication stream, which is what lets it see changes that bypass the security log. Deployment details vary by product and version, so confirm the exact architecture against your domain controller change-control rules.

Share

Keep looking

Where to go from Semperis

Best Cybersecurity software for

Compare Semperis with

Other Cybersecurity software

  • The world's most-loved password manager

    From $2.99/mo10 researched notes
  • Powerful protection against evolving threats

    From $36/yr14 researched notes
  • Simplify online life with LastPass password manager

    Free plan12 researched notes
  • Financial crime, risk and compliance suite for regulated institutions

    Pricing on request10 researched notes
  • Data access governance and change auditing across Active Directory, file shares and Microsoft 365

    Pricing on request11 researched notes
  • Cloud-delivered endpoint protection and EDR, now owned by Broadcom and positioned alongside Symantec.

    14 researched notes
  • AI-powered SIEM platform for modern security operations

    8 researched notes
  • Quest-owned identity governance, PAM and Active Directory management

    Pricing on request11 researched notes
  • Enterprise identity for workforce and customers, with a 5,000 user floor

    From $3/mo11 researched notes
  • European digital identity hub connecting national eID schemes

    Pricing on request10 researched notes
  • Stop breaches with AI-native cybersecurity

    Free, then $7.99/device/month12 researched notes
  • Twilio's free authenticator app with encrypted cloud backup, mobile only since the desktop clients were withdrawn in 2024.

    Free plan14 researched notes
  • Transparent proxy that encrypts, tokenises and masks database fields without application code changes

    Pricing on request13 researched notes
  • Phishing-resistant passwordless authentication with device trust enforced at every login

    Pricing on request11 researched notes
  • Privileged access management, endpoint privilege management and secure remote access

    Pricing on request11 researched notes
  • The leading toolkit for web security testing

    Free, then $449/yr11 researched notes
  • Consumer VPN sold by Bitdefender that runs on network infrastructure licensed from a third party rather than its own.

    14 researched notes

Softwr does not host reviews and shows no star rating for Semperis, because a rating we did not collect is not ours to publish. What is here is the pricing and platform detail from the vendor’s own pages, limitations we could state concretely, and alternatives a reviewer confirmed people weigh against it. Tell us if any of it is wrong.

More on Semperis

Best Cybersecurity software alternatives

Privileged access management from the merged Thycotic and Centrify

quote

Large Chinese video platform that US federal buyers and federal contractors cannot lawfully use

quote

Managed video loss prevention with human auditors for restaurants, convenience stores and retail

quote

Privileged access management, endpoint privilege management and secure remote access

quote

Cloud video surveillance billed per camera per month, where retention length drives the bill more than anything else

Per camera per month

AI video search that runs on cameras you already own, starting near five dollars per camera per month

Per camera per month

Phishing-resistant passwordless authentication with device trust enforced at every login

quote

Compare Semperis with alternatives