Each finding's detail-list table is now its own indented nav item
under "Finding Detail Lists", one click away instead of scroll-only.
Also fixes a double-space artifact in h4 badge titles (regex wasn't
consuming the whitespace after "[Severity]" before inserting the
badge span), which was most visible once those titles started
feeding the nav labels.
badge_findings_table matched literal <h4> with no attributes; once
the toc extension started stamping id="..." on every heading (needed
for the sidebar nav), the h4 severity badges silently stopped
rendering. Match <h4[^>]*> instead.
Links to every h2/h3 section (h4 finding headers excluded -- there
can be many). Sticky on desktop, collapses to a stacked block above
the content on narrow viewports. Active section highlights via
IntersectionObserver as you scroll. Uses markdown's toc extension
for heading ids/slugs rather than hand-rolling a slugifier.
- All timestamps (last logon, password last set, whenCreated, report
generation time) now emit as RFC 3339 UTC in both the Markdown
report and raw JSON dump, for both the Python and PowerShell
scripts.
- md_to_html.py: click any table header to sort ascending/descending
(vanilla JS, numeric-aware); a "Show local time" toggle swaps every
timestamp between UTC and the viewer's local offset, still RFC 3339.
Converts an ad_audit_report_*.md (from either audit script) into a
self-contained, styled HTML page: severity badges on findings, sorted
tables, responsive layout, light/dark theme via prefers-color-scheme.
No network access needed to view -- all CSS is inlined.
Each finding in the Risk & Cleanup table now expands into a full list
of the matching accounts/computers/groups (sAMAccountName, last logon
or type, DN) so the report can be acted on directly instead of just
citing counts. Removed the now-redundant standalone stale-user and
empty-group sections since they're covered by the finding lists.
Surfaces blank-password, AS-REP roastable, unconstrained delegation,
lockout, stale-account, empty-group, and password-never-expires
counts as a severity-ranked findings table at the top of the report,
ahead of the full detail tables -- useful as a reorg-planning summary.
Read-only structural/health audit of Active Directory: OU tree, user
and computer account status/hygiene flags, and group breakdown. Two
equivalent implementations depending on available access -- raw LDAP
via ldap3, or Get-AD* cmdlets via RSAT on a domain-joined machine.