240 modules. Every one is real, runnable, and yours to inspect.
ACQI's discovery suite covers 240 modules across the systems a deal team actually inherits — Azure, M365, Active Directory, network, security, SaaS, virtualization, databases, storage, and AI. Each module is a standalone PowerShell script tied to a specific platform: it signs in, enumerates the relevant objects, and writes the results to a CSV you can open in Excel. Nothing here is a slide-deck claim. The source is on disk, the output is a file, and your team can read either before signing.
Azure
44 modulesEntra ID Connect Health
Azure AD Connect Health and Synchronization Status
Azure
Azure Tenants, Subscriptions, and Resource Groups
Azure Container Registry
Azure Container Registries across accessible subscriptions
Entra ID Sign-Ins
Azure AD Sign-in based Shadow SaaS Discovery
Entra ID Administrative Units
Azure AD Administrative Units and their members using Microsoft Graph API
Azure App Service
Azure App Service Web Apps across all accessible subscriptions
Azure Automation
Azure Automation Accounts, Runbooks, Variables, and Schedules
Azure Batch
Azure Batch accounts across all accessible subscriptions
Entra ID Conditional Access
Azure Conditional Access Policies and performs migration complexity analysis
Azure Cost & Consumption
Azure cost data using Cost Management Query API
Entra ID Devices
Azure AD Registered/Joined devices and Intune Managed Devices
Entra ID Directory Roles
Azure Directory Roles Discovery - enumerates Entra ID (Azure AD) directory
Azure Discovery Orchestrator
Coordinates all Azure sub-modules for a complete Azure tenant scan.
Azure Functions
Azure Function Apps across all accessible subscriptions
Azure Governance
Azure governance assessment with management group hierarchy traversal, policy aggregation, and RBAC resolution
Azure Hybrid Benefit
Cross-references discovered Windows Server / SQL Server licences against
Entra ID Identity
Azure Identity Discovery - enumerates Entra ID (Azure AD) users, groups,
Azure Infrastructure
Core Azure infrastructure including Virtual Machines, Storage, and Network Security
Azure Key Vault
Azure Key Vaults including secrets, keys, and certificates
Azure Key Vault Access
Azure Key Vault Access Policies and RBAC assignments
Azure Log Analytics
Azure Log Analytics workspaces across all accessible subscriptions
Azure Logic Apps
Azure Logic Apps across all accessible subscriptions
Azure + Microsoft 365
Microsoft 365 / Entra ID discovery - users, groups, group members, Teams,
Azure Managed Identities
Azure managed identities and their assigned role definitions.
Azure Management Groups
Azure Management Group hierarchy and subscription associations
Azure Monitor
Azure Monitor inventory across all accessible subscriptions: - Metric alert rules (Microsoft
Azure MySQL
Azure Database for MySQL Single Server and Flexible Server instances across all accessible subscriptions
Azure Named Locations
Azure AD Named Locations used in Conditional Access policies
Azure Network
Azure Network resources including Network Security Groups , Virtual Networks , Subnets , and Public IP Addresses
Azure Organization
Azure AD Organization settings, tenant configuration, and security defaults using Microsoft Graph API
Azure Orphan Resources
Orphaned resource detection using Azure Resource Graph Reads from for cost optimization
Entra ID PIM
Azure AD Privileged Identity Management eligible role assignments
Entra ID PIM Eligible Roles
Entra ID privileged role schedule instances via Graph: 1) roleEligibilityScheduleInstances -> Status=Eligible 2) roleAssignmentScheduleInstances -> Status=Active This tenant often has permanent/active directory role...
Azure RBAC
Azure Role-Based Access Control (RBAC)
Azure Resource Graph
Generic Azure resources across all accessible subscriptions
Azure Resource Providers
Azure Resource Provider
Azure SQL
Azure SQL Servers and Databases
Azure Security
Azure security configurations including Conditional Access Policies, Directory Roles, and Subscription-level RBAC assignments
Azure Service Principal Credentials
Secrets and certificates associated with Azure AD Application Registrations
Azure Storage
Azure Storage Accounts including configuration, encryption status, access tiers, endpoints, and SKU details for migration planning
Azure Storage Access
Azure Storage Account security configurations and network rules
Azure Subscription Owners
All principals assigned the 'Owner' role at the subscription scope
Azure VM Scale Sets
Azure Virtual Machine Scale Sets across all accessible subscriptions
Azure Virtual Machine
Azure Virtual Machines across all accessible subscriptions
M365
29 modulesAccess Reviews
Azure AD Access Reviews and their configurations via Microsoft Graph API
Cloud Sync
Entra Cloud Sync Discovery - enumerates the modern lightweight provisioning
Conditional Access
Azure AD Conditional Access policies, security policies, and access controls using Microsoft Graph API
DLP
Microsoft Purview DLP policies and rules using Microsoft Graph
Entra Agent ID
Discovers Entra Agent IDs (agentIdentity workload identities) via Microsoft Graph.
Entra ID App
Entra ID applications, enterprise applications, service principals, and related security configurations using Microsoft Graph API
Entra ID Security
Entra ID security assessment focusing on app registrations, service principals, consent grants, admin units, and cross-tenant access
Entra Tenant Readiness
Entra ID Tenant Readiness
Exchange
Discovers Exchange Online mailboxes, plans, and usage statistics.
Exchange Coexistence
Converts a mailbox object to a coexistence discovery record.
Exchange Config
Stable id from EXO objects (Guid / ExchangeObjectId / Identity / DistinguishedName).
Group Policy Intune Mapping
GPO-to-Intune readiness classification engine for ACQI
Microsoft Graph
Azure AD / Entra ID users, groups, app registrations, service principals, and group membership relationships for M&A migration matching
Identity Governance
Identity Governance
Intune
Discovers Intune-managed devices, configurations, compliance policies,
Licensing
Discovers all Microsoft 365 license assignments and service plan details
Microsoft 365 Security
M365 security posture assessment with conditional access policies, authentication methods, privileged roles, and security defaults
Microsoft Cloud App Security
Microsoft Defender for Cloud Apps (formerly MCAS) module.
Microsoft 365
Microsoft 365 organization metadata, domains, subscribed SKUs/licenses, service plans , and service health status
OneDrive
Discovers OneDrive for Business users, sites, storage, and sharing.
Power BI
Power BI workspaces , plus migration-useful license footprint via Graph
Power Platform
Power Platform environments, Power Apps, and Power Automate flows via BAP / Power Apps / Flow REST APIs using service-principal client credentials
Project for the Web
Discovers Microsoft Planner tasks (Project for the Web / Planner plans)
Project Online
Discovers Microsoft Project Online projects via Microsoft Graph API.
SharePoint
Discovers SharePoint Online sites, storage quotas, and usage.
SharePoint On-Premises
Discovers SharePoint on-premises farm topology, patch levels, and KEV vulnerability status.
SharePoint Post-Exploit IIS Key Scan
SharePoint IIS key-scan: detects exposed authentication keys and post-exploit indicators.
Microsoft Teams
Discovers Microsoft Teams teams, channels, members, and installed apps.
Teams Call Records
Teams Call Records
Active Directory
2 modulesActive Directory
Active Directory users, groups, computers, organizational units, and infrastructure topology essential for M&A planning
Active Directory Security
AD security scoring based on stale objects, privileged accounts, trust relationships, and anomalies detection
Network
14 modulesCisco Switch Config
Cisco Catalyst switch configurations, VLANs, and port assignments.
Citrix NetScaler
Auto-detects NetScaler appliances via DNS and gateway references
DNS & DHCP
DNS servers, zones, forwarders and DHCP servers, scopes, and failover
Cisco Meraki
Entire Cisco Meraki tenant via Meraki Dashboard API v1
Citrix NetScaler Configuration
Converts a NetScaler config entity to enriched discovery record.
Network Backup
Network devices via nmap and retrieves configuration backups via Oxidized
Network Configuration
Returns vendor-specific commands for network device configuration discovery.
Network Config Backup
Multi-vendor network device configuration collection and drift detection
Network Device Inventory
Producer for the canonical /assets/network-devices surface
Network Infrastructure
Detailed network configurations including adapters, routing tables, and firewall rules
Network Performance
Measures network latency, packet loss, and jitter to gateway, DNS servers, domain controllers, and user-specified targets
Network Topology
Network topology through subnet enumeration, port scanning, and service detection
Palo Alto
Palo Alto Firewalls and Panorama management servers
Passive Network Dependency
Passive Network Dependency
Storage
9 modulesBackup Recovery
Backup infrastructure including top 20 enterprise backup solutions across hybrid and pure Azure environments
Enterprise Storage
Enterprise Storage Discovery - Multi-Vendor Array Support
File Server
File servers and network shares within the local machine and domain environment
File System
NTFS ACL + SMB share discovery that captures permission rows carrying the
NetApp ONTAP
Comprehensive NetApp ONTAP storage infrastructure including Volumes, LUNs, CIFS shares, NFS exports, Aggregates, SnapMirror relationships, and Cluster Nodes
Storage
Multi-vendor enterprise storage discovery orchestrator.
Storage Array
Converts a storage volume object to a normalized record with calculated fields.
Storage Configuration
Storage configuration items across supported platforms.
Veeam
Veeam backup infrastructure: servers, repositories, jobs, and recovery targets.
Virtualization
11 modulesDocker
Docker and container infrastructure including containers, images, networks, volumes, Swarm services, Kubernetes clusters
Hyper-V
Hyper-V Discovery
Hyper-V Configuration
Hyper-V host configuration, virtual switches, and VM inventory.
Kubernetes
Kubernetes clusters across Azure , AWS , and on-premises
Kubernetes Configuration
Kubernetes cluster configuration, namespaces, and workload inventory.
VMware
VMware infrastructure: vCenter Servers, ESXi Hosts, Clusters, Datastores, Virtual Machines, Virtual Networks, Resource Pools, Templates, Snapshots, Distributed Switches, and Storage Policies via PowerCLI
VMware Configuration
Convert a VMware ESXi host object to a discovery record with configuration details.
VMware Host Contention
VMware Host Contention
Virtual Machines
Azure Virtual Machines across all accessible subscriptions
Virtualization
Virtual machines, hosts, and clusters across Hyper-V and VMware
XenServer
Citrix XenServer and XCP-ng hypervisor infrastructure including pools, hosts, virtual machines, storage repositories, virtual disks, and network configuration via xe CLI or XML-RPC API
Database
6 modulesDatabase Schema
Database instances and schemas across SQL Server, MySQL, and PostgreSQL
Databricks
Databricks workspaces, clusters, and jobs via REST API
Oracle
Oracle Database Licence Compliance
Oracle Configuration
Enriches raw Oracle parameter rows with computed category field.
SQL Server
Local SQL Server instances, versions, and databases
SQL Server Configuration
Enriches a SQL Server configuration record with context and derived columns.
SaaS
28 modulesAsana
Lists Asana workspaces, projects, tasks, and members via the Asana REST API.
BambooHR
BambooHR employees, org structure, portal users, and benefits enrollment via REST API for HRIS and headcount-synergy assessment
Confluence
Confluence spaces, pages, and access permissions via Confluence REST API.
Confluence Pages
Confluence pages and blog posts with sensitivity scoring and M&A relevance ranking
Confluence Spaces
Confluence spaces with ownership metadata and M&A relevance scoring
Coupa
Coupa procurement, suppliers, and spend records via the Coupa API.
GitHub
Builds a query command that returns organizations from GitHub API.
GitHub Enterprise
GitHub Enterprise organizations, repositories, users, and teams via REST API
Google Workspace
Google Workspace
SailPoint IdentityNow
Identities, access profiles, roles, and entitlements from SailPoint IdentityNow via REST API
JFrog
JFrog Artifactory repositories, artifacts, and access policies.
JFrog Artifactory
JFrog Artifactory repositories and artifact storage information via the Artifactory REST API with multi-strategy collection and graceful fallback
Jira
Jira projects, issues, and users via REST API
LeanIX
Enterprise Architecture data from LeanIX via GraphQL API
monday.com
monday.com boards, items, and groups via the monday.com GraphQL and REST APIs.
Okta
Okta users, groups, and applications via REST API
Okta Configuration
Records deep Okta configuration for pre-configuring destination systems from CSVs alone
SAP SuccessFactors
Configure TLS / cert-bypass behaviour for the current process.
Salesforce
Salesforce users, projects, and custom apps via REST API
ServiceNow
ServiceNow CMDB items, users, and incidents via REST API
ServiceNow CMDB
ServiceNow CMDB items, users, and incidents via the ServiceNow REST API.
Slack
Lists the Slack workspace, its users, and its channels via the Slack Web API (https://slack
Tableau
Tableau Server
Workday
Workday workers, organizations, and supervisory structures via REST API
Zoom
UI-wired M&A discovery engine for Zoom Video Communications.
Zoom Event Types
Typed event classes for the Zoom discovery engine.
Zoom State Manager
Persists per-entity delta tokens and known entity snapshots for
Zoom Webhook Handler
Parses Zoom Webhook payloads and converts them to ZoomEntityEvent objects.
Security
24 modulesAttack Path Analysis
Graph-based attack path analysis using Active Directory data
Certificate
SSL/TLS certificates from local stores and web servers
Certificate Authority
Certificate Authorities , certificate templates, and issued certificates
Cloud Security Group Soft-Delete
Microsoft Entra ID Cloud Security Group Soft-Delete discovery.
Cloud Security Posture
Multi-cloud security scoring based on CIS benchmarks, compliance frameworks, and ThreatScore
Compliance
Compliance policies, configurations, and compliance status information
Continuous Endpoint Telemetry
Closes the SysTrack competitive gap by sampling endpoint performance counters at a configurable interval over a configurable window, then computing baseline statistics and anomaly counts
Custom Security Attribute
Lists Custom Security Attribute definitions and assignments from Microsoft Graph
Endpoint
Endpoint hardware specs, OS currency, compliance status, and computes Digital Employee Experience scores for migration readiness
Endpoint Migration
And plans endpoint migrations including domain unjoin/rejoin operations, tenant-to-tenant MDM re-enrollment , user profile migration , and cutover day automation for BitLocker, OneDrive, printers, mapped drives, and VPN
Endpoint Protection
EDR / Endpoint Protection Coverage
Hardware Inventory
Detailed hardware specifications including CPU, RAM, BIOS, and Storage
IIS Configuration
Records deep IIS configuration for pre-configuring destination systems from CSVs alone
IIS Web Apps
Local IIS websites, application pools, and virtual directories
SCOM
Comprehensive SCOM discovery with auto-detection and multi-source data extraction
Security Event
Converts a Windows security event to an enriched security event object.
Security Group Analysis
Analyzes Active Directory security groups, nested memberships, permissions, and access patterns to identify security risks and compliance issues
Security Infrastructure
Comprehensive discovery of security infrastructure including antivirus/EDR, firewalls, backup systems, SIEM monitoring, VPN solutions, and security policies
Shadow SaaS
Detects shadow SaaS / unsanctioned cloud application usage in the tenant.
SolarWinds
Discovers SolarWinds Observability Cloud resources via the AIOps REST API.
Splunk
Auto-detects Splunk deployment type and full Splunk infrastructure including search heads, indexers, forwarders, apps, indexes, users, saved searches, and dashboards
Splunk Endpoint
Splunk Endpoint Discovery - extracts infrastructure endpoints and forwarders from Splunk.
Web Server
Multi-source web server discovery for lift-and-shift migration planning
Web Server Configuration
Local and remote web server configurations
AI
6 modulesAI Agent
AI Agent Principal Inventory Discovery (Copilot / Power Platform / Teams /
App Performance
Per-application performance telemetry for pre-migration baseline.
Decision Maker
Decision Maker
Patent Landscape
And clusters intellectual property portfolios by technology stack
Stakeholder
Identifies key stakeholders for M&A transitions by analyzing organizational structure, license assignments , group ownership, and application ownership in Azure AD
User Persona
User Persona
Web
3 modulesLegacy
2 modulesMulti-Job Detection
Potential multi-job scenarios by analysing Azure AD sign-in logs, calendar conflicts, email forwarding rules, meeting pattern gaps, Teams presence anomalies, file exfiltration signals, and browser profile switching...
Per-App Firewall Rule
Per-Application Firewall Rule Discovery & NSG Export
Other
62 modulesEntra ID Connect Sync Rules
Discovers Azure AD Connect synchronization rules, connector attribute flows,
AWS
Comprehensive AWS resource discovery across EC2, S3, RDS, IAM, VPC, and Security Groups
AWS Cloud Infrastructure
AWS Cloud Infrastructure
App Registration
Azure AD app registrations and consent-grant risk scoring.
Application Inventory
Combines Intune, DNS, and internet-based discovery for a complete application inventory.
Application Dependencies
Application-to-application dependencies derived from network flow.
Application Dependency Mapping
Application dependency mapping comparable to RISC Networks CloudScape output.
ARM Request
Azure ARM REST API helper for ad-hoc read calls.
Citrix
Citrix XenApp and XenDesktop infrastructure including Delivery Groups, Machine Catalogs, published Applications, active Sessions, and VDI Session Health
Citrix XenApp
Citrix XenApp/XenDesktop comprehensive discovery for M&A Suite.
Cloud Right-Sizing Advisor
Cloud right-sizing advisor that maps workloads to Azure VM SKUs and
Cloud TCO Estimator
Multi-CSP Total Cost of Ownership estimator. Compares AWS, Azure, GCP
Concurrent Discovery Engine
Parallel discovery capabilities with throttling, resource management, and intelligent batch processing for large-scale M&A discovery operations
CrowdStrike
CrowdStrike hosts, policies, and detection coverage via the CrowdStrike Falcon API.
CyberArk
CyberArk accounts, safes, and privileged session inventory via the CyberArk REST API.
Data Classification
Scans file metadata and content patterns for sensitive information
Data Governance Metadata Management
Data governance artefacts including retention policies, classification tags, and owners.
Device Encryption
BitLocker on Windows and FileVault on macOS encryption status.
Discovery Base
Lower-level helpers used across discovery modules.
Discovery Module Base
Foundational patterns shared by every ACQI discovery module: initialisation, output shaping, error handling.
Dropbox
Dropbox teams, members, and shared folder inventory via the Dropbox API.
Duo
Builds a user query command for Duo API.
Elasticsearch
Elasticsearch cluster health, indices, and shard allocation.
Environment Detection
Detects whether the collector is on-prem, in Azure, or hybrid.
Environment Topology Detector
Identifies dsregcmd join status and topology of joined devices.
External Identity
External identity providers and Active Directory federation trusts.
Federated SSO
Federated SSO configuration across trusted identity providers.
GCP
Google Cloud projects, service-account keys, and the GCP resource graph.
Group Policy
Group Policy Objects, settings, and OU links from Active Directory.
Group Policy Analysis
Post-discovery GPO analysis: conflicts, redundancy, consolidation candidates.
Group Policy Migration
Backs up Group Policy Objects into a staging directory with a migration manifest.
HashiCorp
HashiCorp Vault secrets engines, auth methods, and policies.
Hybrid Connectivity
VPN gateways, ExpressRoute circuits, and site-to-site links.
Hybrid Identity
Intune-managed and Entra-joined devices across hybrid environments.
Information Systems
Unified catalog combining Active Directory computers, Azure resources, and on-premises infrastructure.
Infrastructure
Network subnets, active hosts, and structural environment markers.
Infrastructure Diagnostics
Advanced network infrastructure discovery using nmap and PowerShell to systematically scan subnets, identify live hosts, Lists services, detect operating systems, and collect detailed hardware/software inventory
Multi-Domain Forest
Active Directory forest topology, domain hierarchy, and trusts.
Application Dependency Mapping
SolarWinds NetFlow-derived application dependency mapping.
On Prem
On-premises infrastructure: Active Directory, servers, shares.
OneLogin
OneLogin users, groups, and assigned applications via the OneLogin API.
OpenShift
OpenShift projects, routes, and workloads via the OpenShift API.
Pass-Through Auth Agent
Pass-through Authentication (PTA) Agent Health
Palo Alto Panorama
Performs deep inspection of Palo Alto Panorama management servers
Physical Server
Physical server hardware specifications: CPU, memory, storage controllers.
Ping
Reachable host enumeration across configured subnets.
Post-Cutover Readiness
Post-cutover validation checks: DNS, mail flow, app reachability, auth, data spot-checks.
Printer
Network and locally-attached printers via SNMP and WMI.
Project Inventory
Project Online and Project for the Web plan inventory.
Proofpoint
Proofpoint protection domains, policies, and detected threats.
Qualys
Qualys asset inventory, vulnerabilities, and scan coverage.
RDS Session Metrics
Per-session latency, protocol, and reconnect telemetry for RDS and Citrix Virtual Apps.
Real-Time Discovery Engine
Continuous file-system and scheduled-task monitoring for ongoing estate drift detection.
SaaS Rationalisation
Discovers SaaS application portfolio via Azure AD sign-in log harvesting,
SentinelOne
SentinelOne agents, policies, and threat coverage.
CVE Risk Mapping
Cross-references discovered installed software against CVE databases to produce risk findings.
License Risk Analysis
Software Licence Risk Analysis engine.
Source Identity (LDAP)
On-prem source identities (objectSid, ms-DS-ConsistencyGuid, UPN) for cross-domain joins.
SQL Workload Profiling
Profiles SQL Server query stats, wait types, and IO telemetry to recommend an Azure SQL tier per instance.
Tenable
Tenable.io asset inventory, vulnerability findings, and scan coverage.
Workload Right-Sizing
Current CPU, memory, disk IOPS, and network utilisation, with right-sizing recommendations.
Zscaler
Zscaler tenants, locations, and policy inventory.
All 240 modules, one orchestrated run.
Pick a deal, run discovery, get a readiness score for every entity in scope.