// Penetration testing · Active Directory security

Find the gaps before attackers do.

Crooker Security delivers hands-on penetration testing for small and mid-sized businesses — with deep expertise in Active Directory, the system attackers go after first once they’re inside your network.

  • OSCP · CAPE · CPTS certified
  • ~10 years in security
  • Financial-sector experience

Industry certifications

  • OSCP
  • CAPE
  • CPTS
  • PenTest+
  • CySA+
  • Security+

// What we test

Security testing sized for your business.

Enterprise-grade testing without the enterprise overhead. Every engagement is scoped to your environment, your risks and your budget — and performed by a senior, certified tester.

Network Penetration Testing

External and internal testing that shows what an attacker on the internet — or already inside your office — can actually reach and exploit.

Web Application Testing

Manual testing of your portals, APIs and customer-facing apps against the OWASP Top 10 and the business-logic flaws scanners miss.

Vulnerability Assessment

Broad, cost-effective coverage of your environment — with every result manually validated, so you fix real issues instead of chasing false positives.

Not sure what you need?

Tell us what’s driving the request — an insurance questionnaire, an audit, a customer, or just peace of mind — and we’ll recommend the right scope.

// Active Directory

Active Directory is the keys to the kingdom.

Nearly every ransomware incident ends the same way: the attacker takes over Active Directory. Years of quick fixes, stale accounts and default settings quietly add up to a short path from any user to Domain Admin.

AD is our specialty. We test it the way real adversaries do — then hand you a prioritized, step-by-step plan to break those paths for good.

  • Kerberoasting & AS-REP roasting
  • ACL / ACE abuse & attack paths
  • AD CS certificate misconfigurations
  • Delegation & NTLM relay
  • Credential exposure & LAPS gaps
  • Tiering & privileged account hygiene

// Why Crooker Security

Senior expertise. Small-business focus.

Large firms often sell the engagement with a senior consultant and staff it with a junior one. Here, the person who scopes your project is the person who tests it.

A certified expert on every test

OSCP, CAPE and CPTS are hands-on, exam-lab certifications — proof of practical offensive skill, not just multiple-choice knowledge.

Manual testing, not a scan with a logo

Automated tools are a starting point. The findings that matter come from a human chaining small weaknesses into real impact.

Financial-sector rigor

Nearly a decade of security work focused on the financial industry, where testing has to be careful, documented and defensible to auditors.

Reports people can act on

A plain-English executive summary for leadership, plus reproducible technical detail and specific fixes for your IT team or MSP.

// How it works

A clear process from first call to final fix.

Scope

A short call to understand your environment and goals. You get a fixed-price proposal and written rules of engagement.

Test

Careful, coordinated testing within the agreed window. Critical issues are reported to you immediately — not weeks later.

Report

An executive summary and technical findings ranked by real-world risk, walked through together on a debrief call.

Remediate & retest

We help your team or MSP prioritize fixes, then retest to confirm the issues are actually closed.

// What you get

Findings ranked by what actually matters.

No 300-page scanner dumps. You get a focused report that leadership can read in five minutes and your IT team can work from line by line.

  • Executive summary — overall risk, key themes and business impact in plain English.
  • Technical findings — evidence, reproduction steps and severity for every issue.
  • Remediation guidance — specific, prioritized fixes, not generic advice.
  • Attestation letter — for customers, auditors and cyber-insurance carriers.

// Who we work with

Built for businesses without a red team.

You don’t need a 20-person security department to get a real-world view of your risk. We work directly with owners, IT managers and the MSPs who support them.

  • Banks, credit unions and financial services firms
  • Professional services — legal, accounting, insurance
  • Healthcare practices, manufacturing and logistics
  • MSPs and IT providers who need a trusted testing partner
Small team collaborating around laptops

// FAQ

Common questions

What’s the difference between a vulnerability assessment and a penetration test?

A vulnerability assessment identifies and validates known weaknesses across your environment — it’s broad. A penetration test goes further and actively exploits weaknesses, chaining them together to show what an attacker could really achieve — it’s deep. Many businesses start with an assessment and add a pentest annually.

Will testing disrupt our business?

Testing is planned around your operations. We agree on scope, timing and off-limits systems in advance, avoid destructive techniques unless you explicitly approve them, and stay in contact throughout the engagement.

How much does a penetration test cost?

It depends on scope — the number of hosts, applications and user accounts in play. After a short scoping call you receive a fixed-price proposal, so there are no surprises.

Do you work with our MSP or IT provider?

Yes. We regularly coordinate with internal IT and managed service providers, and our remediation guidance is written so they can act on it directly.

// Next step

Know where you stand before someone else finds out.

Start with a no-obligation scoping call. We’ll talk through your environment, what’s driving the test and the timeline that works for you.