// Services / Active Directory

Active Directory Security Assessment

Attackers don’t need a zero-day when Active Directory hands them a path to Domain Admin. We find those paths, prove them and help you shut them down — before ransomware operators do.

// Why AD

One misconfiguration away from total compromise.

Active Directory decides who can log in, what they can reach and who can change it. In most small and mid-sized businesses it has grown for years — new servers, departed admins, vendor accounts, “temporary” permissions — and nobody has looked at it the way an attacker does.

That’s exactly how modern intrusions unfold: phish one user, then quietly abuse AD to escalate until the attacker controls every system and every backup. Our assessment walks that same path, safely and with your permission, so you see your environment from the adversary’s side.

AD is our specialty. It’s the area of offensive security we’ve invested in most — including the CAPE (Certified Active Directory Pentesting Expert) certification — and it’s where we consistently find the highest-impact issues.

// What we test

A full-spectrum review of your directory.

Attack-path analysis

We collect and graph relationships between users, groups, computers and permissions to find every chain that leads to privileged access — not just the obvious ones.

Kerberos attacks

Kerberoasting, AS-REP roasting, weak service-account passwords, and abuse of unconstrained, constrained and resource-based constrained delegation.

AD Certificate Services

Misconfigured certificate templates, enrollment agents, web enrollment and CA permissions (ESC1–ESC16) — one of the most common and most overlooked escalation routes.

ACL / permission abuse

Dangerous rights such as GenericAll, WriteDACL and ForceChangePassword on users, groups, GPOs and OUs that quietly grant control to the wrong people.

Credential & relay exposure

NTLM relay, SMB signing, LLMNR/NBT-NS poisoning, credentials in shares, GPP passwords, LAPS coverage and cached admin credentials on workstations.

Privileged access & hygiene

Admin tiering, stale and orphaned accounts, non-expiring passwords, service-account sprawl, domain trusts and password policy strength.

// Deliverables

What you receive

  • Executive summary — your AD risk in plain English, with the top themes leadership needs to know.
  • Attack-path walkthroughs — each path to privileged access, step by step, with evidence.
  • Prioritized remediation plan — quick wins first, then structural fixes like tiering and AD CS hardening.
  • Debrief call — a working session with your IT team or MSP to answer questions and plan fixes.
  • Retest — confirmation that the critical paths are actually closed.

// Engagement options

Pick the starting point that fits.

Assumed breach

We start with a standard domain user account — the same foothold a phishing email gives an attacker — and see how far it goes. The most efficient way to test AD.

Configuration review

A collaborative review of AD, Group Policy and AD CS configuration with read-only access, ideal when you want breadth without active exploitation.

As part of an internal pentest

Combine the AD assessment with internal network testing for a complete view of what an attacker on your network can reach.

Post-remediation validation

Already hardened AD? We’ll verify the work — tiering, LAPS, AD CS fixes — and confirm the paths are really gone.

// FAQ

Active Directory assessment questions

Is an AD assessment safe to run in production?

Yes. We work from read-only enumeration first and only exploit issues in ways agreed in the rules of engagement. Anything with even a small risk of disruption — like password spraying or relay attacks — is coordinated with you in advance or excluded.

We use Microsoft 365 / Entra ID. Is this still relevant?

Almost always. Most small and mid-sized businesses run hybrid identity, with on-premises AD synchronized to Entra ID. A compromised on-prem domain often leads straight to the cloud, so we review the hybrid connection points as part of the assessment.

How long does it take?

Most AD assessments for small and mid-sized environments take one to two weeks of testing, followed by reporting. You’ll receive an exact timeline in your proposal.

What access do you need?

For an assumed-breach assessment, a standard domain user account and remote access to the internal network — typically a small virtual machine or VPN connection we help you set up.

// Next step

Know where you stand before someone else finds out.

Start with a no-obligation scoping call. We’ll talk through your environment, what’s driving the test and the timeline that works for you.