
// Services / Active Directory
Active Directory Security Assessment
Attackers don’t need a zero-day when Active Directory hands them a path to Domain Admin. We find those paths, prove them and help you shut them down — before ransomware operators do.
// Why AD
One misconfiguration away from total compromise.
Active Directory decides who can log in, what they can reach and who can change it. In most small and mid-sized businesses it has grown for years — new servers, departed admins, vendor accounts, “temporary” permissions — and nobody has looked at it the way an attacker does.
That’s exactly how modern intrusions unfold: phish one user, then quietly abuse AD to escalate until the attacker controls every system and every backup. Our assessment walks that same path, safely and with your permission, so you see your environment from the adversary’s side.
AD is our specialty. It’s the area of offensive security we’ve invested in most — including the CAPE (Certified Active Directory Pentesting Expert) certification — and it’s where we consistently find the highest-impact issues.
// What we test
A full-spectrum review of your directory.
Attack-path analysis
We collect and graph relationships between users, groups, computers and permissions to find every chain that leads to privileged access — not just the obvious ones.
Kerberos attacks
Kerberoasting, AS-REP roasting, weak service-account passwords, and abuse of unconstrained, constrained and resource-based constrained delegation.
AD Certificate Services
Misconfigured certificate templates, enrollment agents, web enrollment and CA permissions (ESC1–ESC16) — one of the most common and most overlooked escalation routes.
ACL / permission abuse
Dangerous rights such as GenericAll, WriteDACL and ForceChangePassword on users, groups, GPOs and OUs that quietly grant control to the wrong people.
Credential & relay exposure
NTLM relay, SMB signing, LLMNR/NBT-NS poisoning, credentials in shares, GPP passwords, LAPS coverage and cached admin credentials on workstations.
Privileged access & hygiene
Admin tiering, stale and orphaned accounts, non-expiring passwords, service-account sprawl, domain trusts and password policy strength.
# Active Directory assessment — example findings [*] Enumerated 1,284 users · 312 computers · 211 groups [!] 9 Kerberoastable accounts — 2 with admin rights [!] ESC1: enrollable template allows arbitrary SAN [!] Unconstrained delegation enabled on FS02 [!] 41 privileged users with non-expiring passwords [-] LAPS missing on 37% of workstations [-] SMB signing not required on 18 hosts [✓] Shortest path to Domain Admins: 4 hops
// Deliverables
What you receive
- Executive summary — your AD risk in plain English, with the top themes leadership needs to know.
- Attack-path walkthroughs — each path to privileged access, step by step, with evidence.
- Prioritized remediation plan — quick wins first, then structural fixes like tiering and AD CS hardening.
- Debrief call — a working session with your IT team or MSP to answer questions and plan fixes.
- Retest — confirmation that the critical paths are actually closed.
// Engagement options
Pick the starting point that fits.
Assumed breach
We start with a standard domain user account — the same foothold a phishing email gives an attacker — and see how far it goes. The most efficient way to test AD.
Configuration review
A collaborative review of AD, Group Policy and AD CS configuration with read-only access, ideal when you want breadth without active exploitation.
As part of an internal pentest
Combine the AD assessment with internal network testing for a complete view of what an attacker on your network can reach.
Post-remediation validation
Already hardened AD? We’ll verify the work — tiering, LAPS, AD CS fixes — and confirm the paths are really gone.
// FAQ
Active Directory assessment questions
Is an AD assessment safe to run in production?
Yes. We work from read-only enumeration first and only exploit issues in ways agreed in the rules of engagement. Anything with even a small risk of disruption — like password spraying or relay attacks — is coordinated with you in advance or excluded.
We use Microsoft 365 / Entra ID. Is this still relevant?
Almost always. Most small and mid-sized businesses run hybrid identity, with on-premises AD synchronized to Entra ID. A compromised on-prem domain often leads straight to the cloud, so we review the hybrid connection points as part of the assessment.
How long does it take?
Most AD assessments for small and mid-sized environments take one to two weeks of testing, followed by reporting. You’ll receive an exact timeline in your proposal.
What access do you need?
For an assumed-breach assessment, a standard domain user account and remote access to the internal network — typically a small virtual machine or VPN connection we help you set up.
// Next step
Know where you stand before someone else finds out.
Start with a no-obligation scoping call. We’ll talk through your environment, what’s driving the test and the timeline that works for you.