Active Directory Penetration Testing
Most corporate breaches don't stop at the first compromised laptop — they go through Active Directory. I map the real attack path from an assumed foothold to Domain Admin in your actual domain, the same way an intruder would, then show your team exactly which misconfigurations to close first.
What's included
- ADCS misconfiguration testing, ESC1–ESC8
- Kerberoasting & AS-REP roasting
- ACL / DACL abuse chains (BloodHound-mapped)
- NTLM relay & coercion testing
- Delegation abuse (unconstrained/constrained/RBCD)
- Full attack-path walkthrough to Domain Admin
Deliverables
- Executive summary for leadership
- Technical report with CVSS-rated findings
- Attack-path diagram, foothold to Domain Admin
- Command-level evidence for every finding
- Prioritised remediation roadmap
- Live debrief walkthrough with your team
Timeline
5–10 business days, depending on domain size and number of trusts in scope. Exact timeline confirmed in your written proposal before testing starts.
Why an Active Directory test is different from a network scan
A vulnerability scanner tells you what's patched. It won't tell you that a misconfigured certificate template lets any authenticated user request a certificate as Domain Admin, or that a service account with a weak password is Kerberoastable and sits three ACL hops from full domain compromise. Those attack paths only show up when someone actually walks the graph the way an attacker would — which is what this engagement does.
I build the real attack graph in your environment with BloodHound, then chain findings the way an intruder actually would: a phishable user, local admin on one workstation, a Kerberoastable service account, and an ADCS ESC1 misconfiguration is a realistic four-hop path to Domain Admin that no scanner flags as a single chain — because it isn't one vulnerability, it's a sequence of individually "acceptable" misconfigurations.
Methodology
Testing follows a structured attack-path methodology: enumeration and BloodHound collection, credential attacks (Kerberoasting, AS-REP roasting, password spraying where in scope), ACL and delegation abuse chain identification, ADCS template review against the known ESC1–ESC8 misconfiguration classes, and lateral movement validation to confirm each chain is exploitable in practice, not just theoretically present in the graph. Every technique used here is documented in detail in my public Arsenal — the same BloodHound queries, ADCS checks, and NetExec workflows I run on your domain are published for anyone to review.
What testing does not do
No production disruption. No account lockout storms, no domain controller reboots, no destructive actions. Higher-risk techniques are flagged and confirmed with you first under the signed rules of engagement. The goal is proof of exploitability with evidence, not a live-fire exercise on your production domain.
Questions about AD testing
Full attack-path mapping across your Windows domain: initial foothold simulation, Kerberoasting and AS-REP roasting, ACL and DACL abuse (GenericAll, GenericWrite, WriteDACL chains), ADCS certificate-template misconfigurations (ESC1 through ESC8), NTLM relay and coercion, delegation abuse, and lateral movement to Domain Admin. I use BloodHound to build the actual attack graph in your environment, not a generic checklist.
Most engagements start from an assumed-breach position — a low-privilege domain account, or a foothold on a single workstation — since that's the realistic starting point for most real intrusions (phishing, a compromised laptop, a leaked credential). A fully external, zero-knowledge engagement is also available and scoped separately.
5 to 10 business days depending on domain size and the number of trust relationships in scope. Small single-domain environments are typically on the shorter end; multi-domain forests with complex trusts take longer. You get an exact timeline in the written proposal, not an estimate.
No exploitation that risks availability — no ransomware simulation, no account lockout storms, no DC reboots. Techniques like Kerberoasting and ACL abuse are inherently low-noise; anything higher-risk is flagged and confirmed with you before it's attempted, per the rules of engagement.
An executive summary in plain language for leadership, and a full technical section for your engineers: the exact attack path from foothold to Domain Admin, CVSS-rated findings, command-level evidence, and a prioritised remediation roadmap — which misconfigurations to fix first for the biggest reduction in attack surface.
Full internal network and Active Directory assessments start from $1,500, scoped to domain size and complexity. You get a fixed price in writing before testing starts — see the pricing page for details.
Find your Domain Admin path before someone else does
Free scoping call, fixed-price proposal within 24 hours.