Offensive Security

Active Directory Assessment

AD attack-path mapping, Kerberos abuse, and privilege-escalation review.

What it is

Active Directory is where most intrusions turn into disasters. We look for the paths from an ordinary user account to Domain Admin — Kerberos delegation, ACL misconfiguration, credential material left on disk, and the service accounts that quietly hold more privilege than anyone remembers granting.

How we do it

  1. 1

    Domain enumeration

    Users, groups, computers, trusts, GPOs and privileged group membership mapped from a standard user context.

  2. 2

    Attack path analysis

    BloodHound-style graphing to find the shortest route from any owned account to domain dominance.

  3. 3

    Kerberos attacks

    Kerberoasting and AS-REP roasting against service accounts, plus unconstrained and constrained delegation abuse.

  4. 4

    ACL and object permissions

    Dangerous rights — GenericAll, WriteDACL, WriteOwner — on users, groups and OUs that grant silent escalation.

  5. 5

    Credential exposure

    Passwords in GPOs, scripts and shares; cached credentials and LAPS coverage gaps.

  6. 6

    Tiering and hygiene review

    Whether administrative tiering exists in practice, and where privileged accounts log in that they should not.

What's included

  • Attack path graphs from ordinary user to Domain Admin
  • Kerberos delegation and roasting analysis
  • Dangerous ACL discovery across the directory
  • Service account privilege audit
  • Password policy and LAPS coverage review
  • Fix list ordered by which paths it closes

Who needs it

  • Organisations running Windows domains of any real age
  • Teams recovering from or preparing against ransomware
  • Businesses with Active Directory inherited through acquisitions

Deliverables

  • Attack path graphs with the chokepoints marked
  • Privileged account and service account inventory
  • Dangerous permission report by object
  • Remediation sequence — which single change closes the most paths

Compliance relevance

ISO 27001NIST CSFCIS ControlsCyber Essentials

Frequently asked questions

One ordinary domain user account with no special privileges. That is the point — we are modelling what an attacker gets from a single phished employee.
Enumeration and graphing are read-only. Anything that writes to the directory or requests tickets at volume is agreed in advance and run in a window you choose.
Yes, and hybrid is often the weakest moment. Connect servers, synchronisation accounts and the trust between on-premise and cloud are exactly where hybrid environments get compromised.
New to penetration testing?

Our complete guide covers methodology, standards, what a good report contains, and how often to test.

Read the guide

Related services

Network Security Assessment

Internal and external network testing to expose exploitable exposure.

Learn More

Penetration Testing

Manual, OSCP-grade testing that emulates real attackers against your assets.

Learn More

Red Team Operations

Goal-based adversary emulation testing people, process, and technology.

Learn More