Skip to content
Vaptiq logo mark — V orientationVAPTIQ
All services

[ Infrastructure ]

Active Directory Security Assessment

The attack paths from any user to Domain Admin, mapped and proven.
Typical duration
5-10 days
Starting price
Scoped
You provide
One standard domain account

[ 01 / The engagement ]

Active Directory is rarely broken by a vulnerability. It is broken by twenty years of accumulated permissions that were each reasonable on their own. We map every path from an ordinary user account to Domain Admin, prove the ones that work, and hand you the fixes in the order that closes the most paths first, because you will not remediate all of them, and you should not have to.

[ 02 / Coverage ]

What we test, in practice.

This is the working checklist, not a marketing list. Anything your scope adds gets written into the engagement letter before we start.

Methodology

MITRE ATT&CKMicrosoft Securing Privileged Access
  1. 01Full attack-path graphing from every tier to Domain Admin
  2. 02Kerberoasting, AS-REP roasting and delegation abuse
  3. 03AD Certificate Services misconfiguration (ESC1 through ESC14)
  4. 04ACL and object permission abuse across the directory
  5. 05Group Policy Object permissions and SYSVOL exposure
  6. 06Tiering model, privileged access and admin hygiene review
  7. 07Entra ID and hybrid join trust boundaries

[ 03 / What you get ]

Four things land at the end of every engagement.

Technical report

Every finding with CVSS v4.0 score, evidence, reproduction steps and a specific fix, written for the engineer who has to close it.

Executive summary

Two pages your board can read. Risk in business terms, with the three things that matter most called out.

Letter of attestation

A shareable document proving the test happened and what it covered, for customers and auditors who should not see the full report.

Free retest

Once you have fixed things, the same tester verifies each finding and reissues the report. Included for 90 days.

[ 04 / Questions ]

Before you commit.

It is the normal case, and it is why the report is ordered by attack path rather than by finding. Closing three or four choke points usually removes most of the graph.

Yes. Hybrid identity is where the interesting paths are now, so on-premises AD and Entra ID are assessed as one estate rather than two.

Scope a active directory security assessment.

Send us the target and the deadline. You get a written scope and a fixed price, usually within one working day.