[ Infrastructure ]
Active Directory Security Assessment
- Typical duration
- 5-10 days
- Starting price
- Scoped
- You provide
- One standard domain account
[ 01 / The engagement ]
Active Directory is rarely broken by a vulnerability. It is broken by twenty years of accumulated permissions that were each reasonable on their own. We map every path from an ordinary user account to Domain Admin, prove the ones that work, and hand you the fixes in the order that closes the most paths first, because you will not remediate all of them, and you should not have to.
[ 02 / Coverage ]
What we test, in practice.
This is the working checklist, not a marketing list. Anything your scope adds gets written into the engagement letter before we start.
Methodology
- 01Full attack-path graphing from every tier to Domain Admin
- 02Kerberoasting, AS-REP roasting and delegation abuse
- 03AD Certificate Services misconfiguration (ESC1 through ESC14)
- 04ACL and object permission abuse across the directory
- 05Group Policy Object permissions and SYSVOL exposure
- 06Tiering model, privileged access and admin hygiene review
- 07Entra ID and hybrid join trust boundaries
[ 03 / What you get ]
Four things land at the end of every engagement.
Technical report
Every finding with CVSS v4.0 score, evidence, reproduction steps and a specific fix, written for the engineer who has to close it.
Executive summary
Two pages your board can read. Risk in business terms, with the three things that matter most called out.
Letter of attestation
A shareable document proving the test happened and what it covered, for customers and auditors who should not see the full report.
Free retest
Once you have fixed things, the same tester verifies each finding and reissues the report. Included for 90 days.
[ 04 / Questions ]
Before you commit.
It is the normal case, and it is why the report is ordered by attack path rather than by finding. Closing three or four choke points usually removes most of the graph.
Yes. Hybrid identity is where the interesting paths are now, so on-premises AD and Entra ID are assessed as one estate rather than two.
Often scoped together
All services →External Network Penetration Testing
Everything of yours that answers from the internet, including what you forgot.
Internal Network Penetration Testing
We assume the perimeter already failed, and see how far one foothold travels.
Cloud Penetration Testing
AWS, Azure and GCP, IAM paths, workload escape and the blast radius of one key.
Scope a active directory security assessment.
Send us the target and the deadline. You get a written scope and a fixed price, usually within one working day.