From user account to Domain Admin

We simulate real attacker paths in your domain: non-destructive, reproducible and with a clear focus on the paths that lead to a takeover.

  • Post-compromise approach
  • Non-disruptive, no account lockouts
  • Graphical attack paths in the report

A realistic attack path to domain takeover

We start with the rights of a normal domain user and escalate step by step.

  1. Starting point

    Standard user account

    Weak password policies, AS-REP roasting, password reuse.

    AS-REP RoastPassword Spraying
  2. Stage 1

    Service accounts

    SPNs with weak passwords and often excessive privileges.

    KerberoastingSPN Abuse
  3. Stage 2

    GPO & delegation

    Faulty permission inheritance, AdminSDHolder, unsecured scripts.

    GPO AbuseACL Misconfig
  4. Stage 3

    ADCS / certificates

    Misconfigured templates allow certificates to be issued for any user.

    ESC1 to ESC17PKINIT Abuse
  5. Goal

    Domain Admin

    Complete control over KRBTGT, DCSync and Golden Tickets.

    DCSyncGolden Ticket

How the test runs

1

Post-compromise start

We start out from an ordinary account with restricted privileges.

2

Enumeration & mapping

Structure, groups, ACLs and trusts reveal the chains of privileges.

3

Attack simulation

Kerberoasting, GPO and ACL abuse, pass-the-hash.

4

Mitigation & hardening

Prioritised measures and, if you wish, our support when you carry out the hardening.

What you get out of it

Spot hidden attack paths

We show how attackers get from harmless accounts to admin rights, before they do it.

Prioritised recommendations

Every finding rated in a traceable way, from the critical admin gap to the minor misconfiguration.

Targeted hardening advice

Concrete steps for accounts, group policies and delegations, practical and easy to understand.

What you have in hand at the end

  • Graphical attack paths: from user A via group B to Domain Admin

  • Every finding with proof of concept and a clear priority

  • Advice on tiering and Group Managed Service Accounts

  • A debriefing that plans changes without disrupting operations

Not an audit tool export

Automated AD audits produce thousands of warnings that can hardly be worked through. We filter out the noise and concentrate on paths that we have actually verified. A tool warns you that there are many privileged users. We show you that one of them has a weak password, which we cracked, and how we took over the entire domain from there. Context and proof of concept instead of a list.

Safe for day-to-day operations

We do not use any destructive tools that try out passwords indiscriminately and trigger account lockouts. During password spraying we pay meticulous attention to your lockout thresholds; during Kerberoasting we only request encrypted tickets, which from the server's point of view is a legitimate action. The test runs non-disruptively, and your employees carry on working as usual, without disruption.

Scope limits

  • An AD pentest does not replace an Infrastructure Pentest: that one tests services such as open SMB shares or web interfaces. We start where these services merge with your central identity management.

  • We take over the domain during the test in order to prove the risks, not to change anything. No real accounts are manipulated and no data is deleted.

  • The prerequisite is a starting account in your domain. How an attacker gets in initially is covered by phishing or social engineering, not by this test.

Frequently asked questions

What is behind the ADCS vulnerabilities ESC1 to ESC17?

Active Directory Certificate Services are currently one of the most critical targets. Misconfigured templates often allow attackers to request certificates for any user, right up to the domain admin. Because ADCS sits deep in the system and is rarely touched, this is where we often find direct paths to takeover.

What role do service accounts play?

They are often the Achilles heel: passwords that never expire, combined with far-reaching rights. With Kerberoasting we crack their hashes offline. We identify these accounts and recommend switching to Group Managed Service Accounts, which are considerably more secure.

How far would an attacker get in your domain?

In the initial call we clarify the starting point and scope. Free of charge.