We simulate real attacker paths in your domain: non-destructive, reproducible and with a clear focus on the paths that lead to a takeover.
We start with the rights of a normal domain user and escalate step by step.
Weak password policies, AS-REP roasting, password reuse.
SPNs with weak passwords and often excessive privileges.
Faulty permission inheritance, AdminSDHolder, unsecured scripts.
Misconfigured templates allow certificates to be issued for any user.
Complete control over KRBTGT, DCSync and Golden Tickets.
We start out from an ordinary account with restricted privileges.
Structure, groups, ACLs and trusts reveal the chains of privileges.
Kerberoasting, GPO and ACL abuse, pass-the-hash.
Prioritised measures and, if you wish, our support when you carry out the hardening.
We show how attackers get from harmless accounts to admin rights, before they do it.
Every finding rated in a traceable way, from the critical admin gap to the minor misconfiguration.
Concrete steps for accounts, group policies and delegations, practical and easy to understand.
Graphical attack paths: from user A via group B to Domain Admin
Every finding with proof of concept and a clear priority
Advice on tiering and Group Managed Service Accounts
A debriefing that plans changes without disrupting operations
Automated AD audits produce thousands of warnings that can hardly be worked through. We filter out the noise and concentrate on paths that we have actually verified. A tool warns you that there are many privileged users. We show you that one of them has a weak password, which we cracked, and how we took over the entire domain from there. Context and proof of concept instead of a list.
We do not use any destructive tools that try out passwords indiscriminately and trigger account lockouts. During password spraying we pay meticulous attention to your lockout thresholds; during Kerberoasting we only request encrypted tickets, which from the server's point of view is a legitimate action. The test runs non-disruptively, and your employees carry on working as usual, without disruption.
An AD pentest does not replace an Infrastructure Pentest: that one tests services such as open SMB shares or web interfaces. We start where these services merge with your central identity management.
We take over the domain during the test in order to prove the risks, not to change anything. No real accounts are manipulated and no data is deleted.
The prerequisite is a starting account in your domain. How an attacker gets in initially is covered by phishing or social engineering, not by this test.
Active Directory Certificate Services are currently one of the most critical targets. Misconfigured templates often allow attackers to request certificates for any user, right up to the domain admin. Because ADCS sits deep in the system and is rarely touched, this is where we often find direct paths to takeover.
They are often the Achilles heel: passwords that never expire, combined with far-reaching rights. With Kerberoasting we crack their hashes offline. We identify these accounts and recommend switching to Group Managed Service Accounts, which are considerably more secure.
In the initial call we clarify the starting point and scope. Free of charge.