Active Directory, linked services
Active Directory Penetration Testing
Active Directory is the central hub for user management and authentication, and thus forms the backbone of many corporate networks. This is precisely why it is the primary target for attackers: whoever controls the AD controls everything connected to it. We analyse your environment from an attacker’s perspective and uncover technical vulnerabilities as well as structural design flaws that cannot be remedied with a patch.
Request a demoProcess, Methodology & Scope of ReportPentest
Target
Perspective
Standard account to Domain Admin
Focus
Escalation pathways
Prerequisite
A standard user account
When an AD test is due
- The domain has evolved over time and nobody knows any more why certain groups exist.
- Following a migration, a merger or integration with Entra ID.
- An audit in accordance with ISO 27001, BSI Basic Protection or NIS2 requires evidence of the authorisation structure.
- Ransomware incidents in the industry have raised the question of how far an attacker could get within your organisation.
- A service account with extensive privileges has been running for years, with no one willing to touch it.
- There have been staff changes in IT, and since then no one has had a complete Overview of the authorisation structure.
- A hybrid connection to the Cloud has been set up without the additional attack surface being assessed.
Where we’re starting from
With a standard user account
The standard scenario. We start with the permissions of an ordinary employee (Phishing / foot-in-the-door). How far can an attacker who is already on the network get?
No prior knowledge required
Completely without external access, right up to the first domain access. Shows just how easy it is to gain this initial access.
With extended rights
Log in with elevated, but not administrative, privileges (e.g. an IT support account) if this account type poses a specific risk.
What we analyse
- Authorisation structure: nested groups, inherited permissions, orphaned permissions from previous projects, and accounts with significantly more permissions than necessary.
- Escalation paths: Routes from a standard user account to administrative rights, traceable step by step.
- Authentication: Kerberos and NTLM configuration, delegations, password policies in practice, and obsolete protocols.
- Service accounts: Permissions, password ages and dependencies. Service accounts are one of the most common sources of domain admin access.
- Group Policy: Misconfigurations in GPOs that can be exploited to extend privileges or distribute malicious code.
- Trusts and hybrid connections: Trusts between domains and the connection to Entra ID.
- Design flaws: Structural weaknesses in the domain architecture that require a different structure or authorisation model.
- Hardening level: Comparison with the recommendations from Microsoft and the BSI (e.g. tiering models and protected administrative accounts).
What we frequently see
How a test is carried out
Scoping
We define the starting point, the scope of the domain and the time window, including any systems that should be excluded.
Reconnaissance
Capturing the domain structure: users, groups, permissions, trusts and configuration, using standard AD security analysis tools.
Identification of Escalation Paths
Analysing which combinations of permissions lead to elevated privileges, and mapping the most likely routes to Domain Admin.
Controlled Exploitation
Proving that an identified path actually works, in a controlled manner and without making changes to production permissions.
Report and Debrief
Handover of the attack paths as a traceable chain, reviewed together with your AD team.
What we don’t do
- No changes to production permissions. We demonstrate access paths without permanently altering permissions.
- No account locks due to mass password guessing. We obtain consent for the scope and lockout limits for password attacks in advance.
- No disruption to domain operations. Active assessments are carried out in a controlled manner; we treat critical systems such as domain controllers with particular care.
- Immediate notification in the event of an existing compromise. If we find evidence of an ongoing, genuine attack, we report this immediately rather than noting it in the final report.
What you provide
- A standard user account without any special privileges, unless the Blackbox version is requested.
- Network access to the domain, either on-site or via VPN.
- A technical contact from the AD team for enquiries.
- A rough overview of the domain structure, if available. This is not strictly necessary.
What you’ll take away from this
You’ll receive the attack paths as a coherent chain, not as a loose list of individual findings. That’s exactly what makes the difference: a single overly broad permission is rarely critical, but a chain of three such permissions leads to Domain Admin.
In addition, you’ll receive specific recommendations on security architecture, prioritised by impact, so that you can start with the measures that cut off the largest attack path, rather than working through individual findings in any order.
“Anyone who understands the vulnerabilities of Active Directory understands the mindset of an attacker.”
Active Directory Penetration Testing
A standard user account is sufficient for us as a starting point. During the initial consultation, we clarify the scope of the domain, the starting point and the timeframe.
- No interference with production permissions
- Escalation paths as a traceable chain
- Prioritised according to the greatest attack vector
- Alignment with BSI and Microsoft hardening guidelines
Frequently Asked Questions
What customers want to know before carrying out an Active Directory test.
Could the test disrupt our domain?
The risk is low. We avoid destructive actions and mass account suspensions, and coordinate sensitive assessments in advance.
Do we need clear documentation of our domain beforehand?
No. An unclear current status is often part of the problem itself and does not hinder the test.
What if you discover an ongoing attack during the test?
We report this immediately and outside the normal reporting channels, rather than waiting until the final report.
Do you also test hybrid environments with Entra ID?
Yes, the connection to the Cloud is part of the scope of the test, if it exists.
How often should an AD test be repeated?
Annually as a guideline, and additionally following major structural changes such as a migration or merger.

