Active Directory Penetration Testing

Active Directory is the central hub for user management and authentication, and thus forms the backbone of many corporate networks. This is precisely why it is the primary target for attackers: whoever controls the AD controls everything connected to it. We analyse your environment from an attacker’s perspective and uncover technical vulnerabilities as well as structural design flaws that cannot be remedied with a patch.

Request a demoProcess, Methodology & Scope of Report
DOMAIN SECURITY
Active Directory
Pentest
Structural Analysis & Escalation Pathways
Kerberos NTLM Privilege Escalation

Target

Active Directory, linked services

Perspective

Standard account to Domain Admin

Focus

Escalation pathways

Prerequisite

A standard user account

When an AD test is due

  • The domain has evolved over time and nobody knows any more why certain groups exist.
  • Following a migration, a merger or integration with Entra ID.
  • An audit in accordance with ISO 27001, BSI Basic Protection or NIS2 requires evidence of the authorisation structure.
  • Ransomware incidents in the industry have raised the question of how far an attacker could get within your organisation.
  • A service account with extensive privileges has been running for years, with no one willing to touch it.
  • There have been staff changes in IT, and since then no one has had a complete Overview of the authorisation structure.
  • A hybrid connection to the Cloud has been set up without the additional attack surface being assessed.

Where we’re starting from

With a standard user account

The standard scenario. We start with the permissions of an ordinary employee (Phishing / foot-in-the-door). How far can an attacker who is already on the network get?

No prior knowledge required

Completely without external access, right up to the first domain access. Shows just how easy it is to gain this initial access.

With extended rights

Log in with elevated, but not administrative, privileges (e.g. an IT support account) if this account type poses a specific risk.

What we analyse

  • Authorisation structure: nested groups, inherited permissions, orphaned permissions from previous projects, and accounts with significantly more permissions than necessary.
  • Escalation paths: Routes from a standard user account to administrative rights, traceable step by step.
  • Authentication: Kerberos and NTLM configuration, delegations, password policies in practice, and obsolete protocols.
  • Service accounts: Permissions, password ages and dependencies. Service accounts are one of the most common sources of domain admin access.
  • Group Policy: Misconfigurations in GPOs that can be exploited to extend privileges or distribute malicious code.
  • Trusts and hybrid connections: Trusts between domains and the connection to Entra ID.
  • Design flaws: Structural weaknesses in the domain architecture that require a different structure or authorisation model.
  • Hardening level: Comparison with the recommendations from Microsoft and the BSI (e.g. tiering models and protected administrative accounts).

What we frequently see

Findings Why it matters
Kerberoasting-vulnerable service accounts Passwords that can be cracked offline for accounts with often extensive privileges.
Unrestricted Kerberos delegation A compromised system can impersonate virtually any other user.
Groups that are too deeply nested No one has an overview of who actually has which rights to what.
Administrators without protected accounts Everyday workstation accounts with domain administrator rights are a prime target for attack.
Outdated protocols such as NTLMv1 Enable the interception and reuse of login credentials.
Passwords in group policies or scripts Often left over from old migrations, discoverable in plain text.
Lack of tiering separation A compromised workstation can gain access all the way to the domain controller.
Unused but active accounts belonging to former employees Access that is no longer monitored by anyone.

How a test is carried out

1

Scoping

We define the starting point, the scope of the domain and the time window, including any systems that should be excluded.

2

Reconnaissance

Capturing the domain structure: users, groups, permissions, trusts and configuration, using standard AD security analysis tools.

3

Identification of Escalation Paths

Analysing which combinations of permissions lead to elevated privileges, and mapping the most likely routes to Domain Admin.

4

Controlled Exploitation

Proving that an identified path actually works, in a controlled manner and without making changes to production permissions.

5

Report and Debrief

Handover of the attack paths as a traceable chain, reviewed together with your AD team.

What we don’t do

  • No changes to production permissions. We demonstrate access paths without permanently altering permissions.
  • No account locks due to mass password guessing. We obtain consent for the scope and lockout limits for password attacks in advance.
  • No disruption to domain operations. Active assessments are carried out in a controlled manner; we treat critical systems such as domain controllers with particular care.
  • Immediate notification in the event of an existing compromise. If we find evidence of an ongoing, genuine attack, we report this immediately rather than noting it in the final report.

What you provide

  • A standard user account without any special privileges, unless the Blackbox version is requested.
  • Network access to the domain, either on-site or via VPN.
  • A technical contact from the AD team for enquiries.
  • A rough overview of the domain structure, if available. This is not strictly necessary.

What you’ll take away from this

You’ll receive the attack paths as a coherent chain, not as a loose list of individual findings. That’s exactly what makes the difference: a single overly broad permission is rarely critical, but a chain of three such permissions leads to Domain Admin.

In addition, you’ll receive specific recommendations on security architecture, prioritised by impact, so that you can start with the measures that cut off the largest attack path, rather than working through individual findings in any order.

“Anyone who understands the vulnerabilities of Active Directory understands the mindset of an attacker.”

Active Directory Penetration Testing

A standard user account is sufficient for us as a starting point. During the initial consultation, we clarify the scope of the domain, the starting point and the timeframe.

  • No interference with production permissions
  • Escalation paths as a traceable chain
  • Prioritised according to the greatest attack vector
  • Alignment with BSI and Microsoft hardening guidelines

Frequently Asked Questions

What customers want to know before carrying out an Active Directory test.

The risk is low. We avoid destructive actions and mass account suspensions, and coordinate sensitive assessments in advance.

No. An unclear current status is often part of the problem itself and does not hinder the test.

We report this immediately and outside the normal reporting channels, rather than waiting until the final report.

Yes, the connection to the Cloud is part of the scope of the test, if it exists.

Annually as a guideline, and additionally following major structural changes such as a migration or merger.