Active Directory Penetration Testing
Anyone could request that certificate.
A template that lets the requester name the subject will happily name a domain administrator. A senior U.S. engineer follows that, and every other right you granted on purpose, to full domain control. When we reach the domain controller, we leave a card.
- User jdoe A standard domain user. Healthy
- Group Engineering Allowed to enrol. Healthy
- Cert template WorkstationAuth Enrollee supplies the subject. Healthy
- Group Domain Admins A certificate, and the domain. Domain Admin. Critical.
-
ADCSESC1The right that opened each hop - Healthy What a health check sees, object by object
Nothing replaces skill. Illustrative path. Every enrolment right here was granted on purpose.
Kerberoasting & AS-REP Roasting
Service tickets any user can request, cracked offline. A quiet route to a service account.
Delegation Abuse
Unconstrained, constrained, and resource-based delegation set up wrong, used to impersonate admins.
ACL & Access-Rights Attacks
Excessive rights over users, groups, and objects that no scanner flags. We map and walk them.
Credential Attacks
LLMNR and NBT-NS poisoning, hash capture, pass-the-hash, and offline cracking.
Certificate Services (AD CS)
Misconfigured templates and enrollment rights, among the fastest routes to domain compromise today.
Hybrid & Entra ID
Entra Connect sync, federation, and seamless SSO: the seams where a foothold on one side reaches the other.
01
Foothold
Unauthenticated, or one standard user account, the way a real breach begins.
02
Enumeration
We map users, groups, rights, service accounts, and trusts to find the weak edges.
03
Escalation
We chain misconfigurations and credential attacks to climb toward privilege.
04
Domain Control
We prove how far the path goes, up to Domain Admin, with a card where we reached and the storyboard behind it.
Kerberoastable Service Accounts
Human-chosen passwords any domain user can request and crack offline.
Overprivileged Accounts & Groups
Rights far beyond the role, handing attackers an easy climb.
Dangerous Delegation
Delegation set up in ways that let an attacker impersonate privileged users.
Weak Domain Password Policies
Policies that look adequate on paper and fall to our cracking rigs in minutes.
Vulnerable Certificate Templates
AD CS misconfigurations that let a standard user enroll their way to domain privileges.
Risky Hybrid Sync
Entra Connect and federation gaps that let an attacker cross between on-prem and cloud.
Executive Summary
A concise readout for leadership and auditors.
Technical Findings
Each with a severity rating, reproduction steps, and clear remediation.
Attack Storyboard
The whole path, from the account we started with to the domain controller.
Included Retest
We verify your fixes and deliver a clean final report, at no extra cost.
FAQ: Active Directory Penetration Testing
What is Active Directory penetration testing?
It is a test of the identity system behind your Windows network. Starting from a foothold a real attacker would have, our engineers enumerate the domain, exploit misconfigurations, crack weak service account passwords, and map the path from an ordinary user account toward full domain control.
How is it different from an internal network penetration test?
Active Directory testing is the identity-focused core of an internal engagement. An internal network penetration test covers your whole internal environment, including hosts, services, and segmentation; AD testing zeroes in on the domain itself. You can scope an engagement around Active Directory, or run a broader internal test that includes it.
Do you need a domain account to start?
Not necessarily. By default we start unauthenticated, capturing credentials from the network the way an attacker would. Many customers also ask for an assumed-breach test, where we begin with a standard user account to measure how far a phished employee's access reaches. We can run either or both.
Will testing lock out accounts or disrupt the domain?
We are careful with anything that could trigger lockouts. Password cracking on Kerberos and NTLM hashes happens offline, with no failed logins against your domain. Where we do test credentials live, we respect your lockout policy and coordinate thresholds during kickoff. Our goal is to prove risk, not to disrupt your users.
Do you test Entra ID and hybrid identity?
Yes. We test on-premises Active Directory, Entra ID (Azure AD), and the hybrid identity that connects them. Hybrid is where much of the real risk lives: Entra Connect sync, federated logins, and seamless SSO create trust relationships that let a foothold on one side open the door to the other. We test those seams directly, and pair this with our cloud penetration testing when your wider cloud environment is in scope.
How long does an Active Directory penetration test take?
Most engagements run one to two weeks, including reporting. The main drivers are the size of the domain, the number of trusts and forests in scope, and whether it is part of a broader internal test. We give you a firm timeline before we start.
What do we need to provide?
A place to plug in our Transporter device or network access to the domain, a point of contact, and, for an assumed-breach test, a standard user account. No domain admin credentials, no onsite visit, and nothing to install on your workstations.
Does this help with compliance?
Yes. Active Directory testing is part of the internal penetration testing that PCI DSS, SOC 2, HIPAA, GLBA, and CMMC require or strongly recommend, and it is increasingly expected by cyber insurance underwriters. Raxis reports are written to satisfy auditors and include an attestation letter you can share with customers and partners.
What drives the cost?
Scope is the main factor: the size of the domain, the number of domains, trusts, and forests, and whether Active Directory testing stands alone or sits inside a broader internal engagement. Contact us for a quote sized to your environment.
Who performs the testing?
Senior US-based Raxis engineers holding certifications such as OSCP and OSCE. No outsourcing, and no junior testers learning on your domain.