Active Directory Penetration Testing

Anyone could request that certificate.

A template that lets the requester name the subject will happily name a domain administrator. A senior U.S. engineer follows that, and every other right you granted on purpose, to full domain control. When we reach the domain controller, we leave a card.

  1. User jdoe A standard domain user. Healthy
  2. Group Engineering Allowed to enrol. Healthy
  3. Cert template WorkstationAuth Enrollee supplies the subject. Healthy
  4. Group Domain Admins A certificate, and the domain. Domain Admin. Critical.
  • ADCSESC1 The right that opened each hop
  • Healthy What a health check sees, object by object

Nothing replaces skill. Illustrative path. Every enrolment right here was granted on purpose.

What We Test

A domain is a graph, and an attacker reads it as one. We enumerate every right, trust and delegation you have granted, then walk the shortest path we can find from an ordinary account to the top.

Kerberoasting & AS-REP Roasting

Service tickets any user can request, cracked offline. A quiet route to a service account.

Delegation Abuse

Unconstrained, constrained, and resource-based delegation set up wrong, used to impersonate admins.

ACL & Access-Rights Attacks

Excessive rights over users, groups, and objects that no scanner flags. We map and walk them.

Credential Attacks

LLMNR and NBT-NS poisoning, hash capture, pass-the-hash, and offline cracking.

Certificate Services (AD CS)

Misconfigured templates and enrollment rights, among the fastest routes to domain compromise today.

Hybrid & Entra ID

Entra Connect sync, federation, and seamless SSO: the seams where a foothold on one side reaches the other.

How the Attack Unfolds

Four steps, each done by hand, each documented. Real skill leaves evidence.

01

Foothold

Unauthenticated, or one standard user account, the way a real breach begins.

02

Enumeration

We map users, groups, rights, service accounts, and trusts to find the weak edges.

03

Escalation

We chain misconfigurations and credential attacks to climb toward privilege.

04

Domain Control

We prove how far the path goes, up to Domain Admin, with a card where we reached and the storyboard behind it.

Findings We See in the Wild

Not one of these would fail a scan. Chained, they are the route to Domain Admin.

Kerberoastable Service Accounts

Human-chosen passwords any domain user can request and crack offline.

Overprivileged Accounts & Groups

Rights far beyond the role, handing attackers an easy climb.

Dangerous Delegation

Delegation set up in ways that let an attacker impersonate privileged users.

Weak Domain Password Policies

Policies that look adequate on paper and fall to our cracking rigs in minutes.

Vulnerable Certificate Templates

AD CS misconfigurations that let a standard user enroll their way to domain privileges.

Risky Hybrid Sync

Entra Connect and federation gaps that let an attacker cross between on-prem and cloud.

Part of Your Internal Engagement

Active Directory testing is the identity core of an internal engagement, because that is where an attacker meets your domain. Scope it as the focus of an internal test, or as a targeted assessment when AD is the priority. We test remotely through the Raxis Transporter, a small device you plug in, or on site, and it pairs directly with our internal network penetration testing and segmentation validation.

Raxis Transporter remote penetration testing devices

What You Get

The report is the evidence trail, written by the engineer who walked the path, for the team that has to close it. Track status and findings in real time with Raxis One.

Executive Summary

A concise readout for leadership and auditors.

Technical Findings

Each with a severity rating, reproduction steps, and clear remediation.

Attack Storyboard

The whole path, from the account we started with to the domain controller.

Included Retest

We verify your fixes and deliver a clean final report, at no extra cost.

FAQ: Active Directory Penetration Testing

What is Active Directory penetration testing?

It is a test of the identity system behind your Windows network. Starting from a foothold a real attacker would have, our engineers enumerate the domain, exploit misconfigurations, crack weak service account passwords, and map the path from an ordinary user account toward full domain control.

How is it different from an internal network penetration test?

Active Directory testing is the identity-focused core of an internal engagement. An internal network penetration test covers your whole internal environment, including hosts, services, and segmentation; AD testing zeroes in on the domain itself. You can scope an engagement around Active Directory, or run a broader internal test that includes it.

Do you need a domain account to start?

Not necessarily. By default we start unauthenticated, capturing credentials from the network the way an attacker would. Many customers also ask for an assumed-breach test, where we begin with a standard user account to measure how far a phished employee's access reaches. We can run either or both.

Will testing lock out accounts or disrupt the domain?

We are careful with anything that could trigger lockouts. Password cracking on Kerberos and NTLM hashes happens offline, with no failed logins against your domain. Where we do test credentials live, we respect your lockout policy and coordinate thresholds during kickoff. Our goal is to prove risk, not to disrupt your users.

Do you test Entra ID and hybrid identity?

Yes. We test on-premises Active Directory, Entra ID (Azure AD), and the hybrid identity that connects them. Hybrid is where much of the real risk lives: Entra Connect sync, federated logins, and seamless SSO create trust relationships that let a foothold on one side open the door to the other. We test those seams directly, and pair this with our cloud penetration testing when your wider cloud environment is in scope.

How long does an Active Directory penetration test take?

Most engagements run one to two weeks, including reporting. The main drivers are the size of the domain, the number of trusts and forests in scope, and whether it is part of a broader internal test. We give you a firm timeline before we start.

What do we need to provide?

A place to plug in our Transporter device or network access to the domain, a point of contact, and, for an assumed-breach test, a standard user account. No domain admin credentials, no onsite visit, and nothing to install on your workstations.

Does this help with compliance?

Yes. Active Directory testing is part of the internal penetration testing that PCI DSS, SOC 2, HIPAA, GLBA, and CMMC require or strongly recommend, and it is increasingly expected by cyber insurance underwriters. Raxis reports are written to satisfy auditors and include an attestation letter you can share with customers and partners.

What drives the cost?

Scope is the main factor: the size of the domain, the number of domains, trusts, and forests, and whether Active Directory testing stands alone or sits inside a broader internal engagement. Contact us for a quote sized to your environment.

Who performs the testing?

Senior US-based Raxis engineers holding certifications such as OSCP and OSCE. No outsourcing, and no junior testers learning on your domain.

Request a quote

Tell Us What You Need Tested

We usually respond in one business day.

Please let us know what's on your mind. Include any details about your target environment, timeline, or compliance drivers.