Active Directory penetration testing: audit your AD security

Active Directory is the centerpiece of any corporate Microsoft environment. It's also the number one target of ransomware groups. A misconfigured AD can give an attacker full control over your network in a matter of hours.

AD is the fastest path to disaster

Most enterprise ransomware attacks follow the same pattern: compromise a user machine, move laterally across the network, obtain credentials with elevated privileges and, finally, compromise the Domain Controller. Active Directory is the thread that ties all those steps together. Kerberoasting, Pass-the-Hash, ACL abuse, GPO misconfiguration, service accounts with excessive privileges... There are hundreds of paths an attacker can follow. We map them all before anyone uses them.

What we assess in an AD audit

  • Accounts with excessive privileges: Domain Admins, service accounts
  • Kerberoasting and AS-REP Roasting: accounts with exploitable SPNs
  • ACL and permission misconfigurations on AD objects
  • Dangerous GPOs: script execution, weak password policies
  • Privilege escalation paths (attack paths) with BloodHound
  • Legacy protocols: NTLM, NTLMv1, LLMNR, NBT-NS
  • Unconstrained or poorly configured constrained Kerberos delegation
  • General hardening: SMB signing, LDAP signing, Protected Users group

How we audit Active Directory

  1. Initial enumeration: With network access (standard user or internal attacker perspective), we enumerate users, groups, GPOs, SPNs and ACLs.
  2. BloodHound analysis: We visualize the attack paths from any compromised user to Domain Admin.
  3. Controlled exploitation testing: We run real attacks (Kerberoasting, Pass-the-Hash, ACL abuse) to confirm what works in your specific environment.
  4. Escalation and pivoting: We document how far an attacker starting from a standard user account can get.
  5. Prioritized remediation report: We classify findings by urgency and difficulty of correction, with concrete PowerShell/GPO instructions.

Deliverables

  • Attack path map (BloodHound) exported and annotated
  • Technical report with each finding, impact and concrete remediation steps
  • Diagnostic script to verify the most critical fixes
  • Executive report: risk level, critical surfaces and action plan
  • Meeting with the systems team to review the fixes

Who should audit it?

  • Any company with more than 20 employees using Windows in a domain
  • Environments that have suffered a ransomware incident or want to prevent one
  • Companies in the process of ISO 27001 certification or NIS2 adequacy
  • Organizations with legacy environments (Windows Server 2008-2012)
  • Companies after a merger or acquisition with AD integrations

Frequently asked questions

Do you need admin access to run the audit?

Not necessarily. We can start with a standard user account to simulate exactly what an attacker who has compromised a workstation would do. Depending on the agreed scope, we can escalate to higher privileges in a controlled way.

What impact does the audit have on the production environment?

Minimal. By default we avoid any destructive action or anything that could cause mass account lockouts or service interruptions. Everything is agreed in advance.

Do you also harden AD once the problems are identified?

The audit includes detailed remediation instructions. If you need us to implement the fixes directly, we can quote it as an additional service.

How often should Active Directory be audited?

At least once a year and after major infrastructure changes (migrations, new business units, mergers). More dynamic environments should do it every 6 months.