Active Directory

Active Directory penetration testing

Active Directory remains one of the highest-value targets in an internal compromise. Testing should map practical privilege paths, prove impact safely and leave defenders with a prioritised hardening plan.

What AD testing should cover

A strong AD test reviews identity hygiene, certificate services, delegation, ACLs, password policy, local admin controls, Kerberos abuse paths and sensitive group membership.

Why attack paths matter

Individual misconfigurations are useful, but attack paths show how an ordinary user or workstation foothold becomes domain compromise. This makes remediation easier to prioritise.

  • ADCS vulnerable certificate templates
  • Kerberoastable and AS-REP roastable accounts
  • Unconstrained or unsafe constrained delegation
  • Local admin reuse and missing LAPS coverage

How to make findings actionable

The report should state affected objects, evidence, impact, exact remediation, validation steps and where defensive monitoring can detect future attempts.

FAQ

Common questions

Is BloodHound enough for an AD pentest?

No. BloodHound is useful for path analysis, but findings still need manual validation, impact assessment and remediation context.

Do you test ADCS?

Yes. Certificate Services misconfigurations are common routes to domain compromise and should be part of AD testing.

Can AD findings be retested?

Yes. Retesting confirms whether privilege paths are removed and whether the original attack chain is broken.

Choose when your next test starts.

Standard within 10 business days. Rapid as soon as the next business day.

Book a call