Skip to content

SERVICE 03

Active Directory audit: how far a domain user can reach

An audit of your domain: escalation paths, Kerberos, vulnerable GPOs and obsolete or insecure trust relationships. Each path is exploited by hand until the impact is proven. Delivery includes the privilege path graph and a prioritised hardening plan.

  • Kerberos
  • GPO
  • Privilege escalation
  • Trust relationships
  • EDR evasion

Technical scope

  • Escalation paths to Domain Admin, step by step
  • Kerberoasting, AS-REP roasting and delegation abuse
  • Vulnerable GPOs and delegated permissions over OUs
  • Obsolete or insecure trust relationships between domains and forests
  • Manual validation of every path, with no tool output taken at face value
  • Service accounts and inherited permissions over the directory
  • Antivirus and EDR evasion during execution, within the limits set in the rules of engagement

Deliverables

  • Privilege path graph
  • Hardening plan prioritised by risk reduction
  • Detail of every technique with its ATT&CK reference
  • Detection recommendations for your team
  • Retest of every fix, included in the engagement

Audit phases

PHASE 01

Starting position

The team agrees the starting position with you in writing: an unprivileged user, a domain-joined machine or an assumed breach. Never with administrator credentials.

Rules of engagement
PHASE 02

Domain enumeration

The team enumerates users, groups, GPOs, access control lists, delegations and trust relationships. That inventory records the state of the domain within the agreed window and is the basis for the paths traced in the next phase.

Domain inventory
PHASE 03

Escalation and lateral movement

The team follows every path to Domain Admin: Kerberos, reused credentials, inherited permissions and misconfigured delegations. Within the agreed limits, the team evades the antivirus and EDR you have deployed, to measure what your defences catch and what they miss. Each path is taken until access is proven, and the team stops before causing any impact.

Privilege path graph
PHASE 04

Hardening

The graph delivered sets out every privilege path step by step. The team orders the hardening plan by risk reduction and implementation effort.

Prioritised plan

Frequently asked questions

What is the starting position?

The starting position is set in the scope statement: an unprivileged user, a domain-joined machine or an assumed breach. That statement also records the execution window and the notification channel. None of the three starts from administrator credentials.

What is reviewed inside the domain?

The review reaches the whole directory: identities, GPOs, delegated permissions over OUs, Kerberos and trusts between domains and forests. The team tests every path by hand and stops as soon as access is proven, before domain availability is affected. A single point of contact is available throughout the execution window.

What does the delivery include?

The report is signed by the team that ran the audit, and no phase is subcontracted. Every path comes with its reproduction steps and its evidence, so your team can repeat it. The closure report records the final status of each finding once the retest is done.

Published findings of this kind

Request a proposal with the scope defined

Tell us which domain you want tested. We reply within 24 hours.

Request an auditCall