Starting position
The team agrees the starting position with you in writing: an unprivileged user, a domain-joined machine or an assumed breach. Never with administrator credentials.
SERVICE 03
An audit of your domain: escalation paths, Kerberos, vulnerable GPOs and obsolete or insecure trust relationships. Each path is exploited by hand until the impact is proven. Delivery includes the privilege path graph and a prioritised hardening plan.
The team agrees the starting position with you in writing: an unprivileged user, a domain-joined machine or an assumed breach. Never with administrator credentials.
The team enumerates users, groups, GPOs, access control lists, delegations and trust relationships. That inventory records the state of the domain within the agreed window and is the basis for the paths traced in the next phase.
The team follows every path to Domain Admin: Kerberos, reused credentials, inherited permissions and misconfigured delegations. Within the agreed limits, the team evades the antivirus and EDR you have deployed, to measure what your defences catch and what they miss. Each path is taken until access is proven, and the team stops before causing any impact.
The graph delivered sets out every privilege path step by step. The team orders the hardening plan by risk reduction and implementation effort.
The starting position is set in the scope statement: an unprivileged user, a domain-joined machine or an assumed breach. That statement also records the execution window and the notification channel. None of the three starts from administrator credentials.
The review reaches the whole directory: identities, GPOs, delegated permissions over OUs, Kerberos and trusts between domains and forests. The team tests every path by hand and stops as soon as access is proven, before domain availability is affected. A single point of contact is available throughout the execution window.
The report is signed by the team that ran the audit, and no phase is subcontracted. Every path comes with its reproduction steps and its evidence, so your team can repeat it. The closure report records the final status of each finding once the retest is done.
Tell us which domain you want tested. We reply within 24 hours.