Active Directory Pentesting

The crown jewels of enterprise — privilege paths, delegation abuse, and the road to domain dominance.

Why this matters: Active Directory is the keys to the kingdom — and the most commonly misconfigured system in enterprise. One weak delegation, one stale service account, one over-permissive ACL: each is a path from a standard user to Domain Admin. We trace those paths the way real attackers do, then help you cut them.

What we cover

  • Privilege escalation paths from standard user to Domain Admin
  • Kerberoasting, AS-REP roasting, and delegation abuse
  • ACL, OU, and GPO misconfigurations
  • Stale accounts, service accounts, and password policies
  • Lateral movement and persistence techniques
  • Trust relationships and cross-domain attack paths

How we test

1Enumerate

Users, groups, ACLs, delegations, trusts, and service principal names — mapped into an attack graph.

2Exploit paths

Kerberoastable services, unconstrained delegation, writable ACLs, and GPO abuse — exploited safely with reversible proof.

3Demonstrate impact

We prove how far access extends — Domain Admin, Enterprise Admin, or cross-domain — with a path you can trace.

4Report & harden

Every attack path documented with the specific fix, plus a prioritized hardening roadmap; retest included.

What you get

  • Complete AD attack-path map
  • Every exploitable path documented with evidence
  • Prioritized hardening roadmap
  • Free retest after remediation

The engagement at a glance

📞 Free scoping call

A short conversation about your environment. You receive a written scope, timeline, and fixed quote — no obligation.

✍️ Signed authorization

Testing begins only with your written permission and agreed rules of engagement. Always.

⏱️ Time-boxed delivery

A calendar agreed before we start, with an agreed communication plan while testing runs.

🔁 Retest included

A verification pass over everything you fix — included in the price, not an add-on.

See the full engagement process → and how pricing is scoped in our public pricing guide.

Related research from Hmmnm

Common questions

Do you need Domain Admin credentials?

No. We start with a standard domain user (or even an unauthenticated position, depending on scope) and work upward — that is exactly what an attacker does.

Is AD testing safe for production?

Yes with the right rules of engagement. We use safe exploitation techniques, avoid destructive changes, and coordinate everything through an agreed communication plan. Emergency stop contact always available.

What is the difference from your network pentest?

Network pentest covers the broader infrastructure — perimeter, segmentation, services. AD pentest goes deep into the directory itself: identity, delegation, and the paths between them. Many clients do both.

Authorization first, always. Testing happens only with your written permission and agreed rules of engagement — the same ethics that govern responsible disclosure on this site.

Want this assessed for your environment?

A short scoping conversation is enough to get a fixed quote. No obligation — a researcher replies.

Start the conversation →