Active Directory Pentesting
The crown jewels of enterprise — privilege paths, delegation abuse, and the road to domain dominance.
What we cover
- Privilege escalation paths from standard user to Domain Admin
- Kerberoasting, AS-REP roasting, and delegation abuse
- ACL, OU, and GPO misconfigurations
- Stale accounts, service accounts, and password policies
- Lateral movement and persistence techniques
- Trust relationships and cross-domain attack paths
How we test
Users, groups, ACLs, delegations, trusts, and service principal names — mapped into an attack graph.
Kerberoastable services, unconstrained delegation, writable ACLs, and GPO abuse — exploited safely with reversible proof.
We prove how far access extends — Domain Admin, Enterprise Admin, or cross-domain — with a path you can trace.
Every attack path documented with the specific fix, plus a prioritized hardening roadmap; retest included.
What you get
- Complete AD attack-path map
- Every exploitable path documented with evidence
- Prioritized hardening roadmap
- Free retest after remediation
The engagement at a glance
A short conversation about your environment. You receive a written scope, timeline, and fixed quote — no obligation.
Testing begins only with your written permission and agreed rules of engagement. Always.
A calendar agreed before we start, with an agreed communication plan while testing runs.
A verification pass over everything you fix — included in the price, not an add-on.
See the full engagement process → and how pricing is scoped in our public pricing guide.
Related research from Hmmnm
Common questions
Do you need Domain Admin credentials?
No. We start with a standard domain user (or even an unauthenticated position, depending on scope) and work upward — that is exactly what an attacker does.
Is AD testing safe for production?
Yes with the right rules of engagement. We use safe exploitation techniques, avoid destructive changes, and coordinate everything through an agreed communication plan. Emergency stop contact always available.
What is the difference from your network pentest?
Network pentest covers the broader infrastructure — perimeter, segmentation, services. AD pentest goes deep into the directory itself: identity, delegation, and the paths between them. Many clients do both.
Want this assessed for your environment?
A short scoping conversation is enough to get a fixed quote. No obligation — a researcher replies.
Start the conversation →