Skip to content
Raxis X Logo
  • Home
  • Services
      Core Services
      Penetration
      Testing
      Pentest
      As A Service
      Red Team Icon
      Adversary
      Simulation
      Cybersecurity Services Icon
      Cybersecurity
      Services
      Pentest Specialties
    • AI & Large Language Models
    • API Security
    • Blockchain & Crypto
    • Cloud & VPC
    • Internal Networks
    • External Networks and Internet
    • Internet of Things (IoT)
    • Mobile Applications
    • Operational Technology (OT)
    • Phishing & Vishing
    • Physical & Onsite
    • Salesforce Applications
    • Thick Client Application
    • Web Application
    • Wireless Networks
    • Cybersecurity Services
    • Attack Surface Management
    • Breach and Attack Simulation
    • Cybersecurity Code Review
  • Industries
      Critical Infrastructure
    • Energy
    • Communications
    • Transportation
    • Water
    • Compliance Driven
    • Finance and Banking
    • GLBA Safeguards Rule
    • Healthcare
    • HIPAA
    • ISO 27001
    • PCI DSS / Credit Cards
    • SOC 2
    • Blockchain and Cryptocurrency
    • Education
    • Government Agencies
    • Manufacturing
    • Media and Entertainment
    • Technology and Software Development
    • Social Media
  • Resources
      Company Information
    • About Raxis
    • Become a Raxis Partner
    • Careers
    • Certifications
    • Meet Our Team
    • Trust Center
    • Security Research
    • Resources
    • Raxis One
    • AI vs. Human Penetration Testing
    • Penetration Test Glossary
    • Red, Blue, and Purple Teams
    • Transporter Remote Pentesting
    • What is a Penetration Test?
    • The Exploit Blog
    • About These “Top 10 Pentesting Companies” Listicles
    • Signup for Raxis Newsletter
  • About Us
Contact Raxis Login
Raxis X Logo
Contact
  • Home
  • Services
      Core Services
      Penetration
      Testing
      Pentest
      As A Service
      Red Team Icon
      Adversary
      Simulation
      Cybersecurity Services Icon
      Cybersecurity
      Services
      Pentest Specialties
    • AI & Large Language Models
    • API Security
    • Blockchain & Crypto
    • Cloud & VPC
    • Internal Networks
    • External Networks and Internet
    • Internet of Things (IoT)
    • Mobile Applications
    • Operational Technology (OT)
    • Phishing & Vishing
    • Physical & Onsite
    • Salesforce Applications
    • Thick Client Application
    • Web Application
    • Wireless Networks
    • Cybersecurity Services
    • Attack Surface Management
    • Breach and Attack Simulation
    • Cybersecurity Code Review
  • Industries
      Critical Infrastructure
    • Energy
    • Communications
    • Transportation
    • Water
    • Compliance Driven
    • Finance and Banking
    • GLBA Safeguards Rule
    • Healthcare
    • HIPAA
    • ISO 27001
    • PCI DSS / Credit Cards
    • SOC 2
    • Blockchain and Cryptocurrency
    • Education
    • Government Agencies
    • Manufacturing
    • Media and Entertainment
    • Technology and Software Development
    • Social Media
  • Resources
      Company Information
    • About Raxis
    • Become a Raxis Partner
    • Careers
    • Certifications
    • Meet Our Team
    • Trust Center
    • Security Research
    • Resources
    • Raxis One
    • AI vs. Human Penetration Testing
    • Penetration Test Glossary
    • Red, Blue, and Purple Teams
    • Transporter Remote Pentesting
    • What is a Penetration Test?
    • The Exploit Blog
    • About These “Top 10 Pentesting Companies” Listicles
    • Signup for Raxis Newsletter
  • About Us

Active Directory Penetration Testing

Active Directory runs the identity behind almost every Windows network, which makes it the first thing a real attacker goes after. Raxis maps the path from one ordinary user account to full domain control, the same way an intruder would.

Request a Quote Schedule Demo

One Account Is Rarely Just One Account

In a healthy domain, a standard user can do very little. In most domains we test, that user is a starting point. We find the path from there to the top.

OS icon

Any Domain User Is a Foothold

Once an attacker has any authenticated account, from a phished employee or a cracked password, they can query the directory, enumerate privileges, and start hunting for the next step up.

user with puzzle and nodes icon

Misconfiguration Beats Exploits

Domain compromise rarely comes from an unpatched server. It comes from delegation set up wrong, permissions granted too broadly, and service accounts with weak passwords.

network fear icon

The Blast Radius Is the Whole Domain

Reach Domain Admin and you own every workstation, server, and account. We show you exactly how reachable that is from where an attacker starts.

Request A Quote Schedule Demo

What We Test

A Raxis Active Directory penetration test works the way a real intrusion unfolds: gain a foothold, understand the domain, escalate, and move toward control. Every step is done by hand and documented.

Kerberoasting and AS-REP roasting

We request service tickets any domain user can ask for and crack the weak passwords behind them offline, a quiet path to service account compromise.

Delegation abuse

Unconstrained, constrained, and resource-based delegation set up incorrectly let us impersonate users, including domain administrators.

Access control and ACL attacks

Excessive rights over users, groups, and objects create escalation paths that no scanner flags. We map and exploit them.

Credential attacks

LLMNR and NBT-NS poisoning, hash capture, pass-the-hash, and offline cracking turn network position into working credentials.

Certificate services (AD CS)

Misconfigured certificate templates and enrollment rights are among the fastest routes to domain compromise we see today, and we test for them directly.

Hybrid and Entra ID attacks

Entra Connect sync, federated logins, and seamless SSO create trust between on-prem AD and the cloud. We test those seams, showing how a foothold on one side reaches the other.

How the Attack Unfolds

These are real vulnerabilities our engineers find in thick client applications again and again.

1. Foothold

We start from an unauthenticated position or a standard user account, matching how a real breach begins.

2. Enumeration

We map users, groups, permissions, service accounts, and trust relationships to find the weak links.

3. Escalation

We chain misconfigurations and credential attacks to climb from ordinary user toward privileged access.

4. Domain control

We demonstrate how far the path goes, up to and including Domain Admin, with proof and a full storyboard.

Illuminated cargo cranes at the Port of Baltimore with stacked containers at dusk.

Across On-Prem, Entra ID, and Hybrid

Most organizations no longer run identity in one place. On-premises Active Directory syncs to Entra ID, users log in through federation, and trust flows both ways. That in-between space is where we find some of the most serious attack paths, because each side is often tested alone and the seams between them are tested by no one. Raxis tests your full identity footprint in one engagement: on-prem AD, Entra ID, and the hybrid connections that join them.
Learn More About Operational Technology Learn More About Physical Pentest

Active Directory: Part of Your Internal Engagement

Active Directory testing lives inside a Raxis internal network penetration test, because that is where an attacker meets your domain. Book it as the focus of an internal engagement, or as a targeted assessment when AD is your priority. We test remotely through the Raxis Transporter, a small device you plug into your network, or on site when you prefer. Either way it pairs directly with our full internal network penetration testing and segmentation validation.
Learn More About Remote Testing
Transporter Remote Pentest Devices

What You Get

Every Raxis Active Directory penetration test delivers everything you need to understand, fix, and prove your domain’s security. Track status, findings, and report delivery in real time with Raxis One.

Request Sample Report

Executive Summary

A concise summary written for leadership and auditors.

Technical Findings

Every finding includes a severity rating, reproduction steps, and clear remediation guidance.

Attack Storyboard

A step-by-step narrative shows exactly how we got in and how far we could go.

Included Retest

We verify your fixes and deliver a clean final report at no extra cost.

Findings We See in the Wild

These are real Active Directory weaknesses our engineers find again and again.

Kerberoastable Service Accounts

Service accounts with human-chosen passwords that any domain user can request and crack offline.

Overprivileged Accounts and Groups

Users and groups holding rights far beyond their role, handing attackers easy escalation.

Dangerous Delegation

Delegation configured in ways that let an attacker impersonate privileged users.

Weak Domain Password Policies

Policies that look adequate on paper but fall to our cracking rigs in minutes.

Vulnerable Certificate Templates

AD CS misconfigurations that let a standard user enroll their way to domain privileges.

Risky Hybrid Sync

Entra Connect and federation misconfigurations that let an attacker cross between on-prem AD and the cloud.

Active Directory Penetration Testing FAQ

It is a test of the identity system behind your Windows network. Starting from a foothold a real attacker would have, our engineers enumerate the domain, exploit misconfigurations, crack weak service account passwords, and map the path from an ordinary user account toward full domain control.

Active Directory testing is the identity-focused core of an internal engagement. An internal network penetration test covers your whole internal environment, including hosts, services, and segmentation; AD testing zeroes in on the domain itself. You can scope an engagement around Active Directory, or run a broader internal test that includes it.

Not necessarily. By default we start unauthenticated, capturing credentials from the network the way an attacker would. Many customers also ask for an assumed-breach test, where we begin with a standard user account to measure how far a phished employee’s access reaches. We can run either or both.

We are careful with anything that could trigger lockouts. Password cracking on Kerberos and NTLM hashes happens offline, with no failed logins against your domain. Where we do test credentials live, we respect your lockout policy and coordinate thresholds during kickoff. Our goal is to prove risk, not to disrupt your users.

Yes. We test on-premises Active Directory, Entra ID (Azure AD), and the hybrid identity that connects them. Hybrid is where much of the real risk lives: Entra Connect sync, federated logins, and seamless SSO create trust relationships that let a foothold on one side open the door to the other. We test those seams directly, and pair this with our cloud penetration testing when your wider cloud environment is in scope.

Most engagements run one to two weeks, including reporting. The main drivers are the size of the domain, the number of trusts and forests in scope, and whether it is part of a broader internal test. We give you a firm timeline before we start.

A place to plug in our Transporter device or network access to the domain, a point of contact, and, for an assumed-breach test, a standard user account. No domain admin credentials, no onsite visit, and nothing to install on your workstations.

Yes. Active Directory testing is part of the internal penetration testing that PCI DSS, SOC 2, HIPAA, GLBA, and CMMC require or strongly recommend, and it is increasingly expected by cyber insurance underwriters. Raxis reports are written to satisfy auditors and include an attestation letter you can share with customers and partners.

Scope is the main factor: the size of the domain, the number of domains, trusts, and forests, and whether Active Directory testing stands alone or sits inside a broader internal engagement. Contact us for a quote sized to your environment.

Senior US-based Raxis engineers holding certifications such as OSCP and OSCE. No outsourcing, and no junior testers learning on your domain.

Let’s Chat About Your Project

Have questions about penetration testing? Want a quote or just a better sense of how we work? Reach out. We’ll answer your questions, walk you through our services, and put together a scope that fits your environment. No sales pressure, no obligation. Just a straightforward conversation with our team.

Request a Quote Schedule Demo
Raxis Company Logo
2870 Peachtree Road
Suite #915-8924
Atlanta, GA 30305 USA
+1 678.421.4544
Contact Us Online
  • Facebook
  • X
  • Instagram
  • LinkedIn
  • YouTube
Company Information
  • About Raxis
  • Careers
  • Terms and Conditions
  • Trust Center
  • Privacy Policy
  • Partner Program
  • Sign Up For Our Newsletter
Resources
  • The Exploit Blog
  • Penetration Test Glossary
  • What is a Penetration Test?
Content Update On August 12, 2026 By Mark Puckett – Raxis
©2026 Raxis LLC