Active Directory Penetration Testing

From one ordinary user account to full domain control, the way a real intruder moves.

Any Domain User Is a Foothold

Once an attacker has any authenticated account, from a phished employee or a cracked password, they can query the directory, enumerate privileges, and start hunting for the next step up.

Misconfiguration Beats Exploits

Domain compromise rarely comes from an unpatched server. It comes from delegation set up wrong, permissions granted too broadly, and service accounts with weak passwords.

The Blast Radius Is the Whole Domain

Reach Domain Admin and you own every workstation, server, and account. We show you exactly how reachable that is from where an attacker starts.

What We Test

A Raxis Active Directory penetration test works the way a real intrusion unfolds: gain a foothold, understand the domain, escalate, and move toward control. Every step is done by hand and documented.

Kerberoasting and AS-REP roasting

We request service tickets any domain user can ask for and crack the weak passwords behind them offline, a quiet path to service account compromise.

Delegation abuse

Unconstrained, constrained, and resource-based delegation set up incorrectly let us impersonate users, including domain administrators.

Access control and ACL attacks

Excessive rights over users, groups, and objects create escalation paths that no scanner flags. We map and exploit them.

Credential attacks

LLMNR and NBT-NS poisoning, hash capture, pass-the-hash, and offline cracking turn network position into working credentials.

Certificate services (AD CS)

Misconfigured certificate templates and enrollment rights are among the fastest routes to domain compromise we see today, and we test for them directly.

Hybrid and Entra ID attacks

Entra Connect sync, federated logins, and seamless SSO create trust between on-prem AD and the cloud. We test those seams, showing how a foothold on one side reaches the other.

How the Attack Unfolds

These are real vulnerabilities our engineers find in thick client applications again and again.

1. Foothold

We start from an unauthenticated position or a standard user account, matching how a real breach begins.

2. Enumeration

We map users, groups, permissions, service accounts, and trust relationships to find the weak links.

3. Escalation

We chain misconfigurations and credential attacks to climb from ordinary user toward privileged access.

4. Domain control

We demonstrate how far the path goes, up to and including Domain Admin, with proof and a full storyboard.

Illuminated cargo cranes at the Port of Baltimore with stacked containers at dusk.

Across On-Prem, Entra ID, and Hybrid

Most organizations no longer run identity in one place. On-premises Active Directory syncs to Entra ID, users log in through federation, and trust flows both ways. That in-between space is where we find some of the most serious attack paths, because each side is often tested alone and the seams between them are tested by no one. Raxis tests your full identity footprint in one engagement: on-prem AD, Entra ID, and the hybrid connections that join them.

Active Directory: Part of Your Internal Engagement

Active Directory testing lives inside a Raxis internal network penetration test, because that is where an attacker meets your domain. Book it as the focus of an internal engagement, or as a targeted assessment when AD is your priority. We test remotely through the Raxis Transporter, a small device you plug into your network, or on site when you prefer. Either way it pairs directly with our full internal network penetration testing and segmentation validation.

Transporter Remote Pentest Devices

What You Get

Every Raxis Active Directory penetration test delivers everything you need to understand, fix, and prove your domain’s security. Track status, findings, and report delivery in real time with Raxis One.

Executive Summary

A concise summary written for leadership and auditors.

Technical Findings

Every finding includes a severity rating, reproduction steps, and clear remediation guidance.

Attack Storyboard

A step-by-step narrative shows exactly how we got in and how far we could go.

Included Retest

We verify your fixes and deliver a clean final report at no extra cost.

Findings We See in the Wild

These are real Active Directory weaknesses our engineers find again and again.

Kerberoastable Service Accounts

Service accounts with human-chosen passwords that any domain user can request and crack offline.

Overprivileged Accounts and Groups

Users and groups holding rights far beyond their role, handing attackers easy escalation.

Dangerous Delegation

Delegation configured in ways that let an attacker impersonate privileged users.

Weak Domain Password Policies

Policies that look adequate on paper but fall to our cracking rigs in minutes.

Vulnerable Certificate Templates

AD CS misconfigurations that let a standard user enroll their way to domain privileges.

Risky Hybrid Sync

Entra Connect and federation misconfigurations that let an attacker cross between on-prem AD and the cloud.

FAQ: Active Directory Penetration Testing

What is Active Directory penetration testing?

It is a test of the identity system behind your Windows network. Starting from a foothold a real attacker would have, our engineers enumerate the domain, exploit misconfigurations, crack weak service account passwords, and map the path from an ordinary user account toward full domain control.

How is it different from an internal network penetration test?

Active Directory testing is the identity-focused core of an internal engagement. An internal network penetration test covers your whole internal environment, including hosts, services, and segmentation; AD testing zeroes in on the domain itself. You can scope an engagement around Active Directory, or run a broader internal test that includes it.

Do you need a domain account to start?

Not necessarily. By default we start unauthenticated, capturing credentials from the network the way an attacker would. Many customers also ask for an assumed-breach test, where we begin with a standard user account to measure how far a phished employee's access reaches. We can run either or both.

Will testing lock out accounts or disrupt the domain?

We are careful with anything that could trigger lockouts. Password cracking on Kerberos and NTLM hashes happens offline, with no failed logins against your domain. Where we do test credentials live, we respect your lockout policy and coordinate thresholds during kickoff. Our goal is to prove risk, not to disrupt your users.

Do you test Entra ID and hybrid identity?

Yes. We test on-premises Active Directory, Entra ID (Azure AD), and the hybrid identity that connects them. Hybrid is where much of the real risk lives: Entra Connect sync, federated logins, and seamless SSO create trust relationships that let a foothold on one side open the door to the other. We test those seams directly, and pair this with our cloud penetration testing when your wider cloud environment is in scope.

How long does an Active Directory penetration test take?

Most engagements run one to two weeks, including reporting. The main drivers are the size of the domain, the number of trusts and forests in scope, and whether it is part of a broader internal test. We give you a firm timeline before we start.

What do we need to provide?

A place to plug in our Transporter device or network access to the domain, a point of contact, and, for an assumed-breach test, a standard user account. No domain admin credentials, no onsite visit, and nothing to install on your workstations.

Does this help with compliance?

Yes. Active Directory testing is part of the internal penetration testing that PCI DSS, SOC 2, HIPAA, GLBA, and CMMC require or strongly recommend, and it is increasingly expected by cyber insurance underwriters. Raxis reports are written to satisfy auditors and include an attestation letter you can share with customers and partners.

What drives the cost?

Scope is the main factor: the size of the domain, the number of domains, trusts, and forests, and whether Active Directory testing stands alone or sits inside a broader internal engagement. Contact us for a quote sized to your environment.

Who performs the testing?

Senior US-based Raxis engineers holding certifications such as OSCP and OSCE. No outsourcing, and no junior testers learning on your domain.

Request a quote

Tell Us What You Need Tested

We usually respond in one business day.

Please let us know what's on your mind. Include any details about your target environment, timeline, or compliance drivers.