Active Directory Penetration Testing
Active Directory runs the identity behind almost every Windows network, which makes it the first thing a real attacker goes after. Raxis maps the path from one ordinary user account to full domain control, the same way an intruder would.
One Account Is Rarely Just One Account
In a healthy domain, a standard user can do very little. In most domains we test, that user is a starting point. We find the path from there to the top.
What We Test
A Raxis Active Directory penetration test works the way a real intrusion unfolds: gain a foothold, understand the domain, escalate, and move toward control. Every step is done by hand and documented.
Kerberoasting and AS-REP roasting
We request service tickets any domain user can ask for and crack the weak passwords behind them offline, a quiet path to service account compromise.
Delegation abuse
Unconstrained, constrained, and resource-based delegation set up incorrectly let us impersonate users, including domain administrators.
Access control and ACL attacks
Excessive rights over users, groups, and objects create escalation paths that no scanner flags. We map and exploit them.
Credential attacks
LLMNR and NBT-NS poisoning, hash capture, pass-the-hash, and offline cracking turn network position into working credentials.
Certificate services (AD CS)
Misconfigured certificate templates and enrollment rights are among the fastest routes to domain compromise we see today, and we test for them directly.
Hybrid and Entra ID attacks
Entra Connect sync, federated logins, and seamless SSO create trust between on-prem AD and the cloud. We test those seams, showing how a foothold on one side reaches the other.
How the Attack Unfolds
These are real vulnerabilities our engineers find in thick client applications again and again.

Across On-Prem, Entra ID, and Hybrid
Active Directory: Part of Your Internal Engagement

What You Get
Every Raxis Active Directory penetration test delivers everything you need to understand, fix, and prove your domain’s security. Track status, findings, and report delivery in real time with Raxis One.
Executive Summary
A concise summary written for leadership and auditors.
Technical Findings
Every finding includes a severity rating, reproduction steps, and clear remediation guidance.
Attack Storyboard
A step-by-step narrative shows exactly how we got in and how far we could go.
Included Retest
We verify your fixes and deliver a clean final report at no extra cost.
Findings We See in the Wild
These are real Active Directory weaknesses our engineers find again and again.
Kerberoastable Service Accounts
Service accounts with human-chosen passwords that any domain user can request and crack offline.
Overprivileged Accounts and Groups
Users and groups holding rights far beyond their role, handing attackers easy escalation.
Dangerous Delegation
Delegation configured in ways that let an attacker impersonate privileged users.
Weak Domain Password Policies
Policies that look adequate on paper but fall to our cracking rigs in minutes.
Vulnerable Certificate Templates
AD CS misconfigurations that let a standard user enroll their way to domain privileges.
Risky Hybrid Sync
Entra Connect and federation misconfigurations that let an attacker cross between on-prem AD and the cloud.
Active Directory Penetration Testing FAQ
Have questions about penetration testing? Want a quote or just a better sense of how we work? Reach out. We’ll answer your questions, walk you through our services, and put together a scope that fits your environment. No sales pressure, no obligation. Just a straightforward conversation with our team.