Active Directory Penetration Testing
From one ordinary user account to full domain control, the way a real intruder moves.
Any Domain User Is a Foothold
Once an attacker has any authenticated account, from a phished employee or a cracked password, they can query the directory, enumerate privileges, and start hunting for the next step up.
Misconfiguration Beats Exploits
Domain compromise rarely comes from an unpatched server. It comes from delegation set up wrong, permissions granted too broadly, and service accounts with weak passwords.
The Blast Radius Is the Whole Domain
Reach Domain Admin and you own every workstation, server, and account. We show you exactly how reachable that is from where an attacker starts.
Kerberoasting and AS-REP roasting
We request service tickets any domain user can ask for and crack the weak passwords behind them offline, a quiet path to service account compromise.
Delegation abuse
Unconstrained, constrained, and resource-based delegation set up incorrectly let us impersonate users, including domain administrators.
Access control and ACL attacks
Excessive rights over users, groups, and objects create escalation paths that no scanner flags. We map and exploit them.
Credential attacks
LLMNR and NBT-NS poisoning, hash capture, pass-the-hash, and offline cracking turn network position into working credentials.
Certificate services (AD CS)
Misconfigured certificate templates and enrollment rights are among the fastest routes to domain compromise we see today, and we test for them directly.
Hybrid and Entra ID attacks
Entra Connect sync, federated logins, and seamless SSO create trust between on-prem AD and the cloud. We test those seams, showing how a foothold on one side reaches the other.
1. Foothold
We start from an unauthenticated position or a standard user account, matching how a real breach begins.
2. Enumeration
We map users, groups, permissions, service accounts, and trust relationships to find the weak links.
3. Escalation
We chain misconfigurations and credential attacks to climb from ordinary user toward privileged access.
4. Domain control
We demonstrate how far the path goes, up to and including Domain Admin, with proof and a full storyboard.
Executive Summary
A concise summary written for leadership and auditors.
Technical Findings
Every finding includes a severity rating, reproduction steps, and clear remediation guidance.
Attack Storyboard
A step-by-step narrative shows exactly how we got in and how far we could go.
Included Retest
We verify your fixes and deliver a clean final report at no extra cost.
Kerberoastable Service Accounts
Service accounts with human-chosen passwords that any domain user can request and crack offline.
Overprivileged Accounts and Groups
Users and groups holding rights far beyond their role, handing attackers easy escalation.
Dangerous Delegation
Delegation configured in ways that let an attacker impersonate privileged users.
Weak Domain Password Policies
Policies that look adequate on paper but fall to our cracking rigs in minutes.
Vulnerable Certificate Templates
AD CS misconfigurations that let a standard user enroll their way to domain privileges.
Risky Hybrid Sync
Entra Connect and federation misconfigurations that let an attacker cross between on-prem AD and the cloud.
FAQ: Active Directory Penetration Testing
What is Active Directory penetration testing?
It is a test of the identity system behind your Windows network. Starting from a foothold a real attacker would have, our engineers enumerate the domain, exploit misconfigurations, crack weak service account passwords, and map the path from an ordinary user account toward full domain control.
How is it different from an internal network penetration test?
Active Directory testing is the identity-focused core of an internal engagement. An internal network penetration test covers your whole internal environment, including hosts, services, and segmentation; AD testing zeroes in on the domain itself. You can scope an engagement around Active Directory, or run a broader internal test that includes it.
Do you need a domain account to start?
Not necessarily. By default we start unauthenticated, capturing credentials from the network the way an attacker would. Many customers also ask for an assumed-breach test, where we begin with a standard user account to measure how far a phished employee's access reaches. We can run either or both.
Will testing lock out accounts or disrupt the domain?
We are careful with anything that could trigger lockouts. Password cracking on Kerberos and NTLM hashes happens offline, with no failed logins against your domain. Where we do test credentials live, we respect your lockout policy and coordinate thresholds during kickoff. Our goal is to prove risk, not to disrupt your users.
Do you test Entra ID and hybrid identity?
Yes. We test on-premises Active Directory, Entra ID (Azure AD), and the hybrid identity that connects them. Hybrid is where much of the real risk lives: Entra Connect sync, federated logins, and seamless SSO create trust relationships that let a foothold on one side open the door to the other. We test those seams directly, and pair this with our cloud penetration testing when your wider cloud environment is in scope.
How long does an Active Directory penetration test take?
Most engagements run one to two weeks, including reporting. The main drivers are the size of the domain, the number of trusts and forests in scope, and whether it is part of a broader internal test. We give you a firm timeline before we start.
What do we need to provide?
A place to plug in our Transporter device or network access to the domain, a point of contact, and, for an assumed-breach test, a standard user account. No domain admin credentials, no onsite visit, and nothing to install on your workstations.
Does this help with compliance?
Yes. Active Directory testing is part of the internal penetration testing that PCI DSS, SOC 2, HIPAA, GLBA, and CMMC require or strongly recommend, and it is increasingly expected by cyber insurance underwriters. Raxis reports are written to satisfy auditors and include an attestation letter you can share with customers and partners.
What drives the cost?
Scope is the main factor: the size of the domain, the number of domains, trusts, and forests, and whether Active Directory testing stands alone or sits inside a broader internal engagement. Contact us for a quote sized to your environment.
Who performs the testing?
Senior US-based Raxis engineers holding certifications such as OSCP and OSCE. No outsourcing, and no junior testers learning on your domain.