Skip to content

Network

Active Directory
Security Assessment

Starts at $6,000, fixed scope, free retest. See all pricing →

Get a fixed quote

Reply in one business day

Senior certified testers, manual-first185+ years combined experienceOnboarding within 24 hoursFree retest includedOur methodology

When you need it

When Active Directory needs its own assessment

The situations that bring teams to this engagement, and where it fits alongside the rest of your program.

  • Active Directory has grown for years, and nobody can say how far one ordinary account reaches.
  • A cyber insurer or a customer questionnaire asked specifically about domain admin exposure and privileged access.
  • A phishing incident or a compromised account raised the question of what that access could have reached in the domain.
  • You want the Active Directory attack paths tested in depth, without the full internal network test of every host and segment.
  • You are moving to hybrid identity with Entra Connect and want the on-premises-to-cloud paths tested before they set.

Definition

What is an Active Directory security assessment?

Almost every internal network compromise ends in Active Directory, because Active Directory holds the credentials, the trust, and the keys to everything else. An Active Directory security assessment starts where a real intrusion starts, with one ordinary user account or one workstation, and works toward Domain Admin the way an attacker would, so you learn the exact paths that exist and the small set of fixes that close most of them.

It costs $6,000 for one domain of up to a few hundred hosts, the same as the internal network Small tier, with every testing day spent on the domain. When you also need the hosts, segmentation, and services around the domain tested, the full internal network penetration test covers all of it.

Why AD

Why Active Directory is the target

A Windows domain is a trust system. Every user, computer, service, and group is an object, and the relationships between them decide who can do what. Those relationships accumulate for years: a help-desk group given rights to reset passwords, a service account added to Domain Admins to make a backup job work, a legacy server that still speaks protocols the rest of the network abandoned. Attackers do not exploit Active Directory so much as read it, find the relationships that were never meant to exist, and follow them.

That is why the internal test spends most of its time on the domain, and why an external test that never reaches the inside tells you little about how a breach would actually unfold. This assessment concentrates the whole engagement on that domain, so the attack paths are mapped in depth.

What we look for

Active Directory attack paths we hunt for

These are the weaknesses that turn one ordinary account into control of the domain. We test each one from the account you give us and prove the paths that actually work.

Kerberos attacks

The service and account attacks that turn a standard user into a set of crackable or reusable credentials.

We test for

  • Kerberoasting of service accounts
  • AS-REP roasting of accounts without pre-authentication
  • Ticket abuse, including golden and silver tickets in scope
  • Weak service-account passwords
  • Password spraying within agreed lockout thresholds

Delegation and ACL abuse

The permissions and trust relationships that accumulate for years and quietly become escalation paths.

We test for

  • Unconstrained, constrained, and resource-based delegation
  • Dangerous ACLs on users, groups, and computers
  • GenericAll, WriteDACL, and reset-password rights
  • Nested group membership that grants more than intended
  • GPO abuse and misconfiguration

Certificate Services (ADCS)

The newer, high-impact escalation path: certificate templates that let an ordinary user mint credentials for anyone.

We test for

  • Vulnerable certificate templates (ESC1 through ESC8)
  • Enrollment and issuance policy weaknesses
  • CA configuration and access control
  • Certificate-based authentication abuse
  • NTLM relay to the certificate service

Credential exposure

The secrets sitting where a standard user can already reach them, before any exploit is needed.

We test for

  • Passwords in shares, scripts, and GPO preferences
  • LAPS coverage and local-administrator reuse
  • Stale, privileged, and never-disabled accounts
  • Cleartext and reversibly stored credentials
  • Cached and in-memory credential exposure

Coercion and relay

The protocols that can be tricked into authenticating to an attacker, then relayed onward to escalate.

We test for

  • LLMNR, NBT-NS, and mDNS poisoning
  • NTLM relay to LDAP, SMB, and ADCS
  • Authentication coercion (PetitPotam-style)
  • SMB signing and channel-binding gaps
  • Machine-account and printer-bug paths

Hybrid identity (Entra ID)

The bridge between on-premises Active Directory and the cloud it syncs to, where an on-premises foothold becomes a cloud one.

We test for

  • Entra Connect and password hash sync abuse
  • Seamless single sign-on and pass-through authentication
  • On-premises-to-cloud and cloud-to-on-premises pivots
  • Synced privileged accounts and conditional access gaps
  • Cloud admin paths that begin on premises

Where it starts

Where the assessment starts

The tester starts with what an attacker holds after a successful phishing email or a compromised laptop: a standard domain user account with no special privileges, or a workstation on the internal network with no credentials at all. Both are realistic, and we agree which one, or both, during scoping.

The tester connects through a small device shipped to the office or a VPN you provide, so there is no travel and no one has to host a visitor, or works on site where you prefer. Testing runs under written rules of engagement: no changes to domain controllers, password spraying only within agreed lockout thresholds, and agreed windows. For the same starting point across the whole internal estate, see our assumed breach internal test; for the covert version that also grades detection, see the red team.

The tooling

The tools we use, explained

We use the same tooling attackers do, and we have written about most of it: BloodHound for mapping the attack paths through the domain, Impacket and NetExec for enumeration and lateral movement, Responder for poisoning and relay, Kerbrute for Kerberos enumeration, and Evil-WinRM for remote execution.

Every step is mapped to MITRE ATT&CK, so your defenders can replay the timeline against their alerts.

Pricing

How an Active Directory assessment is priced

One domain has a published price. Anything larger is quoted from the scope. Either way the price is fixed in writing before work begins.

One domain

One Active Directory domain of up to a few hundred hosts, from one standard user: $6,000, with a free retest.

Multiple domains or forests

Several domains, forests, or trusts, or thousands of hosts, quoted from the scope.

The whole internal network

The domain plus the hosts, services, and segmentation around it is the internal network penetration test, also from $6,000.

Methodology

Active Directory security assessment methodology

Full methodology →

Every engagement follows the Penetration Testing Execution Standard and the relevant OWASP guides.

These are the phases your Active Directory security assessment runs through.

  1. 01

    Starting foothold

    One standard user account, or a workstation on the network, reached through a device we ship, a VPN you provide, or on site.

  2. 02

    Domain enumeration

    The domain, hosts, shares, trusts, and relationships mapped from that account, with BloodHound and by hand.

  3. 03

    Credential access & escalation

    Credentials captured, relayed, or cracked, and privileges escalated through the paths the enumeration reveals.

  4. 04

    Path to Domain Admin

    Movement toward Domain Admin and tier-zero control, testing ADCS, delegation, and hybrid identity along the way.

  5. 05

    Report & retest

    Attack paths mapped to MITRE ATT&CK, fixes ranked by paths broken, an attestation letter, and a free retest.

How it works

How your engagement runs

From scope through the final retest, your team stays in the loop at every step, with findings tracked live in our platform.

  1. 01

    Scope & kickoff

    Targets, roles, and rules of engagement defined in writing, with a fixed scope and timeline.

  2. 02

    Testing goes live

    Findings post to your live platform dashboard the moment our testers confirm them.

  3. 03

    Track remediation

    Follow every finding from open to fixed, with severity, evidence, and status in one place.

  4. 04

    Report & retest

    Executive and technical reports land, then request a free retest in one click.

Proof

Proof in the field

Every engagement is confidential, so the work below is anonymized to sector and engagement type.

All case studies →

Free

Retest on every penetration test

185+

Years combined experience

14

Senior in-house specialists

24h

Onboarding after signing

Fintech · Payments

Web Application Penetration Test

High risk

Critical: a remote code execution flaw in the application’s web framework that could have given an attacker full control of the server. We escalated it to the development team while the test was still running.

Outcome. The critical RCE was reported and remediated during the engagement via an emergency framework upgrade, which also closed the server-side request forgery, and the remaining findings were retested to confirmation.

1

Critical (RCE)

Mid-test

Critical remediated

2

High

Read the case study

HR & Payroll SaaS

Web Application Penetration Test

High risk

Critical: a file-inclusion flaw that let an attacker read sensitive files from the server through the application itself. High: stored cross-site scripting capable of session theft, insecure direct object references, and an authorization bypass that let an administrator create or delete organization owners.

Outcome. Delivered a remediation plan sequenced by real business impact, critical and high findings first, with a complimentary retest to verify every fix.

28

Findings

1

Critical

5

High

Read the case study

FAQ

Frequently asked questions

What teams most often ask before scoping Active Directory security assessment.

Still have questions? 
01What is an Active Directory security assessment, and how is it different from a full internal test?

An Active Directory security assessment concentrates the whole engagement on the domain: the Kerberos, delegation, ACL, GPO, certificate-services, credential, relay, and hybrid-identity paths that turn one ordinary account into Domain Admin. A full internal network penetration test covers all of that plus the hosts, services, shares, and segmentation around the domain. If your concern is specifically domain admin exposure and privileged access, this is the focused version; if you want the whole internal estate, choose the internal test. Both start from the same foothold, and both start at $6,000: the difference is where the testing days go.

02Where does the test start?

From the position a real attacker has after a phishing email or a compromised laptop: either a standard domain user account with no special privileges, or a workstation on the network with no credentials at all. We agree which one, or both, during scoping. We connect through a small device we ship or a VPN you provide, so there is no travel, or on site where you prefer.

03Do you need Domain Admin credentials to run it?

No, the opposite. The point is to start with what an attacker would have, a standard user or an unauthenticated foothold, and prove how far it reaches. Being handed Domain Admin would defeat the exercise. We do agree in advance which systems, if any, must stay untouched, and stop at those boundaries while documenting the path we would have taken.

04Will users notice, and is it safe for the domain controllers?

Mostly not. The assessment is not a stealth exercise, so your IT team knows it is running, but it does not disrupt users. It runs under written rules of engagement: no changes to domain controllers, password spraying only within agreed lockout thresholds, and agreed testing windows. Anything critical is escalated to your contact immediately rather than waiting for the report. The covert, detection-focused version is a red team.

05Do you test hybrid identity with Entra ID?

Yes. Many domains now sync to Entra ID, and the bridge between them is a common escalation path. We test Entra Connect and password hash sync, seamless single sign-on and pass-through authentication, synced privileged accounts, and the pivots in both directions, on-premises to cloud and cloud to on-premises. For a tenant-first review of Microsoft 365 and Entra ID, see our Microsoft 365 security assessment.

06How are the findings presented?

As attack paths, not just a list of issues. The report shows the routes from an ordinary user to Domain Admin, each with proof of concept and evidence, mapped to MITRE ATT&CK so your defenders can see what should have been detected. The fixes are ranked by how many paths each one breaks, so you start with the change that removes the most risk. Our Active Directory hardening checklist lists the controls those fixes usually land on.

07How much does an Active Directory security assessment cost?

One Active Directory domain of up to a few hundred hosts is $6,000, fixed before work begins, with a free retest. Multiple domains or forests, or thousands of hosts, are quoted from the scope, and the price is still fixed in writing before testing starts. Starting prices for every service are on our pricing page.

Ready to test your defenses?

Talk to our team about scoping Active Directory security assessment.

Prefer the full scoping questionnaire? 

Get a Fixed-Scope Quote

Tell us what you need tested. We reply within one business day.