Active Directory Penetration Testing
Active Directory penetration testing across Europe. We map attack paths to domain admin, prove them, and hand you fixed-price findings with a free retest.
Active Directory penetration testing finds the paths an attacker walks from an ordinary user account to full control of your domain, and it finds them before someone else does. If AD runs your identity, then AD is the prize, and a single misconfiguration usually connects a helpdesk login to domain admin.
Almost every Windows-based organisation in Europe runs on Active Directory, and almost every one carries attack paths that no one designed on purpose. They accumulate: a service account added to a privileged group “temporarily” in 2019, a delegation setting nobody understands, an ACL that lets a normal user reset an admin’s password. We map those paths, prove the ones that work, and show you which single changes cut the most of them at once.
What Active Directory penetration testing covers
The goal is concrete: start from the access a phished employee or a compromised workstation would give, and reach the objects that let an attacker own the estate. Along the way we surface the specific misconfigurations that make it possible, ranked by how much risk each one carries.
The path, not just the list
A findings list tells you that a service account is Kerberoastable. An attack path tells you that cracking that account’s password gives write access to a group, that the group controls a GPO, that the GPO deploys to a server where a domain admin logs in, and that from there it’s over. We chase the path to its end and show you the shortest place to break it.
Assumed-breach starting point
We begin with a low-privilege domain user, the access a real intruder gets from one phished password. From there the interesting question is not whether we can get in but how fast we reach the top, and whether anything in your environment would notice. Everything runs under NDA against scope you sign off in advance.
How we test Active Directory
This is hands-on work by an engineer who has broken real domains, not a scan and a template. We use the tools every serious operator uses, then apply the judgment a tool doesn’t have. Since people ask, no, DAST is not the same as penetration testing: a dynamic application scanner probes web apps for injection and misconfiguration, while Active Directory testing is a manual, path-driven assessment of your identity infrastructure. Different target, different discipline.
Enumeration and mapping
We collect the domain’s structure with BloodHound and the SharpHound collectors, pulling users, groups, sessions, ACLs and delegation settings, then graph the routes from where we stand to Tier 0. This is where the picture forms: which accounts are overprivileged, which ACLs are dangerous, and which “normal” users sit one hop from control.
Credential and ticket attacks
Kerberoasting extracts crackable tickets for service accounts, and AS-REP roasting targets accounts that don’t require pre-authentication. We crack offline, replay hashes and tickets where password reuse allows, and test the certificate-services attack paths that have become one of the most reliable escalation routes in modern AD.
AD Certificate Services
Misconfigured certificate templates let a normal user request a certificate that authenticates as someone else, up to and including a domain administrator. These ESC-class issues are common, quiet, and devastating, and most defenders don’t know the service is even in scope until we show them the path.
Escalation to domain and forest
With enough access we demonstrate control: DCSync to pull password hashes straight from a domain controller, GPO abuse to run code across every machine a policy touches, and where trusts exist, escalation across domains and into the forest root. We stop at proof, capture the evidence, and never disrupt production to make a point.
Detection and reporting
Because the techniques map to MITRE ATT&CK, we can also tell you what your monitoring caught and what it missed. The report walks the whole path with command output and screenshots, then gives your team the specific, prioritized fixes that collapse the most attack paths for the least effort.
Attack paths we find most often
Active Directory fails in patterns. After enough engagements the same handful of issues account for most full-domain compromises, and none of them require a novel exploit.
Kerberoastable service accounts with weak passwords
Service accounts often have old, human-chosen passwords and rights far beyond what they need. Any domain user can request their tickets, and a weak password cracks in hours on commodity hardware. When that account is also a local admin everywhere, one crack becomes an estate.
Dangerous ACLs and shadow admins
Rights like GenericAll, WriteDACL or the ability to reset another user’s password turn ordinary accounts into “shadow admins” nobody tracks. These delegated permissions are almost always accidental, granted years ago and never reviewed. BloodHound surfaces them; we prove which ones actually lead somewhere.
Certificate services misconfigurations
The ESC1 through ESC8 template and endpoint issues have quietly become one of the fastest routes to domain admin in networks that run AD CS. They are widespread, easy to exploit once known, and frequently missed by testing that predates the technique.
Legacy protocols and cached credentials
Unsigned SMB, NTLM where Kerberos should be enforced, and privileged credentials cached on ordinary workstations all give an attacker an opening. A domain admin who logs into a helpdesk machine leaves a token behind, and that token is a straight line to the top.
Want this tested on your own systems?
Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.
What you get
Two reports for two audiences, plus a graph you can actually use and a retest to prove the fixes work.
Executive summary
A clear read for leadership: how far an attacker gets, what that would cost, and the small number of changes that matter most. It answers “how bad is it and what do we fix first” without a glossary.
Technical report and attack graphs
Every finding with impact, CVSS, reproduction steps and a specific fix, plus the attack-path graphs showing exactly how access chains together. Your engineers can trace each path and confirm the break point once it’s remediated.
Attestation and free retest
An attestation letter for auditors, clients and insurers, and a no-cost retest after you remediate to confirm the paths are genuinely closed and haven’t simply moved.
Compliance and standards
Testing your identity backbone maps to the frameworks European organisations report against, and we tune the deliverables to whichever apply.
ISO 27001, SOC 2 and PCI DSS
ISO 27001 Annex A control 8.8 on technical vulnerability management and access-control controls all speak directly to AD hygiene. SOC 2 auditors expect independent testing of the systems that enforce access, and PCI DSS 4.0 requirement 11.4 covers the penetration testing that AD sits at the centre of. Our reports carry the evidence these reviews want.
DORA and NIS2
For financial entities and essential-service operators, DORA and NIS2 both push threat-led, evidence-based testing of the systems that would cause the most damage if compromised. Active Directory is almost always at the top of that list.
Why manual testing beats a scanner
No scanner reasons about attack paths. It can flag a weak password policy or a missing patch, but it will not tell you that user A can reset user B’s password, that B controls a GPO, and that the GPO runs on a domain controller. That reasoning is the whole value of the engagement, and it only comes from an operator who has walked these paths before. It is also why we compete against other penetration testing companies on depth rather than volume: fewer findings, each one proven, each one connected to real business impact.
Context that changes the fix
The same finding can be trivial in one domain and critical in another, and only a person who understands the surrounding environment can tell which. A Kerberoastable account with a strong random password is a low-priority note. The same account with a 2016-vintage password and admin rights on the file server is a five-alarm problem. We rank by the reality of your estate, not by a generic severity table, so your team spends its remediation time where it actually moves the needle.
Where Active Directory testing fits
An AD assessment is most valuable as part of a wider programme rather than a one-off box-tick. It pairs naturally with an internal network test that establishes the initial foothold and with a phishing simulation that shows how realistic that foothold is. Run together, they tell a single story: how an attacker gets in, how they reach identity, and how far identity takes them. Run once a year, or after any significant change to your domain, they keep that story honest as the environment drifts.
After a merger or migration
Domain consolidations, trust additions and cloud-identity migrations are exactly the moments new attack paths appear. If you have recently joined two forests, added a trust, or hybrid-joined to Entra ID, the assessment catches the misconfigurations that come with the change while they are still fresh and easy to fix.
Pricing
Cost scales with the size and complexity of the domain: the number of users and hosts, whether there are multiple domains or a forest with trusts, and how deep you want the assessment to go. Here is the typical shape.
| Engagement | What’s included | Timeline | Price |
|---|---|---|---|
| Essential | Single domain, assumed-breach user, BloodHound mapping, core escalation testing, full report and free retest | 4–6 working days | from €3,500 |
| Standard | Larger single domain with AD CS, GPO and delegation review, detection assessment, exec and technical reporting | 6–10 working days | €4,500–€9,000 |
| Advanced | Multiple domains or a full forest with trusts, Tier 0 objective, evasion testing and blue-team debrief | 10–16 working days | €9,000–€20,000 |
| Compliance add-on | Mapping and attestation for ISO 27001, SOC 2, PCI DSS or DORA | with any tier | from €800 |
| Custom / large estate | Complex multi-forest environments, scoped after a call | on scoping | custom |
Every engagement is fixed-price, quoted after a free 20-minute scoping call, with no hourly surprises and a retest included. Get a fixed quote
FAQ
How much does Active Directory penetration testing cost?
How long does an AD assessment take?
Is DAST the same as penetration testing?
Will the test affect our domain controllers or users?
Do you test Active Directory Certificate Services?
What do we actually receive?
Where are you based and can you work across Europe?
Does this help with ISO 27001 or SOC 2?
Related services
Any organisation whose access and identity run on a Windows domain: enterprises with a large user base and legacy configuration, financial and regulated firms facing DORA or ISO 27001, and IT teams that suspect years of accumulated permissions have quietly opened a path to domain admin and want it found and closed.
Security you can prove
The same standard on every engagement, big or small.
Evidence, not opinions
Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".
Humans over scanners
Certified engineers find the logic flaws and chained attacks automated tools walk straight past.
Fixed price, free retest
You know the cost up front, and verifying the fix is part of the deal — not a second invoice.
Ready to lock this down?
Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.
Tell us what you're running
Scoping is free. We reply within one business day, and under 30 minutes for active incidents.