Home/Services/Active Directory Penetration Testing
security service

Active Directory Penetration Testing

Active Directory penetration testing across Europe. We map attack paths to domain admin, prove them, and hand you fixed-price findings with a free retest.

Manual, expert-ledEvidence-based findingsFree remediation retest

Active Directory penetration testing finds the paths an attacker walks from an ordinary user account to full control of your domain, and it finds them before someone else does. If AD runs your identity, then AD is the prize, and a single misconfiguration usually connects a helpdesk login to domain admin.

Almost every Windows-based organisation in Europe runs on Active Directory, and almost every one carries attack paths that no one designed on purpose. They accumulate: a service account added to a privileged group “temporarily” in 2019, a delegation setting nobody understands, an ACL that lets a normal user reset an admin’s password. We map those paths, prove the ones that work, and show you which single changes cut the most of them at once.

What Active Directory penetration testing covers

The goal is concrete: start from the access a phished employee or a compromised workstation would give, and reach the objects that let an attacker own the estate. Along the way we surface the specific misconfigurations that make it possible, ranked by how much risk each one carries.

Kerberoasting and AS-REP roasting of weak service accounts
Dangerous ACLs and delegation abuse mapped with BloodHound
Unconstrained and constrained delegation attack paths
AD Certificate Services misconfigurations, the ESC1 to ESC8 classes
Pass-the-hash, pass-the-ticket and overpass-the-hash
GPO abuse, SYSVOL secrets and Group Policy Preferences passwords
DCSync rights, trust relationships and forest-wide escalation

The path, not just the list

A findings list tells you that a service account is Kerberoastable. An attack path tells you that cracking that account’s password gives write access to a group, that the group controls a GPO, that the GPO deploys to a server where a domain admin logs in, and that from there it’s over. We chase the path to its end and show you the shortest place to break it.

Assumed-breach starting point

We begin with a low-privilege domain user, the access a real intruder gets from one phished password. From there the interesting question is not whether we can get in but how fast we reach the top, and whether anything in your environment would notice. Everything runs under NDA against scope you sign off in advance.

How we test Active Directory

This is hands-on work by an engineer who has broken real domains, not a scan and a template. We use the tools every serious operator uses, then apply the judgment a tool doesn’t have. Since people ask, no, DAST is not the same as penetration testing: a dynamic application scanner probes web apps for injection and misconfiguration, while Active Directory testing is a manual, path-driven assessment of your identity infrastructure. Different target, different discipline.

Enumeration and mapping

We collect the domain’s structure with BloodHound and the SharpHound collectors, pulling users, groups, sessions, ACLs and delegation settings, then graph the routes from where we stand to Tier 0. This is where the picture forms: which accounts are overprivileged, which ACLs are dangerous, and which “normal” users sit one hop from control.

Credential and ticket attacks

Kerberoasting extracts crackable tickets for service accounts, and AS-REP roasting targets accounts that don’t require pre-authentication. We crack offline, replay hashes and tickets where password reuse allows, and test the certificate-services attack paths that have become one of the most reliable escalation routes in modern AD.

AD Certificate Services

Misconfigured certificate templates let a normal user request a certificate that authenticates as someone else, up to and including a domain administrator. These ESC-class issues are common, quiet, and devastating, and most defenders don’t know the service is even in scope until we show them the path.

Escalation to domain and forest

With enough access we demonstrate control: DCSync to pull password hashes straight from a domain controller, GPO abuse to run code across every machine a policy touches, and where trusts exist, escalation across domains and into the forest root. We stop at proof, capture the evidence, and never disrupt production to make a point.

Detection and reporting

Because the techniques map to MITRE ATT&CK, we can also tell you what your monitoring caught and what it missed. The report walks the whole path with command output and screenshots, then gives your team the specific, prioritized fixes that collapse the most attack paths for the least effort.

48h
typical time to first confirmed attack path
100%
manually verified, no scanner false positives
Free
retest after remediation

Attack paths we find most often

Active Directory fails in patterns. After enough engagements the same handful of issues account for most full-domain compromises, and none of them require a novel exploit.

Kerberoastable service accounts with weak passwords

Service accounts often have old, human-chosen passwords and rights far beyond what they need. Any domain user can request their tickets, and a weak password cracks in hours on commodity hardware. When that account is also a local admin everywhere, one crack becomes an estate.

Dangerous ACLs and shadow admins

Rights like GenericAll, WriteDACL or the ability to reset another user’s password turn ordinary accounts into “shadow admins” nobody tracks. These delegated permissions are almost always accidental, granted years ago and never reviewed. BloodHound surfaces them; we prove which ones actually lead somewhere.

Certificate services misconfigurations

The ESC1 through ESC8 template and endpoint issues have quietly become one of the fastest routes to domain admin in networks that run AD CS. They are widespread, easy to exploit once known, and frequently missed by testing that predates the technique.

Legacy protocols and cached credentials

Unsigned SMB, NTLM where Kerberos should be enforced, and privileged credentials cached on ordinary workstations all give an attacker an opening. A domain admin who logs into a helpdesk machine leaves a token behind, and that token is a straight line to the top.

Get a fixed quote

Want this tested on your own systems?

Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.

Get a fixed quote

What you get

Two reports for two audiences, plus a graph you can actually use and a retest to prove the fixes work.

Executive summary

A clear read for leadership: how far an attacker gets, what that would cost, and the small number of changes that matter most. It answers “how bad is it and what do we fix first” without a glossary.

Technical report and attack graphs

Every finding with impact, CVSS, reproduction steps and a specific fix, plus the attack-path graphs showing exactly how access chains together. Your engineers can trace each path and confirm the break point once it’s remediated.

Attestation and free retest

An attestation letter for auditors, clients and insurers, and a no-cost retest after you remediate to confirm the paths are genuinely closed and haven’t simply moved.

Compliance and standards

Testing your identity backbone maps to the frameworks European organisations report against, and we tune the deliverables to whichever apply.

ISO 27001, SOC 2 and PCI DSS

ISO 27001 Annex A control 8.8 on technical vulnerability management and access-control controls all speak directly to AD hygiene. SOC 2 auditors expect independent testing of the systems that enforce access, and PCI DSS 4.0 requirement 11.4 covers the penetration testing that AD sits at the centre of. Our reports carry the evidence these reviews want.

DORA and NIS2

For financial entities and essential-service operators, DORA and NIS2 both push threat-led, evidence-based testing of the systems that would cause the most damage if compromised. Active Directory is almost always at the top of that list.

Why manual testing beats a scanner

No scanner reasons about attack paths. It can flag a weak password policy or a missing patch, but it will not tell you that user A can reset user B’s password, that B controls a GPO, and that the GPO runs on a domain controller. That reasoning is the whole value of the engagement, and it only comes from an operator who has walked these paths before. It is also why we compete against other penetration testing companies on depth rather than volume: fewer findings, each one proven, each one connected to real business impact.

Context that changes the fix

The same finding can be trivial in one domain and critical in another, and only a person who understands the surrounding environment can tell which. A Kerberoastable account with a strong random password is a low-priority note. The same account with a 2016-vintage password and admin rights on the file server is a five-alarm problem. We rank by the reality of your estate, not by a generic severity table, so your team spends its remediation time where it actually moves the needle.

Where Active Directory testing fits

An AD assessment is most valuable as part of a wider programme rather than a one-off box-tick. It pairs naturally with an internal network test that establishes the initial foothold and with a phishing simulation that shows how realistic that foothold is. Run together, they tell a single story: how an attacker gets in, how they reach identity, and how far identity takes them. Run once a year, or after any significant change to your domain, they keep that story honest as the environment drifts.

After a merger or migration

Domain consolidations, trust additions and cloud-identity migrations are exactly the moments new attack paths appear. If you have recently joined two forests, added a trust, or hybrid-joined to Entra ID, the assessment catches the misconfigurations that come with the change while they are still fresh and easy to fix.

Pricing

Cost scales with the size and complexity of the domain: the number of users and hosts, whether there are multiple domains or a forest with trusts, and how deep you want the assessment to go. Here is the typical shape.

Engagement What’s included Timeline Price
Essential Single domain, assumed-breach user, BloodHound mapping, core escalation testing, full report and free retest 4–6 working days from €3,500
Standard Larger single domain with AD CS, GPO and delegation review, detection assessment, exec and technical reporting 6–10 working days €4,500–€9,000
Advanced Multiple domains or a full forest with trusts, Tier 0 objective, evasion testing and blue-team debrief 10–16 working days €9,000–€20,000
Compliance add-on Mapping and attestation for ISO 27001, SOC 2, PCI DSS or DORA with any tier from €800
Custom / large estate Complex multi-forest environments, scoped after a call on scoping custom

Every engagement is fixed-price, quoted after a free 20-minute scoping call, with no hourly surprises and a retest included. Get a fixed quote

FAQ

How much does Active Directory penetration testing cost?
Active Directory penetration testing starts from €3,500 and is priced by the size of the domain and whether multiple domains or a forest are in scope. You get a fixed quote after a free scoping call rather than an hourly rate.
How long does an AD assessment take?
A single domain usually runs 4–6 working days plus the report, and forests with trusts take longer. If we reach domain admin quickly, you hear about the path the same day so you can start fixing before the write-up lands.
Is DAST the same as penetration testing?
No. DAST is automated dynamic scanning of web applications for issues like injection and misconfiguration. Active Directory penetration testing is manual, path-driven work against your identity infrastructure, chasing real routes to domain admin that no scanner reasons about.
Will the test affect our domain controllers or users?
No. We agree intrusive steps in advance, avoid anything that risks availability, and stop at proof rather than disruption. Attacks such as DCSync are demonstrated carefully and never used to damage production.
Do you test Active Directory Certificate Services?
Yes, when AD CS is in scope. The ESC1 to ESC8 certificate-template and endpoint issues are among the most reliable escalation paths in modern AD, and we test for all of them where the service is present.
What do we actually receive?
An executive summary, a technical report with every finding scored and reproducible, attack-path graphs from BloodHound, an attestation letter and a free retest. The fixes are prioritized so you close the most paths for the least effort.
Where are you based and can you work across Europe?
We are a European offensive-security team headquartered in Limassol, Cyprus, and we work with clients across Europe on site or remotely. Most Active Directory testing is done through a jump host we configure, so location is rarely a constraint.
Does this help with ISO 27001 or SOC 2?
Yes. The report and attestation are written to support ISO 27001 Annex A vulnerability-management controls, SOC 2 independent-testing expectations and PCI DSS 4.0 requirement 11.4. Tell us your framework and we align the output to it.

Related services

Who needs this

Any organisation whose access and identity run on a Windows domain: enterprises with a large user base and legacy configuration, financial and regulated firms facing DORA or ISO 27001, and IT teams that suspect years of accumulated permissions have quietly opened a path to domain admin and want it found and closed.

why safetybis

Security you can prove

The same standard on every engagement, big or small.

Evidence, not opinions

Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".

Humans over scanners

Certified engineers find the logic flaws and chained attacks automated tools walk straight past.

Fixed price, free retest

You know the cost up front, and verifying the fix is part of the deal — not a second invoice.

500+
assessments delivered
<30min
incident first response
12k+
infections removed
98%
fixed within one retest
$ safetybis quote --service "Active Directory Penetration Testing"

Ready to lock this down?

Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.

get in touch

Tell us what you're running

Scoping is free. We reply within one business day, and under 30 minutes for active incidents.