IDENTITY & ACCESS SECURITY

Active Directory Attack Surface & Resilience

Active Directory is the skeleton key to your enterprise. Privilege Zero systematically dismantles every Kerberos abuse path, ACL misconfiguration, ADCS escalation, and trust boundary exploit in your domain — before attackers discover them.

ACTIVE DIRECTORY DOMAIN DOMAIN CONTROLLER OU: USERS OU: SERVERS OU: ADMIN KERBEROS · LDAP · ADCS · GPO AZURE AD CONNECT — HYBRID BOUNDARY
Why AD is Always the Target

One Domain. Every Key.

In virtually every enterprise network, owning Active Directory means owning everything. Every server, every workstation, every user account — they all trust the domain. Ransomware operators know this. State-sponsored actors know this. Miscreants with Kerberoasting scripts know this.

Active Directory's complexity is its weakness. The sheer number of OUs, GPOs, ACLs, service principals, and trust relationships creates a surface area that grows faster than security teams can audit it. Privilege Zero conducts a dedicated AD assessment — not a checkbox exercise against CIS benchmarks, but a genuine attempt to own your domain using current attacker methodology.

18+
Distinct Attack Classes Assessed
ESC1–8
Full ADCS Certificate Abuse Coverage
BloodHound
Attack Path Graph Included in Every Report
Hybrid
Azure AD Connect & Entra ID Scope Available
Assessment Structure

From Enumeration to Exploitation

01
Full Domain Enumeration

Ingest the complete domain into BloodHound and supplement with targeted LDAP queries: all users, computers, groups, GPOs, OUs, trusts, service principals, and privileged account delegation settings.

02
Misconfiguration & ACL Analysis

Identify every dangerous permission in the domain: GenericAll, WriteDACL, GenericWrite, AddMember, ForceChangePassword — and trace which accounts hold them, even through nested group membership chains.

03
Kerberos & Authentication Protocol Attacks

Execute Kerberoasting, AS-REP Roasting, unconstrained/constrained delegation abuse, Pass-the-Ticket, Overpass-the-Hash, and shadow credential attacks to demonstrate the breadth of Kerberos-based privilege escalation.

04
ADCS Certificate Abuse

Test every Active Directory Certificate Services configuration against the full ESC1–ESC8 vulnerability taxonomy — certificate template misconfigurations that allow any domain user to escalate to domain admin via a certificate request.

05
Trust & Federation Boundary Testing

Examine cross-domain and cross-forest trust relationships, Azure AD Connect configurations, and ADFS federation endpoints for SID filtering gaps and cloud-to-on-premise privilege escalation paths.

06
Exploitation & Privilege Verification

With explicit authorisation, exploit confirmed attack paths — DCSync, golden ticket, silver ticket, certificate-based escalation — to prove real-world impact and validate attack path accuracy before reporting.

Attack Coverage

The AD Attack Taxonomy We Cover

Kerberos Attacks

  • Kerberoasting
  • AS-REP Roasting
  • Pass-the-Ticket
  • Overpass-the-Hash
  • Golden Ticket
  • Silver Ticket

ACL & Delegation

  • GenericAll / WriteDACL
  • Unconstrained Delegation
  • RBCD Abuse
  • AdminSDHolder
  • Shadow Credentials

ADCS & Certificates

  • ESC1 — Template Misconfiguration
  • ESC3 — Agent Enrollment
  • ESC4 — Template ACL Write
  • ESC6 — EDITF_ALTNAME
  • ESC8 — NTLM Relay to ADCS

Infrastructure

  • DCSync
  • GPO Misconfiguration
  • LAPS Bypass
  • SID History Injection
  • Print Spooler (PrintNightmare variants)

Hybrid & Cloud

  • AAD Connect Password Sync
  • Seamless SSO Token Abuse
  • PTA Agent Compromise
  • On-Prem → Entra Escalation

Trust Relationships

  • Cross-Domain SID Filtering
  • Cross-Forest Trust Abuse
  • Foreign Principal Membership
  • ADFS Token Forgery
Deliverables

From Attack Paths to Hardened Domain

BloodHound Attack Path Report

Exported attack graphs with annotated screenshots showing every privilege escalation path from standard user to domain admin.

Misconfiguration Catalogue

Every misconfiguration, ordered by exploitability — with specific PowerShell or AD configuration remediation for each item.

AD Tiering & Hardening Roadmap

Phased hardening plan aligned to Microsoft's Privileged Access model and tiering recommendations — achievable without a domain rebuild.

Retest Verification

Post-remediation re-enumeration to confirm attack paths are closed and no new paths were introduced during hardening.

Secure Your Identity Infrastructure

Your Domain Is Either Hardened or It's a Liability

We deliver a full BloodHound-backed attack path report and hardening roadmap within 10 business days of kickoff.

Assess My Active Directory Discuss Scope