PXL Security LTD, Sofia, Bulgaria Offensive security since 2014[email protected]

Active Directory & Internal Network

Find the path to Domain Admin first.

An internal assessment focused on Active Directory and the network around it: the group memberships, permissions and sessions that chain a single foothold into full domain control.

Attack paths, not just findings

Active Directory compromise is rarely one exploit; it's a chain of legitimate permissions. We map that graph the way attackers do, then show the one or two choke points that collapse dozens of paths when fixed. (It's the work behind our BloodHound write-up.)

We can start from an assumed breach or a low-privileged account, and work alongside your team or quietly, as you prefer.

What we look at

  • AD objects, ACLs and trusts
  • Local-admin and privileged-group sprawl
  • Credential exposure and session hygiene
  • Kerberos and delegation weaknesses
  • Lateral-movement and escalation paths
  • Tiering and administrative hygiene

How it works

  1. Foothold and collect

    From an agreed starting point, we map the domain.

  2. Path analysis

    We identify the shortest routes to high-value targets.

  3. Validated exploitation

    We prove the paths safely, end to end.

  4. Report and retest

    Choke-point fixes, prioritised, then verified.

What you receive

Clear deliverables, agreed in the proposal, with no surprises at the end of the engagement.

  • Executive summaryBusiness-level risk, written for leadership and boards.
  • Technical reportEvery finding with severity, evidence and reproduction.
  • Prioritised fixesDeveloper-ready remediation, ranked by real risk.
  • Retest letterWe verify your fixes and confirm closure in writing.

Let's scope your active directory & internal network.

Send a short description of your environment and goals. A senior tester, not a salesperson, will reply with questions, a proposed approach and a quote.

Prefer email? Write to [email protected]. We reply within one business day.