Active Directory & Internal Network
Find the path to Domain Admin first.
An internal assessment focused on Active Directory and the network around it: the group memberships, permissions and sessions that chain a single foothold into full domain control.
Attack paths, not just findings
Active Directory compromise is rarely one exploit; it's a chain of legitimate permissions. We map that graph the way attackers do, then show the one or two choke points that collapse dozens of paths when fixed. (It's the work behind our BloodHound write-up.)
We can start from an assumed breach or a low-privileged account, and work alongside your team or quietly, as you prefer.
What we look at
- AD objects, ACLs and trusts
- Local-admin and privileged-group sprawl
- Credential exposure and session hygiene
- Kerberos and delegation weaknesses
- Lateral-movement and escalation paths
- Tiering and administrative hygiene
How it works
Foothold and collect
From an agreed starting point, we map the domain.
Path analysis
We identify the shortest routes to high-value targets.
Validated exploitation
We prove the paths safely, end to end.
Report and retest
Choke-point fixes, prioritised, then verified.
What you receive
Clear deliverables, agreed in the proposal, with no surprises at the end of the engagement.
- Executive summaryBusiness-level risk, written for leadership and boards.
- Technical reportEvery finding with severity, evidence and reproduction.
- Prioritised fixesDeveloper-ready remediation, ranked by real risk.
- Retest letterWe verify your fixes and confirm closure in writing.
Related services
Let's scope your active directory & internal network.
Send a short description of your environment and goals. A senior tester, not a salesperson, will reply with questions, a proposed approach and a quote.