Offensive security assessments

Active Directory Pentesting

Domain Controllers are servers that implement AD services, handling user authentication and managing directory data.

What we assess

Coverage areas included in this engagement. Select a topic for methodology depth and business impact.

TopicSummary
Active Directory (AD) - Basics UnderstandingWithin Active Directory, there are three built-in groups that comprise the highest privilege groups in the director
Active Directory (AD) TerminologyWe validate this area during scoped assessments, documenting impact and remediation guidance.
DLLA DLL (Dynamic Link Library) is a file format used in Microsoft Windows environments to contain code, data, and resources that can be used by multiple programs simultaneously. DLLs help modularize applications, allowing them to share common functions without duplicating code acr…
Extended Active Directory (AD) TerminologyWe validate this area during scoped assessments, documenting impact and remediation guidance.
I. Active Directory EnumerationWe validate this area during scoped assessments, documenting impact and remediation guidance.
II. Local Privilege EscalationWe validate this area during scoped assessments, documenting impact and remediation guidance.
III. Domain Privilege EscalationWe validate this area during scoped assessments, documenting impact and remediation guidance.
IV. Domain Persistence and DominanceWe validate this area during scoped assessments, documenting impact and remediation guidance.
Kerberos OverviewWe validate this area during scoped assessments, documenting impact and remediation guidance.
Kerberos-Related AttacksWe validate this area during scoped assessments, documenting impact and remediation guidance.
Microsoft Access TerminologyWe validate this area during scoped assessments, documenting impact and remediation guidance.
ReconnaissanceWe validate this area during scoped assessments, documenting impact and remediation guidance.
ReconnaissanceWe validate this area during scoped assessments, documenting impact and remediation guidance.
Red Teaming TerminologyWe validate this area during scoped assessments, documenting impact and remediation guidance.
Scanning and EnumerationWe validate this area during scoped assessments, documenting impact and remediation guidance.
Scanning and EnumerationWe validate this area during scoped assessments, documenting impact and remediation guidance.
Users and AccountsWe validate this area during scoped assessments, documenting impact and remediation guidance.
V. Cross Trust AttacksWe validate this area during scoped assessments, documenting impact and remediation guidance.
Vulnerability AssessmentWe validate this area during scoped assessments, documenting impact and remediation guidance.
Vulnerability AssessmentWe validate this area during scoped assessments, documenting impact and remediation guidance.

How we run it

Documented phases aligned to industry frameworks. Every step produces evidence your engineering team can replay.

Scope and authorization

We confirm written authorization, in-scope assets, and rules of engagement before testing begins.

  • We confirm written authorization, in-scope assets, and rules of engagement before testing begins.

Assessment and validation

Our operators assess the attack surface using documented methodologies aligned to industry frameworks.

  • Our operators assess the attack surface using documented methodologies aligned to industry frameworks.

Reporting and retest

Findings are delivered with severity ratings, remediation guidance, and an agreed retest window for critical issues.

  • Findings are delivered with severity ratings, remediation guidance, and an agreed retest window for critical issues.

Certification spotlight

Our operators hold industry-recognized offensive security credentials. For this engagement we lean on the certification below.

CompTIA PenTest+ certification badge

Primary certification

PenTest+

CompTIA

Why this matters for your engagement

CompTIA PenTest+ validates hands-on offensive methodology across networks, applications, and cloud targets. We apply this framework to scope, execute, and report findings with reproducible evidence your engineering team can action.

Also held
CompTIA Security+
CompTIA CySA+

Risk areas we cover

High-level risk themes for this engagement. Cards with an arrow open the matching topic page.

Active Directory (AD) - Basics Understanding

Within Active Directory, there are three built-in groups that comprise the highest privilege groups in the director

Active Directory (AD) Terminology

We validate this area during scoped assessments, documenting impact and remediation guidance.

DLL

A DLL (Dynamic Link Library) is a file format used in Microsoft Windows environments to contain code, data, and resources that can be used by multiple programs simultaneously. DLLs help modularize applications, allowing them to share common functions without duplicating code acr…

Extended Active Directory (AD) Terminology

We validate this area during scoped assessments, documenting impact and remediation guidance.

I. Active Directory Enumeration

We validate this area during scoped assessments, documenting impact and remediation guidance.

II. Local Privilege Escalation

We validate this area during scoped assessments, documenting impact and remediation guidance.

III. Domain Privilege Escalation

We validate this area during scoped assessments, documenting impact and remediation guidance.

IV. Domain Persistence and Dominance

We validate this area during scoped assessments, documenting impact and remediation guidance.

Kerberos Overview

We validate this area during scoped assessments, documenting impact and remediation guidance.

Kerberos-Related Attacks

We validate this area during scoped assessments, documenting impact and remediation guidance.

Microsoft Access Terminology

We validate this area during scoped assessments, documenting impact and remediation guidance.

Reconnaissance

We validate this area during scoped assessments, documenting impact and remediation guidance.

What you receive

Every engagement concludes with actionable output your security and engineering teams can operationalize.

Findings report

Documented vulnerabilities with severity ratings, affected assets, and reproducible evidence your team can action.

Remediation guidance

Prioritized recommendations mapped to risk and effort, with clear ownership for engineering and operations teams.

Retest scope

Defined retest window for critical and high findings so you can confirm fixes before auditors or leadership review.

Compliance and trust

Findings are mapped to severity frameworks and can support SOC 2, ISO 27001, HIPAA, and GDPR evidence requests. Review our security practices and subprocessors in the Trust Center.