Active Directory Security and Penetration Testing Service
Kerberoasting, AS-REP Roasting, NTLM relay and BloodHound attack-path analysis — measure how far an attacker could get towards Domain Admin.
What Is Active Directory Security and Penetration Testing?
Active Directory (AD) is one of the most critical pieces of infrastructure in a Microsoft-based enterprise network — the place where user identities, computers, servers, security groups and access rights are centrally managed. Most organisations today run their authentication, authorisation and access management through Active Directory.
Active Directory security and penetration testing is a comprehensive security assessment carried out to evaluate the security posture of the domain infrastructure, identify misconfigurations, and find the weaknesses an attacker could use for privilege escalation, lateral movement or to obtain Domain Administrator rights.
Testing covers far more than the domain controllers: user accounts, service accounts, Group Policy Objects (GPO), the Kerberos infrastructure, DNS services, LDAP, SMB, NTLM, Active Directory Certificate Services (AD CS) and domain security configuration are all analysed using genuine attacker techniques.
SecureSys Active Directory security tests are conducted in line with MITRE ATT&CK, Microsoft Security Baselines, NIST, PTES and Microsoft Active Directory Security Best Practices.
Why Should You Run an Active Directory Security Test?
When Active Directory is compromised, an attacker gains control not of a single user account but of the entire corporate network. Obtaining Domain Administrator rights can mean complete control over servers, client machines, file shares and critical systems.
A misconfigured Active Directory environment creates the following risks:
- Compromise of Domain Administrator rights
- Account takeover
- Kerberos attacks
- NTLM relay attacks
- Pass-the-Hash attacks
- Pass-the-Ticket attacks
- Golden Ticket and Silver Ticket attacks
- Unauthorised access and privilege escalation
- Ransomware spreading across the domain
- Manipulation of Group Policy Objects
- Abuse of service accounts
- Data leakage and loss of business continuity
Active Directory security is therefore one of the most critical components of any corporate cyber security strategy.
What Is the Active Directory Infrastructure?
Active Directory is the central directory service that provides user authentication, device management and access authorisation.
Its core components are:
- Domain Controller (DC)
- Forest
- Domain
- Organizational Unit (OU)
- Group Policy Objects (GPO)
- DNS
- LDAP
- Kerberos
- NTLM
- Active Directory Certificate Services (AD CS)
- Active Directory Federation Services (AD FS)
- Group Managed Service Accounts (gMSA)
Active Directory Vulnerabilities
Because Active Directory is the central authentication system of a corporate network, it is among the first targets an attacker goes after. Misconfiguration, weak password policy, incorrect permissions and legacy protocols can all lead to complete compromise of the domain.
SecureSys Active Directory security testing analyses not only known vulnerabilities but also the privilege escalation, lateral movement and credential theft techniques attackers use in real environments.
The principal risks assessed are:
- Weak password policies
- Poor management of privileged accounts
- Unauthorised administrative rights
- GPO misconfiguration
- SMB and LDAP security gaps
- Kerberos weaknesses
- Active Directory Certificate Services (AD CS) vulnerabilities
- Insecure service accounts
- LLMNR and NetBIOS configuration
- Legacy protocols (NTLMv1 and similar)
- Inadequate network segmentation
- Delegation misconfiguration
Kerberos Security Testing
Kerberos is the default authentication protocol in an Active Directory environment. Misconfiguration or weak service accounts can allow an attacker to obtain privileged access without ever knowing a user's password.
SecureSys Kerberos security analysis evaluates the following:
- Kerberos ticket security
- Ticket Granting Ticket (TGT)
- Service ticket analysis
- Kerberos delegation
- Constrained delegation
- Unconstrained delegation
- Resource-Based Constrained Delegation (RBCD)
- Ticket lifetime
- AES / RC4 configuration
- Kerberos encryption types
NTLM and LDAP Security
NTLM and LDAP services are still actively used in many organisations. Misconfigured NTLM or LDAP can allow an attacker to capture credentials and move further into the domain.
The principal checks performed:
- NTLMv1 usage
- NTLM relay protection
- LDAP signing
- LDAP channel binding
- Anonymous LDAP
- SMB signing
- LDAP enumeration
- LDAP authorisation controls
Pass-the-Hash (PtH) Attacks
In a Pass-the-Hash attack, the attacker authenticates to a system using the NTLM hash value without knowing the user's actual password.
SecureSys analysis evaluates:
- Hash protection mechanisms
- LSASS protection
- Credential Guard
- NTLM usage
- Hash storage behaviour
Pass-the-Ticket (PtT) Attacks
In a Pass-the-Ticket attack, Kerberos tickets are captured and used to impersonate a user's privileges.
The technique poses a particularly critical risk for Domain Administrator accounts.
Areas analysed:
- Ticket security
- TGT protection
- Service ticket security
- Ticket lifetime
- Ticket reuse
Golden Ticket Attacks
A Golden Ticket attack is one of the most critical Active Directory attacks: if the Kerberos KRBTGT account is compromised, the attacker can forge a valid ticket for any user they choose.
A successful Golden Ticket attack yields:
- Domain Administrator access
- Authorisation with no expiry
- Control of the entire domain
SecureSys testing analyses KRBTGT security, password rotation and ticket validation processes.
Silver Ticket Attacks
Silver Ticket attacks target specific services rather than the domain as a whole.
By forging tickets for file servers, SQL Server, IIS or other service accounts, an attacker can gain unauthorised access to those particular services.
What Is Kerberoasting?
Kerberoasting is a Kerberos-based attack that targets service accounts with a Service Principal Name (SPN) defined.
The attacker obtains service tickets and then performs offline password cracking against them.
Areas tested:
- SPN accounts
- Service accounts
- Weak passwords
- AES usage
- RC4 usage
- Managed service accounts
What Is AS-REP Roasting?
User accounts with "Do not require Kerberos preauthentication" enabled are exposed to AS-REP Roasting.
In that case the attacker can obtain the Kerberos response without knowing the user's password and mount an offline password cracking attack.
SecureSys assesses:
- Preauthentication
- User account configuration
- AES support
- Legacy accounts
LLMNR and NBT-NS Poisoning
LLMNR and NetBIOS Name Service (NBT-NS) are among the most frequently abused services on a corporate network.
On a misconfigured network an attacker can:
- Harvest NTLM hashes
- Perform SMB relay
- Capture credentials
The principal checks performed:
- LLMNR
- NBT-NS
- WPAD
- SMB signing
- DNS configuration
SMB Relay and NTLM Relay Attacks
SMB relay attacks redirect user authentication traffic to other systems, and are critical in a domain environment.
Scenarios analysed:
- SMB signing
- NTLM relay
- LDAP relay
- HTTP relay
- RPC relay
BloodHound Analysis and Attack Paths
BloodHound is an advanced analysis method that maps users, groups, computers and permission relationships in an Active Directory environment to reveal the attack paths through which an adversary could reach Domain Administrator rights.
SecureSys uses BloodHound analysis to evaluate:
- Attack paths
- Shortest path to Domain Admin
- Privilege escalation
- Delegation abuse
- ACL abuse
- GPO abuse
- Trust relationships
Active Directory Certificate Services (AD CS) Security
When Active Directory Certificate Services is misconfigured, it can give rise to the ESC (Enterprise Security Configuration) vulnerabilities that have become some of the most critical Active Directory attacks in recent years.
Areas analysed:
- ESC1
- ESC2
- ESC3
- ESC4
- ESC6
- ESC8
- Certificate templates
- Enrollment rights
- PKI configuration
Group Policy (GPO) Security
Group Policy Objects centrally manage computer and user configuration across the domain.
Misconfigured GPOs can lead to:
- Privilege escalation
- Malware distribution
- Security policy being altered
SecureSys analyses:
- GPO delegation
- GPO permissions
- Startup scripts
- Logon scripts
- Scheduled tasks
- Registry policy
Privileged Access and Service Account Analysis
Service accounts and privileged users are the most sensitive components of Active Directory.
The principal areas tested:
- Domain Admin
- Enterprise Admin
- Schema Admin
- Backup Operator
- Account Operator
- Service accounts
- Managed service accounts
- gMSA
- Local Administrator
- SID history
Lateral Movement Techniques
Attackers do not stop at a single compromised machine; they work to move on to other systems within the domain.
SecureSys evaluates the following techniques through controlled scenarios:
- Pass-the-Hash
- Pass-the-Ticket
- PsExec
- WMI
- WinRM
- RDP
- SMB
- Remote service creation
- Scheduled tasks
- DCOM
- Remote PowerShell
MITRE ATT&CK and Active Directory
SecureSys Active Directory security tests are carried out with reference to the MITRE ATT&CK Enterprise framework.
The principal techniques analysed:
- Initial access
- Execution
- Persistence
- Privilege escalation
- Credential access
- Discovery
- Lateral movement
- Collection
- Exfiltration
- Command and control
This means we assess not only isolated technical vulnerabilities but the complete attack chain an adversary could follow in the real world.
The Active Directory Security Testing Process
SecureSys Active Directory security tests follow this methodology:
- Scoping and planning
- Active Directory inventory analysis
- Review of the domain and forest structure
- User, group and permission analysis
- Kerberos and NTLM security checks
- BloodHound attack path analysis
- Service account and GPO review
- Privilege escalation scenarios
- Lateral movement simulation
- AD CS and certificate infrastructure analysis
- Risk assessment
- Preparation of technical and executive reports
- Remediation guidance and retest
Why SecureSys?
Active Directory security is not a matter of checking user accounts or domain controllers alone. A genuine assessment must cover authentication protocols, authorisation structures, service accounts, trust relationships, the certificate infrastructure and every attack path an adversary could take towards Domain Administrator rights.
At SecureSys we conduct Active Directory security testing in line with MITRE ATT&CK Enterprise, Microsoft Security Baselines and accepted industry best practice. By testing BloodHound attack paths, Kerberoasting, AS-REP Roasting, NTLM relay, AD CS security and privilege escalation scenarios under controlled conditions, we reveal not only the vulnerabilities that exist today but the attack chains they make possible.
The SecureSys Difference
- Expert penetration testing under TSE TS 13638
- Active Directory security assessment referenced against MITRE ATT&CK Enterprise
- BloodHound attack path and privilege escalation analysis
- Kerberos, NTLM, LDAP and SMB security testing
- Kerberoasting, AS-REP Roasting, Pass-the-Hash and Golden Ticket scenarios
- Active Directory Certificate Services (AD CS) security analysis
- Group Policy, service account and privileged access controls
- Comprehensive reporting at both technical and executive level
- Risk prioritisation, actionable remediation guidance and retest support
Want to learn more about this service?
Our expert team will reach out for a free consultation as soon as possible.