Active Directory
Configuration Review
A structured, non-intrusive review of on-premises Active Directory configuration — benchmarking your tiering model, ACLs, Kerberos policy, Group Policy, and ADCS setup against attacker-relevant risk, without live exploitation of your domain.
Active Directory remains the crown jewel of most enterprise environments — and the most targeted. A compromised domain is a compromised organisation. Our AD configuration reviews are conducted by experienced consultants who specialise in Microsoft identity attack paths, applying that offensive knowledge to a structured, non-disruptive audit of your domain's configuration.
We focus exclusively on on-premises Active Directory — reviewing the configuration that would allow a standard domain user account to escalate toward Domain Admin, without carrying out live exploitation against your environment. Our approach treats AD as an attacker would: as a graph of privilege relationships to be mapped, not a checklist to be ticked.
Our reviews are structured to provide both a technical findings narrative and a clear picture of organisational risk — where privilege escalation paths exist in your configuration, and how they should be prioritised for remediation.
Domain & Forest Enumeration
Comprehensive, read-only enumeration of users, groups, computers, OUs, GPOs, ACLs, trusts, and SPNs using BloodHound, ldapdomaindump, and custom tooling. We map the full privilege graph and identify high-value targets to scope the review.
Privileged Access & Tiering Review
Review of privileged group membership (Domain Admins, Enterprise Admins, and nested equivalents), the administrative tiering model, use of Privileged Access Workstations, and separation between standard and privileged accounts.
ACL & Delegation Review
Analysis of Active Directory ACLs for over-permissive rights — GenericAll, WriteDACL, ForceChangePassword, GenericWrite, and AddMember on high-value groups and accounts — using BloodHound path mapping to identify indirect escalation routes to Domain Admin without exploiting them live.
Kerberos & Authentication Policy Review
Assessment of Kerberos ticket policy, service accounts exposed to Kerberoasting, accounts vulnerable to AS-REP roasting, delegation configuration (unconstrained, constrained, and resource-based), password policy, and continued reliance on legacy protocols such as NTLM.
Group Policy & Hardening Baseline Review
Review of Group Policy Objects against CIS and Microsoft security baselines, identifying insecure settings, legacy protocol enablement, weak local admin password management, and gaps in LAPS deployment.
ADCS Configuration Review
Review of Active Directory Certificate Services — certificate templates, enrolment permissions, and CA configuration — for the misconfiguration classes (ESC1–ESC15) known to provide a path to domain compromise, assessed by configuration inspection rather than live exploitation.
Reporting & Remediation Guidance
Findings are risk-rated by potential impact and mapped to MITRE ATT&CK, with a clear narrative of the privilege escalation paths your configuration currently permits. Technical and executive reporting, and a debrief with your AD administrators — included as standard.
We bring the same offensive knowledge as real threat actors — BloodHound path analysis, deep familiarity with Kerberos, ACL, and ADCS abuse — to a review that doesn't touch your production domain through live exploitation. We think in attack graphs, not checklists. Every engagement produces a clear narrative of the paths your current configuration would allow, from low-privileged user to domain compromise.
Our experienced consultants specialise in on-premises Active Directory and have reviewed domains across organisations ranging from SMEs to large enterprises. We consistently find privilege escalation paths that internal teams and automated scanners miss.