Home  /  Services  /  Active Directory Testing
Services · Active Directory

Active Directory
penetration testing.

Almost every ransomware case ends the same way: an attacker with one ordinary user account walks a chain of misconfigurations to Domain Admin. We walk that chain first, prove each step, and hand your team the exact ACLs, delegations and group memberships to fix.

01
Who this is for

Built for companies that grew faster than their domain did.

01

Startups that inherited a domain

Your AD was set up in a week by whoever was available, three years and four acquisitions ago. Nobody has audited the nesting since. That is the single most common shape of a domain compromise we see.

02

Companies preparing for an audit or a raise

Due diligence, cyber insurance and enterprise customers all ask the same question: has a qualified third party tested your domain. This produces the evidence, and the remediation plan behind it.

03

Security teams that already run BloodHound

Collecting the graph is not the same as proving the path. We validate which edges are actually walkable in your environment, and demote the ones that are theoretical.

02
Coverage

What we actually attack.

Not a checklist. These are the paths that end in domain compromise, in the order an adversary would try them.

01

Credential exposure

Kerberoasting and AS-REP roasting against service accounts, passwords in SYSVOL and GPP, LAPS misconfiguration, cleartext credentials in scripts and shares, and reversible encryption flags.

02

Delegation abuse

Unconstrained, constrained and resource-based constrained delegation. These are consistently the fastest route from a foothold to Domain Admin, and consistently the least understood.

03

ACL and object chains

GenericAll, WriteDACL, WriteOwner, AddMember and ForceChangePassword edges, traced end to end. We show you the chain, not a list of permissions.

04

Authentication relay and coercion

NTLM relay, LLMNR and NBT-NS poisoning, PetitPotam-style coercion, and SMB and LDAP signing gaps that make them work.

05

Certificate services (AD CS)

Vulnerable certificate templates, ESC1 through ESC8 conditions, and enrolment rights that quietly grant domain-wide impersonation.

06

Lateral movement and persistence

Pass-the-hash and pass-the-ticket, session hunting, local admin sprawl across the estate, and the persistence an attacker would leave behind once inside.

03
How the engagement runs

Six steps, every time.

The same disciplined sequence on every engagement, so you know what is happening and when, and so nothing reaches your report unproven.

01

Scope

A conversation, not a form. We agree the boundary, the accounts, the timing and the escalation contact, and it is enforced technically.

02

Map

We build the real picture of what is reachable, which is almost always larger than the inventory you were given.

03

Prove

Every candidate finding is actively validated against a baseline. Anything that fails is demoted or dropped before it reaches you.

04

Chain

Confirmed findings are linked into the routes an attacker would walk. One finding is a ticket. A path is a breach.

05

Report

Evidence, reproduction steps, prioritised remediation and detection content, as SARIF, JSON and HTML mapped to MITRE ATT&CK.

06

Retest

You fix, we verify, and the report is updated. A finding is not closed because someone said it was.

04
Straight answers

The questions we actually get.

Will this break our domain?

No. The engagement is read-and-prove, not destructive. We do not disable accounts, modify GPOs, or leave persistence. Where a proof would require a state change, we demonstrate the precondition and stop, and we say so in the report rather than doing it quietly.

Do you need Domain Admin to start?

No, and asking for it would defeat the point. We start from the position a real attacker starts from: a standard domain user, or in a black-box engagement, network access alone. The whole finding is how far that gets.

We already run BloodHound. What does this add?

BloodHound shows you edges that may exist. It cannot tell you which are actually walkable given your GPOs, tiering, EDR and account state. We validate the path and demote what does not hold, so your team fixes real routes instead of chasing graph noise.

How long does it take?

A single-domain environment is typically one to two weeks including reporting. Multi-domain or multi-forest takes longer. We scope after a conversation, not from a price list, and you get the number before you commit.

Who actually performs the testing?

A named tester, and you are told who before the engagement starts. The practice is led by Yaniv Avisror, CRTE certified, with nine years administering enterprise infrastructure (MCSA, MCSE) before moving to offensive work.

Start here

Scoping is
a conversation.

Tell us what you are protecting and what worries you. You will get an honest answer on whether this engagement is the right next step, who would run it, and what it would cost, before you commit to anything.

Direct line contact@lahavsec.com
Offensive Security · Defensive Value
Accepting new engagements