Credential exposure
Kerberoasting and AS-REP roasting against service accounts, passwords in SYSVOL and GPP, LAPS misconfiguration, cleartext credentials in scripts and shares, and reversible encryption flags.
Almost every ransomware case ends the same way: an attacker with one ordinary user account walks a chain of misconfigurations to Domain Admin. We walk that chain first, prove each step, and hand your team the exact ACLs, delegations and group memberships to fix.
Your AD was set up in a week by whoever was available, three years and four acquisitions ago. Nobody has audited the nesting since. That is the single most common shape of a domain compromise we see.
Due diligence, cyber insurance and enterprise customers all ask the same question: has a qualified third party tested your domain. This produces the evidence, and the remediation plan behind it.
Collecting the graph is not the same as proving the path. We validate which edges are actually walkable in your environment, and demote the ones that are theoretical.
Not a checklist. These are the paths that end in domain compromise, in the order an adversary would try them.
Kerberoasting and AS-REP roasting against service accounts, passwords in SYSVOL and GPP, LAPS misconfiguration, cleartext credentials in scripts and shares, and reversible encryption flags.
Unconstrained, constrained and resource-based constrained delegation. These are consistently the fastest route from a foothold to Domain Admin, and consistently the least understood.
GenericAll, WriteDACL, WriteOwner, AddMember and ForceChangePassword edges, traced end to end. We show you the chain, not a list of permissions.
NTLM relay, LLMNR and NBT-NS poisoning, PetitPotam-style coercion, and SMB and LDAP signing gaps that make them work.
Vulnerable certificate templates, ESC1 through ESC8 conditions, and enrolment rights that quietly grant domain-wide impersonation.
Pass-the-hash and pass-the-ticket, session hunting, local admin sprawl across the estate, and the persistence an attacker would leave behind once inside.
The same disciplined sequence on every engagement, so you know what is happening and when, and so nothing reaches your report unproven.
A conversation, not a form. We agree the boundary, the accounts, the timing and the escalation contact, and it is enforced technically.
We build the real picture of what is reachable, which is almost always larger than the inventory you were given.
Every candidate finding is actively validated against a baseline. Anything that fails is demoted or dropped before it reaches you.
Confirmed findings are linked into the routes an attacker would walk. One finding is a ticket. A path is a breach.
Evidence, reproduction steps, prioritised remediation and detection content, as SARIF, JSON and HTML mapped to MITRE ATT&CK.
You fix, we verify, and the report is updated. A finding is not closed because someone said it was.
No. The engagement is read-and-prove, not destructive. We do not disable accounts, modify GPOs, or leave persistence. Where a proof would require a state change, we demonstrate the precondition and stop, and we say so in the report rather than doing it quietly.
No, and asking for it would defeat the point. We start from the position a real attacker starts from: a standard domain user, or in a black-box engagement, network access alone. The whole finding is how far that gets.
BloodHound shows you edges that may exist. It cannot tell you which are actually walkable given your GPOs, tiering, EDR and account state. We validate the path and demote what does not hold, so your team fixes real routes instead of chasing graph noise.
A single-domain environment is typically one to two weeks including reporting. Multi-domain or multi-forest takes longer. We scope after a conversation, not from a price list, and you get the number before you commit.
A named tester, and you are told who before the engagement starts. The practice is led by Yaniv Avisror, CRTE certified, with nine years administering enterprise infrastructure (MCSA, MCSE) before moving to offensive work.
Tell us what you are protecting and what worries you. You will get an honest answer on whether this engagement is the right next step, who would run it, and what it would cost, before you commit to anything.
אתר LahavSec פועל להנגשת השירותים והתכנים המוצגים בו לאנשים עם מוגבלות, בהתאם לתקנות שוויון זכויות לאנשים עם מוגבלות (התאמות נגישות לשירות), התשע"ג-2013, ותקן ישראלי 5568 המבוסס על הנחיות WCAG 2.0 ברמה AA.
באתר הוטמע תפריט נגישות המאפשר, בין היתר: הגדלה והקטנה של גודל הטקסט, מצב ניגודיות גבוהה, הדגשת קישורים, מעבר לגופן קריא, ריווח שורות מוגדל, סמן עכבר מוגדל, עצירת אנימציות והקראת העמוד.
חרף מאמצינו להנגיש את כלל הדפים באתר, ייתכן שיתגלו חלקים שטרם הונגשו במלואם. אנו ממשיכים לפעול לשיפור נגישות האתר באופן שוטף.
נתקלתם בבעיית נגישות? נשמח שתפנו אלינו לרכז הנגישות מטעם החברה בכתובת contact@lahavsec.com, ואנו נשתדל להשיב ולטפל בפנייה בהקדם האפשרי.
This site includes an accessibility menu (text size, contrast, underline links, readable font, line spacing, large cursor, stop animations, read‑aloud) per Israeli accessibility regulations (IS 5568 / WCAG 2.0 AA). For accessibility issues, contact .
הצהרת נגישות זו עודכנה לאחרונה בתאריך: 16/07/2026.