Active Directory Assessment

Service Overview

Active Directory Assessment by Dognet Technologies is a thorough technical analysis of Microsoft identity infrastructure—Active Directory, Azure AD (Entra ID) and hybrid environments—that constitutes the heart of authentication and authorization in almost all organisations using Microsoft technologies. 90% of ransomware attacks culminate in the compromise of AD domain controllers, because anyone controlling Active Directory controls the entire organization.

Active Directory Assessment

AD

Our assessment systematically evaluates configurations, permits, delegations, trust reports, privileged accounts and Group Policy objects that, if poorly configured, allow an attacker with limited initial access to scale privileges until complete control of the domain.

Verified Attack Techniques and Vulnerability

Testing covers the main chains of attack documented against Active Directory, using the same techniques adopted by ransomware and APT groups:

  • Kerberoasting: identification of service accounts with configured SPN, verification of the complexity of passwords and force of Kerberos ciphers used, assessment of the resistance to offline cracking attacks of TGS hash.
  • AS-REP Roasting: identification of accounts with Kerberos pre authentication disabled, vulnerable to offline craccable hash extraction without the need for initial credentials.
  • Pass-the-Hash / Pass-the-Ticket: verification of configurations that allow reuse of NTLM hash and Kerberos ticket for lateral movement without knowing the passwords in clear.
  • DCSync Attack: identification of accounts or groups with Replicating Directory Changes permissions that allow the extraction of all domain hashs by simulating a domain controller.
  • Golden Ticket and Silver Ticket: check the conditions that allow the creation of Kerberos tickets falsified with arbitrary validity for long-term persistence.
  • BloodHound Attack Paths: complete mapping of privilege escalation paths through analysis of ACL reports, delegations and memberships to groups—identifying each path that leads from a standard user to domain admin.
  • Misconfigured Delegation: Unconstrained Delegation, Constrained Delegation, Resource-Based Constrained Delegation—analysis of configurations that allow unauthorized impersonation.
  • AdminSDHolder and ACL Abuse: Access Control List analysis on critical objects (domain, AdminSDHolder, GPO) to identify excessive permissions that allow privilege escalation stealth.
  • Azure AD / Enter ID: in hybrid environments, analysis of Azure AD Connect configurations, Seamless SSO, PTA/PHS, Privileged roles, Conditional Access policies and Service Principal permissions.

Tools Used

The asset uses well-established professional tools in the security community: BloodHound/SharpHound for mapping AD reports and identifying attack path; Impacket suite for Windows protocols explosion; PowerView and ADRecon for enumeration and configuration analysis; PingCastle for compliance assessment and risk scoring of AD infrastructure; Rubeus for Kerberos analysis; and custom tool developed internally for specific scenarios.

Deliverable

Technical report with: overall risk score of AD infrastructure with benchmark compared to best practices Microsoft and CIS; attack critical paths displayed with noted BloodHound graphs; detailed findings for each vulnerability with severity, real impact and specific remediation steps; prioritized hardening checklist; and technical walkthrough session with the IT team for corrective action planning.

EnglishenEnglishEnglish