Core service
Active Directory Security Assessments
Deep assessment of directory privilege, authentication and trust paths that could lead to domain compromise.
Active Directory security depends on more than privileged-group membership. Delegation, ACLs, certificate templates, service accounts, legacy protocols and operational practices can create indirect routes to control. Safestorm maps these relationships and validates the attack paths that present meaningful risk.
Founder-led technical delivery
Why Safestorm for this assessment
Active Directory is a central part of Felix’s offensive-security background, including enterprise infrastructure, red teaming and advanced attack-path analysis. His OSCP and OSEP training supports a hands-on approach that combines graph-based relationship analysis with manual LDAP, RPC and host enumeration, connecting directory configuration to the techniques an attacker could use to gain, extend and retain privilege.
- More than six years’ offensive-security experience
- OSCP and OSEP certified
- Red teaming, adversary simulation and control validation
- Published IPv6 research presented at BSides London
Felix’s prior experience includes identifying high-impact weaknesses in healthcare environments. Client identities and engagement details remain confidential.
What the assessment covers
Final coverage is agreed during scoping and reflects your technologies, user roles, threat model and operational constraints.
- Domain and forest architecture, trusts, privileged groups and administrative tiering
- Kerberos, NTLM, LDAP signing, channel binding and legacy authentication exposure
- Directory ACLs, delegated permissions, nested groups and control-path analysis
- Service accounts, SPNs, managed service accounts and credential hygiene
- Kerberoasting, AS-REP roasting and password-spraying preconditions
- Group Policy, logon scripts, software deployment and SYSVOL permissions
- Active Directory Certificate Services templates, enrolment rights and escalation paths
- Resource-based constrained delegation, domain trusts and cross-boundary privilege paths
- Credential reuse techniques, including pass-the-hash, where safely applicable
- Local administrator management, endpoint privilege and lateral-movement opportunities
- Domain-controller hardening, audit policy and visibility of identity attacks
Common risks identified
Testing is not limited to this list. These examples illustrate the types of material risk the assessment is designed to uncover.
- A standard domain identity following an indirect path to privileged control
- Kerberos or NTLM weaknesses exposing reusable credentials or enabling relay
- Unsafe certificate templates permitting impersonation or privilege escalation
- Delegated permissions and stale groups granting unintended directory control
- Weak administrative tiering exposing highly privileged sessions to lower-trust systems
A controlled process
How the engagement works
- Step 1
Define domains, forests, trusts, assumed access and critical identity assets
- Step 2
Agree data collection, credential use and safe-validation boundaries
- Step 3
Enumerate directory configuration, permissions and authentication controls
- Step 4
Model privilege relationships and investigate viable attack paths
- Step 5
Validate material escalation routes using proportionate techniques
- Step 6
Report immediate fixes and structural improvements, then retest priorities
Who this service is suitable for
- On-premises Active Directory and hybrid identity environments
- Organisations concerned about ransomware and credential-based intrusion paths
- Directories affected by mergers, legacy administration or complex delegation
- Teams validating identity hardening and privileged-access programmes
Not sure whether this is the right assessment? Safestorm can help define the assurance question before recommending a scope.
Methodology and industry references
Testing is risk-led and tailored rather than reduced to a checklist. Relevant, recognised guidance helps structure coverage and communicate results.
Referencing a framework does not represent certification against it or guarantee compliance with every control.
Frequently asked questions
Is this the same as an internal infrastructure test?
No. There is overlap, but this assessment goes deeper into directory permissions, delegation, authentication configuration, certificate services, trusts and identity-specific privilege paths.
Does the assessment include Microsoft Entra ID?
Hybrid trust and synchronisation may be considered where relevant. A comprehensive Entra ID or wider Azure assessment should be stated explicitly in scope because it introduces a separate control plane and attack surface.
Do you need Domain Administrator access?
Not necessarily. Testing can begin from a representative standard-user position. Read-only administrative data may improve configuration coverage, but active privilege is only requested when justified by the agreed objective.
Define the right scope
Tell us what you need to assess, your timescale and the assurance outcome you need. We will propose a proportionate scope and clear rules of engagement.
Discuss your requirements