Active Directory
We assess permissions, delegation and domain configuration.
- ACLs, privileged groups and tiering
- Kerberos, SPNs, delegation and RBCD
- GPO, AD CS, service accounts and secrets
We connect trust relationships, delegation and excessive permissions into attack paths leading to critical systems.
The assessment does not end with weak passwords and GPO settings. We analyse what a compromised account, workstation or application can reach and which relationship enables the next step.
We assess permissions, delegation and domain configuration.
We test cloud identity and administrative boundaries.
Weaknesses are connected to detection and response.
We identify accounts, systems and paths with the greatest business impact.
Approved data is used to model effective permissions, trust and delegation.
We do not become Domain Admin for theatre. Minimal proofs, simulations and dedicated test accounts are preferred.
Fixes are prioritised by how much they shorten real attack paths, not by raw setting count.
The report presents the chain rather than four disconnected warnings.
This model illustrates the analysis method and does not describe a client environment.
Excessive ACLs allow service-account modification
The account is delegated into a higher-trust system
Admin credentials and workstations are not separated
The fix removes the relationship, constrains delegation and adds detection
It depends on the objective. A low-privilege account commonly represents a compromised user; an assumed-breach starting point is also possible.
Destructive activity is excluded. Higher-risk operations require separate approval and dedicated resources or are replaced with a safe proof.
Yes. Hybrid assessments cover AD, Entra ID, applications, synchronisation and relationships between both layers.
We will agree a starting point, crown jewels and a safe validation model.