
Active Directory Attack Resistance
Active Directory Security Assessment by certified experts
Check your Active Directory configuration for vulnerabilities
Home › Penetration Testing › Active Directory Security Assessment
In any Active Directory environment, there is a complex, dynamic, and often difficult to navigate network of user permissions and objects. Attackers often exploit these relationships to gradually gain more and more privileges and eventually achieve their goal. In many Red Team assessments, the Active Directory environment is a key defensive vulnerability.
Our Active Directory Attack Resistance service is directly designed to test the most common issues of Active Directory installations, covering the top areas where we consistently find weaknesses: Enterprise AD configuration, the unprotected access to credentials, and the quality of the passwords used.
With an audit of the Active Directory for its attack resistance, attack paths are systematically identified and hardening potentials are worked out.
Compared to a Red Team Assessment, the AD attack resistance audit is very focused and takes significantly less time due to the significantly reduced complexity of the approach.
Typically, the following three components are checked:
Enterprise AD Configuration
Due to the large number of groups, objects, organizational units, etc. found in a production Active Directory landscape, it is not uncommon to find unwanted combinations as well as obsolete accounts. By cleverly exploiting such combinations, it is often possible for attackers to extend privileges all the way up to the domain administrator. We identify such combinations so that they can be addressed accordingly and paths removed.
Unprotected access to credentials
One of the most common vulnerabilities uncovered through the use of our Red Team is the internally free availability of credentials. Too often these are present, for example in administrative scripts, on unsecured network shares. In this test, we scan the network starting from a client or server for this and similar privileged information.
Quality of passwords used
The technical enforcement of a minimum standard for password quality for both technical and non-technical users is an important component of the actual security of an environment. Nevertheless, these frameworks are often circumvented – sometimes for purely practical reasons, such as setting a temporary password during password reset and setting an initial password. To test the performance of your company’s password management, we try to break as many passwords as possible and, in this context, we also analyze the relevant specifications for setting up and resetting passwords.
Why Redlings?

A Trusted Partner
✓
In-depth threat analysis and consultation
✓
A deep understanding of how hackers work
✓
In accordance with recognized rules of technology (BSI, PTES, PCI DSS, OSSTMM, NIST, OWASP)
✓
Extensive report with recommendations to fix found vulnerabilities
✓
Comprehensive post-test support for effective elimination of detected risks
Have we sparked your interest?
Just give us a call or write us a message!
Related Services

Penetration Testing
Penetration Testing: Secure your digital infrastructure from hackers and criminals. Find security vulnerabilities before the attackers through a pentest.

Network Pentest
A network penetration test is a security assessment for your organization’s internal or external IT infrastructure and exposed network services.

Web Application Penetration Testing
We examine your web applications and web servers for vulnerabilities.

Social Engineering & Phishing Testing
A Social Engineering Security Assessment may range from simple email phishing to sophisticated campaigns using multiple communication techniques including spearphishing, vishing and on-site engagement.

Red Teaming
Assess your organisation’s threat detection and response capabilities using a emulated cyber attack.

Cloud Penetration Testing
With our cloud security assessment one or more systems in a cloud environment are reviewed for security (e.g. AWS, Azure, GCP).


