Runbook 01 — Active Directory Pentest
Active Directory remains one of the most important security components in enterprise environments.
It commonly controls:
Users
Computers
Authentication
Authorization
Administrative Access
Group Membership
Service Accounts
Enterprise Applications
File Servers
Windows Servers
Security Policies
Trust RelationshipsA weakness in Active Directory can therefore affect much more than a single account or server.
The purpose of this runbook is to provide a repeatable methodology for conducting an authorized Active Directory penetration test.
Use this runbook only in the GoHackersCloud lab, systems you own, purpose-built security training environments, or environments where you have explicit authorization.
Runbook Information
Section titled “Runbook Information”Runbook: 01 — Active Directory Pentest
Track: OffSec
Category: Penetration Testing Runbook
Difficulty: Intermediate → Advanced
Primary Role: Penetration Tester / Security Consultant
Environment: Enterprise Windows / Active Directory
Primary Goal: Identify Active Directory security weaknesses and privilege relationships
Primary Deliverable: Active Directory Penetration Testing Report
When to Use This Runbook
Section titled “When to Use This Runbook”Use this runbook when performing:
Internal Penetration Testing
Active Directory Security Assessment
Identity Security Review
Enterprise Security Assessment
Purple Team Validation
Security Architecture Review
Post-Compromise Impact Analysis
Privilege Path AssessmentActive Directory Pentest Workflow
Section titled “Active Directory Pentest Workflow”Use the following sequence:
AUTHORIZE ↓UNDERSTAND THE ENVIRONMENT ↓IDENTIFY DOMAIN CONTEXT ↓DISCOVER DOMAIN CONTROLLERS ↓MAP USERS ↓MAP GROUPS ↓MAP COMPUTERS ↓REVIEW AUTHENTICATION ↓REVIEW SERVICE ACCOUNTS ↓REVIEW PERMISSIONS ↓REVIEW DELEGATION ↓REVIEW GROUP POLICY ↓REVIEW TRUSTS ↓MAP ADMINISTRATIVE RELATIONSHIPS ↓BUILD ATTACK PATHS ↓VALIDATE SAFELY ↓COLLECT EVIDENCE ↓ASSESS BUSINESS IMPACT ↓RECOMMEND REMEDIATION ↓RETEST01 — Confirm Authorization
Section titled “01 — Confirm Authorization”Before performing any technical activity, confirm:
Who Authorized the Assessment?
Which Domain Is In Scope?
Which Forests Are In Scope?
Which Domain Controllers Are In Scope?
Which Workstations Are In Scope?
Which Servers Are In Scope?
Which Test Accounts Are Provided?
Which Techniques Are Allowed?
Which Activities Are Prohibited?
What Is the Testing Window?
Who Is the Emergency Contact?Scope Record
Section titled “Scope Record”Document:
Customer / Lab:
Assessment Name:
Domain:
Forest:
Authorized Networks:
Authorized Systems:
Authorized Accounts:
Excluded Systems:
Allowed Techniques:
Restricted Techniques:
Testing Window:
Emergency Contact:
Cleanup Requirements:02 — Establish Rules of Engagement
Section titled “02 — Establish Rules of Engagement”Define allowed activities such as:
Domain Enumeration
User Enumeration
Group Enumeration
Computer Enumeration
Permission Analysis
Authentication Review
Group Policy Review
Service Account Review
Trust Analysis
Attack-Path Mapping
Controlled ValidationAvoid unless specifically authorized:
Destructive Testing
Service Disruption
Account Lockout Testing
Mass Password Attempts
Persistence
Production Credential Extraction
Malware Deployment
Security-Control Evasion03 — Prepare the Evidence Workspace
Section titled “03 — Prepare the Evidence Workspace”Create:
AD-Pentest/|+-- 01-Scope/|+-- 02-Domain/|+-- 03-Users/|+-- 04-Groups/|+-- 05-Computers/|+-- 06-Authentication/|+-- 07-Service-Accounts/|+-- 08-Permissions/|+-- 09-GPO/|+-- 10-Delegation/|+-- 11-Trusts/|+-- 12-Attack-Paths/|+-- 13-Evidence/|+-- 14-Findings/|+-- 15-Report/|+-- 16-Retest/Evidence Standard
Section titled “Evidence Standard”For every important observation, capture:
Timestamp
Source Host
Current Identity
Domain
Target Object
Method
Result
Security Significance
Screenshot / Output
Finding Reference04 — Establish Current Identity
Section titled “04 — Establish Current Identity”From an authorized Windows system:
whoamiThen:
whoami /allRecord:
Username
Domain
SID
Groups
Privileges
Integrity Level05 — Identify Domain Context
Section titled “05 — Identify Domain Context”Check:
$env:USERDOMAINand:
$env:USERDNSDOMAINYou can also review:
systeminfoDocument:
Computer Name
Domain Name
DNS Domain
Current User
Current Groups06 — Identify the Domain Controller
Section titled “06 — Identify the Domain Controller”Use:
nltest /dsgetdc:<DOMAIN>Example lab format:
nltest /dsgetdc:corp.novatech.localRecord:
Domain Controller
IP Address
Site
Domain
Forest
Authentication Services07 — Validate DNS
Section titled “07 — Validate DNS”Active Directory depends heavily on DNS.
Use:
nslookup <DOMAIN>Example:
nslookup corp.novatech.localThen identify domain controllers and related records.
Document:
DNS Servers
Domain Controllers
Internal Domains
Hostnames08 — Build the Domain Architecture
Section titled “08 — Build the Domain Architecture”Create a diagram:
FOREST | +-- DOMAIN | +-- DOMAIN CONTROLLERS | +-- ORGANIZATIONAL UNITS | +-- USERS | +-- GROUPS | +-- COMPUTERS | +-- SERVICE ACCOUNTS | +-- GPOs09 — Enumerate Domain Users
Section titled “09 — Enumerate Domain Users”Where authorized:
net user /domainIf Active Directory PowerShell tools are available:
Get-ADUser -Filter *Build:
| User | Enabled | Role | Privilege | Notes |
|---|---|---|---|---|
| analyst01 | Yes | Analyst | Standard | |
| helpdesk01 | Yes | Support | Elevated | Review |
| svc_app | Yes | Service | Service | Review |
| admin01 | Yes | Administrator | High | Critical |
10 — Prioritize Interesting Accounts
Section titled “10 — Prioritize Interesting Accounts”Focus on:
Administrators
Help Desk
Service Accounts
Backup Accounts
Deployment Accounts
Application Accounts
Security Operations
Database Accounts
Legacy Accounts
Dormant Accounts11 — Review User Attributes
Section titled “11 — Review User Attributes”Where authorized, inspect attributes relevant to security.
Examples:
Account Enabled
Password Settings
Group Membership
Description
ServicePrincipalName
Administrative Roles
Account Age
Password AgeDo not treat every unusual attribute as a vulnerability.
12 — Identify Disabled and Dormant Accounts
Section titled “12 — Identify Disabled and Dormant Accounts”Look for:
Disabled Users
Dormant Users
Former Employee Accounts
Unused Administrative Accounts
Unused Service AccountsSecurity concern:
OLD ACCOUNT +UNNECESSARY PRIVILEGE =UNNECESSARY ATTACK SURFACE13 — Enumerate Domain Groups
Section titled “13 — Enumerate Domain Groups”Use:
net group /domainor:
Get-ADGroup -Filter *Document:
Group Name
Purpose
Members
Nested Groups
Administrative Rights14 — Review Domain Admins
Section titled “14 — Review Domain Admins”Use:
net group "Domain Admins" /domainRecord:
Direct Members
Nested Membership
Account Purpose
Business Requirement15 — Review Other Privileged Groups
Section titled “15 — Review Other Privileged Groups”Depending on environment, review:
Enterprise Admins
Schema Admins
Administrators
Account Operators
Server Operators
Backup Operators
DNSAdmins
Group Policy Administrators
Custom Administrative GroupsDo not assume:
Not Domain Admin=Not Privileged16 — Analyze Nested Group Membership
Section titled “16 — Analyze Nested Group Membership”A common privilege relationship is:
USER ↓GROUP A ↓GROUP B ↓ADMINISTRATIVE GROUPExample:
helpdesk01 ↓HelpDesk ↓ServerSupport ↓Local AdministratorMap nested membership carefully.
17 — Build the Group Relationship Map
Section titled “17 — Build the Group Relationship Map”Create:
USER ↓GROUP ↓NESTED GROUP ↓RESOURCE ↓PERMISSIONThis often reveals hidden privilege.
18 — Enumerate Computers
Section titled “18 — Enumerate Computers”If AD PowerShell is available:
Get-ADComputer -Filter * |Select-Object Name, OperatingSystemDocument:
| Computer | OS | Role | Criticality |
|---|---|---|---|
| DC01 | Windows Server | Domain Controller | Critical |
| APP01 | Windows Server | Application | High |
| FILE01 | Windows Server | File Server | High |
| WS01 | Windows | Workstation | Medium |
19 — Classify Systems
Section titled “19 — Classify Systems”Classify assets as:
Domain Controllers
Administrative Workstations
Application Servers
Database Servers
File Servers
User Workstations
Jump Servers
Management Servers20 — Review Domain Controllers
Section titled “20 — Review Domain Controllers”Document:
Domain Controller Name
Operating System
Site
Network Location
Administrative Access
Security Controls
LoggingDomain controllers should receive the highest security priority.
21 — Review Authentication Architecture
Section titled “21 — Review Authentication Architecture”Understand:
Kerberos
NTLM
LDAP
LDAPS
SMB
DNS
RPCConceptually:
USER ↓AUTHENTICATION ↓DOMAIN CONTROLLER ↓ACCESS TOKEN / TICKET ↓ENTERPRISE RESOURCE22 — Review Kerberos Context
Section titled “22 — Review Kerberos Context”From an authenticated training system:
klistDocument:
Current Tickets
Domain
Authentication ContextThe goal is to understand the environment, not to extract or forge authentication material.
23 — Review Password Policy
Section titled “23 — Review Password Policy”Use:
net accounts /domainDocument:
Minimum Length
Maximum Age
Minimum Age
Lockout Threshold
Lockout DurationAssess the policy in context.
24 — Review Account Lockout
Section titled “24 — Review Account Lockout”Ask:
Is Lockout Enabled?
Is the Threshold Appropriate?
Could Normal Users TriggerOperational Disruption?
Are Privileged AccountsProtected Differently?Do not intentionally trigger lockouts without explicit authorization.
25 — Review Administrative Accounts
Section titled “25 — Review Administrative Accounts”Determine whether administrators use:
Separate Admin Accounts
Dedicated Workstations
MFA
Privileged Access Management
Administrative TieringA common secure pattern is:
NORMAL ACCOUNT ↓Daily Work
ADMIN ACCOUNT ↓Privileged Administration26 — Review Service Accounts
Section titled “26 — Review Service Accounts”Identify accounts used by:
Windows Services
Applications
Databases
Backup Systems
Scheduled Tasks
Monitoring
AutomationIf AD tools are available:
Get-ADUser -Filter {ServicePrincipalName -like "*"} `-Properties ServicePrincipalName27 — Build the Service Account Inventory
Section titled “27 — Build the Service Account Inventory”| Account | Service | Host | Privilege | Owner | Review |
|---|---|---|---|---|---|
| svc_app | Application | APP01 | Medium | App Team | Yes |
| svc_backup | Backup | FILE01 | High | Infra | Yes |
28 — Assess Service Account Governance
Section titled “28 — Assess Service Account Governance”Review:
Privilege
Password Management
Interactive Logon
Group Membership
Host Access
Application Access
Account Ownership
RotationAsk:
Does This AccountHave More AccessThan Its Service Requires?29 — Prefer Managed Service Identities
Section titled “29 — Prefer Managed Service Identities”Where possible, recommend:
Managed Service Accounts
gMSA
Automatic Password Management
Restricted Host Usage
Least Privilege30 — Review Active Directory Permissions
Section titled “30 — Review Active Directory Permissions”Active Directory objects have access control lists.
Conceptually:
IDENTITY ↓PERMISSION ↓AD OBJECTRelevant permissions may include the ability to:
Read
Write
Modify Membership
Reset Password
Modify Attributes
Modify Permissions
Take Ownership31 — Build the AD Permission Matrix
Section titled “31 — Build the AD Permission Matrix”| Identity | Object | Permission | Business Need | Risk |
|---|---|---|---|---|
| HelpDesk | Users OU | Reset Password | Yes | Medium |
| DevOps | Service Group | Modify Members | Review | High |
| LegacyAdmin | Server OU | Full Control | No | Critical |
32 — Review Delegated Administration
Section titled “32 — Review Delegated Administration”Delegation is common and often necessary.
Review:
Help Desk Delegation
Server Administration
Password Reset Rights
Group Membership Management
OU Administration
Application AdministrationThe question is not:
Does Delegation Exist?It is:
Is DelegationLimited to What the Role Needs?33 — Identify Excessive Delegation
Section titled “33 — Identify Excessive Delegation”Example:
HELP DESK ↓Reset Password ↓Privileged AdministratorIf unintended, this could create a dangerous relationship.
34 — Review Object Ownership
Section titled “34 — Review Object Ownership”Ownership may grant the ability to change permissions.
Map:
IDENTITY ↓OWNS ↓AD OBJECTCheck whether ownership aligns with business responsibilities.
35 — Review ACL Inheritance
Section titled “35 — Review ACL Inheritance”Understand whether permissions were:
Explicit
Inherited
Nested Through GroupsMisconfigured inheritance can unintentionally spread privilege.
36 — Review Group Membership Control
Section titled “36 — Review Group Membership Control”Determine:
Who Can Add Members?
Who Can Remove Members?
Who Owns Privileged Groups?
Are Changes Monitored?37 — Review Administrative Paths
Section titled “37 — Review Administrative Paths”An administrative path might look like:
USER ↓SUPPORT GROUP ↓LOCAL ADMIN ON SERVER ↓ADMINISTRATIVE SESSION ↓HIGHER-VALUE SYSTEMThe goal is to understand these relationships.
38 — Review Local Administrator Relationships
Section titled “38 — Review Local Administrator Relationships”On authorized Windows systems:
net localgroup administratorsor:
Get-LocalGroupMember AdministratorsDocument:
Domain Users
Domain Groups
Local Users
Service Accounts39 — Identify Administrative Overlap
Section titled “39 — Identify Administrative Overlap”Example:
ADMIN A ↓SERVER 1
ADMIN B ↓SERVER 1 ↓SERVER 2
PRIVILEGED ADMIN ↓SERVER 2Administrative overlap can create indirect attack paths.
40 — Review Administrative Tiering
Section titled “40 — Review Administrative Tiering”A strong model may separate:
Tier 0Domain Controllers / Identity
Tier 1Servers / Applications
Tier 2WorkstationsIdeally:
Tier 0 Admin XNormal Workstation Logon41 — Review Privileged Sessions
Section titled “41 — Review Privileged Sessions”Determine whether highly privileged accounts routinely authenticate to:
Workstations
Application Servers
Shared Admin Systems
Lower-Trust ServersSuch activity can expand credential and privilege exposure.
42 — Review Group Policy
Section titled “42 — Review Group Policy”Group Policy can control:
Security Settings
Firewall
Audit Policy
User Rights
Software
Scripts
Local Groups
Administrative ConfigurationUse:
gpresult /rto understand applicable policy from the current host.
43 — Review GPO Architecture
Section titled “43 — Review GPO Architecture”Build:
DOMAIN ↓OU ↓GPO ↓COMPUTERS / USERSDocument:
GPO Name
Scope
Purpose
Owner
Security Filtering44 — Review Privileged GPO Management
Section titled “44 — Review Privileged GPO Management”Ask:
Who Can Create GPOs?
Who Can Edit GPOs?
Who Can Link GPOs?
Who Can Modify GPO Permissions?Because GPOs can influence many systems, these rights can be highly sensitive.
45 — Review Logon Scripts
Section titled “45 — Review Logon Scripts”If GPOs deploy scripts, review:
Script Location
Ownership
Permissions
Execution Context
Business PurposeA privileged process should not depend on files writable by unauthorized users.
46 — Review Delegation
Section titled “46 — Review Delegation”Kerberos delegation enables services to act on behalf of users in specific scenarios.
Review conceptually:
Unconstrained Delegation
Constrained Delegation
Resource-Based Constrained DelegationThe security question is:
Is Delegation Necessary?
Is It Restricted?
Which Systems Participate?
Which Identities Control It?47 — Build Delegation Inventory
Section titled “47 — Build Delegation Inventory”| System / Account | Delegation Type | Purpose | Owner | Risk |
|---|---|---|---|---|
| APP01 | Constrained | Application | App Team | Review |
| Legacy01 | Legacy configuration | Unknown | Unknown | High |
48 — Review Domain Trusts
Section titled “48 — Review Domain Trusts”Enterprise environments may contain:
Parent / Child Domains
Multiple Forests
Acquired Companies
Legacy Domains
Partner TrustsMap:
DOMAIN A ↓TRUST ↓DOMAIN B49 — Trust Assessment Questions
Section titled “49 — Trust Assessment Questions”Ask:
What Type of Trust Exists?
What Direction?
Is It Transitive?
Why Does It Exist?
Which Identities Can Cross It?
Is Selective Authentication Used?
Who Owns the Trust?50 — Review SMB and File Services
Section titled “50 — Review SMB and File Services”Active Directory users often receive access through groups.
Map:
USER ↓GROUP ↓FILE SHARE ↓DATAReview only authorized shares.
51 — Identify Sensitive Shares
Section titled “51 — Identify Sensitive Shares”Look for:
Deployment
Administration
Software
Backups
Scripts
Documentation
Application ConfigurationAvoid unnecessary collection.
52 — Minimum Evidence Principle
Section titled “52 — Minimum Evidence Principle”Do not:
Copy All FilesInstead:
Demonstrate the Permission
Capture Minimal Evidence
Redact Sensitive Data
Document Business Impact53 — Review Password and Secret Exposure
Section titled “53 — Review Password and Secret Exposure”Operational environments may accidentally place secrets in:
Scripts
Configuration
Documentation
Deployment Files
Backups
Shared FoldersIf discovered:
Document Exposure
Do Not Reuse Outside Scope
Do Not Include Full Secretsin Reports54 — Review Administrative Workstations
Section titled “54 — Review Administrative Workstations”High-privilege administration should ideally occur from hardened systems.
Assess:
Who Uses Them?
Which Roles?
Which Networks?
Which Security Controls?
Which Accounts Can Log On?55 — Review Remote Administration
Section titled “55 — Review Remote Administration”Common technologies include:
RDP
WinRM
PowerShell Remoting
Administrative Shares
Management PlatformsDetermine:
Who Can Use Them?
From Which Networks?
To Which Systems?
Is MFA Used?
Is Access Logged?56 — Review Network Segmentation
Section titled “56 — Review Network Segmentation”Identity security and network security should reinforce each other.
Example:
USER NETWORK XDOMAIN CONTROLLERMANAGEMENT PORTSbut:
ADMIN NETWORK ↓DOMAIN CONTROLLERMANAGEMENT PORTS57 — Build the Access Matrix
Section titled “57 — Build the Access Matrix”| Source | Destination | Service | Expected | Observed |
|---|---|---|---|---|
| User subnet | DC01 | Admin service | Deny | |
| Admin subnet | DC01 | Admin service | Allow | |
| App server | DC01 | Required AD | Allow |
58 — Identify Active Directory Attack Paths
Section titled “58 — Identify Active Directory Attack Paths”You are now ready to connect findings.
Example:
LOW-PRIVILEGE USER ↓HELPDESK GROUP ↓PASSWORD RESET RIGHT ↓SERVER ADMIN ↓CRITICAL SERVERAnother:
USER ↓CUSTOM GROUP ↓LOCAL ADMIN ↓APPLICATION SERVER ↓PRIVILEGED ADMIN SESSION59 — Attack Paths Are Relationships
Section titled “59 — Attack Paths Are Relationships”Do not report only:
Misconfigured Group
Weak Permission
Excessive Local AdminAsk:
HOW DO THEY CONNECT?60 — Create Attack Path AP-01
Section titled “60 — Create Attack Path AP-01”Attack Path ID:AD-AP-01
Starting Identity:helpdesk01
Relationship 01:Member of HelpDesk
Relationship 02:HelpDesk can reset passwords forServerAdmins
Target:Server Administrator Identity
Potential Impact:A compromised HelpDesk account couldinfluence a higher-privilegedadministrative identity.
Recommended Path Break:Limit delegated reset rights tonon-privileged user populations.61 — Create Attack Path AP-02
Section titled “61 — Create Attack Path AP-02”Attack Path ID:AD-AP-02
Starting Identity:support01
Relationship:Support group has local administrativerights on APP01.
Relationship:Privileged administrators regularlyuse APP01.
Target:Higher-value administrative context.
Impact:Administrative overlap increases thesecurity significance of APP01.
Recommended Path Break:Implement administrative tiering andremove unnecessary local administratorrights.62 — Validate Paths Safely
Section titled “62 — Validate Paths Safely”Before validation:
REVIEW SCOPE ↓CONFIRM IMPACT ↓IDENTIFY MINIMUM PROOF ↓VALIDATE ↓COLLECT EVIDENCE ↓STOPDo not continue simply because additional impact might be possible.
63 — Do Not Over-Exploit
Section titled “63 — Do Not Over-Exploit”Professional validation should answer:
Does the Permission Exist?
Can the Starting Identity Use It?
Does It Reach the Identified Target?
What Control Should Break the Path?Once demonstrated, unnecessary expansion of access is not required.
64 — Create the Findings Register
Section titled “64 — Create the Findings Register”| ID | Finding | Severity | Attack Path |
|---|---|---|---|
| AD-001 | Excessive delegated privileges | High | AP-01 |
| AD-002 | Broad local administrator rights | High | AP-02 |
| AD-003 | Weak service-account governance | High | AP-03 |
| AD-004 | Privileged GPO management | Critical | AP-04 |
| AD-005 | Sensitive share exposure | Medium | AP-05 |
65 — Finding AD-001
Section titled “65 — Finding AD-001”Title:Excessive Password Reset Delegation
Observation:A support group can reset passwords foraccounts with administrative access.
Impact:Compromise of a support account couldprovide a path toward privilegedidentities.
Recommendation:Restrict password-reset delegation andexclude privileged administrativeaccounts from general support scope.66 — Finding AD-002
Section titled “66 — Finding AD-002”Title:Broad Local Administrator Assignment
Observation:A general support group has localadministrator access across multipleservers.
Impact:Compromise of one support identity couldincrease access across many enterprisesystems.
Recommendation:Use server-specific administrative rolesand remove broad local administratorassignments.67 — Finding AD-003
Section titled “67 — Finding AD-003”Title:Excessive Service Account Privilege
Observation:A service identity is assigned privilegesbeyond documented applicationrequirements.
Impact:Compromise of the application or serviceidentity could provide unnecessary accessto additional resources.
Recommendation:Apply least privilege and migrate tomanaged service identities where possible.68 — Finding AD-004
Section titled “68 — Finding AD-004”Title:Excessive Group Policy Management Rights
Observation:A non-Tier-0 administrative group canmodify a GPO applied to sensitivesystems.
Impact:Unauthorized modification of securitypolicy could affect multiple privilegedassets.
Recommendation:Restrict GPO administration to dedicatedauthorized identities and monitor allpolicy changes.69 — Finding AD-005
Section titled “69 — Finding AD-005”Title:Sensitive Administrative InformationExposed Through File Share
Observation:Operational files containing sensitiveconfiguration are accessible to moreusers than required.
Impact:The information could support additionalreconnaissance and privilege-pathanalysis.
Recommendation:Restrict access according to businessneed and move secrets to approved secretmanagement systems.70 — Risk Prioritization
Section titled “70 — Risk Prioritization”Consider:
Starting Access Required
Privilege Gained
Target Criticality
Number of Affected Systems
Number of Affected Users
Ease of Abuse
Existing Monitoring
Attack-Path PositionRisk Matrix
Section titled “Risk Matrix”| Severity | Typical Meaning |
|---|---|
| Critical | Direct or near-direct path to Tier-0 / identity control |
| High | Major privilege expansion or sensitive administrative path |
| Medium | Meaningful weakness requiring additional conditions |
| Low | Limited security exposure |
| Informational | Hardening or governance observation |
71 — Identity Hardening Recommendations
Section titled “71 — Identity Hardening Recommendations”Prioritize:
Least Privilege
Administrative Tiering
Dedicated Admin Accounts
MFA
Privileged Access Management
Regular Access Reviews
Removal of Dormant Accounts72 — Group Hardening
Section titled “72 — Group Hardening”Review:
Privileged Group Membership
Nested Membership
Group Ownership
Membership Change Rights
Temporary Access
Approval Process73 — Service Account Hardening
Section titled “73 — Service Account Hardening”Prefer:
gMSA
Managed Password Rotation
Non-Interactive Accounts
Restricted Host Usage
Minimal Group Membership
Minimal Network Access74 — Domain Controller Hardening
Section titled “74 — Domain Controller Hardening”Protect DCs with:
Restricted Administration
Dedicated Admin Networks
No Normal User Activity
Tier-0 Accounts
Strong Monitoring
Secure Baselines
Patch Management75 — GPO Hardening
Section titled “75 — GPO Hardening”Apply:
Restricted Editors
Restricted Link Rights
Change Monitoring
Backup
Version Control
Regular Review76 — Delegation Hardening
Section titled “76 — Delegation Hardening”Review all delegation for:
Business Need
Scope
Target Services
Controlling Identity
Legacy ConfigurationRemove configurations that are no longer required.
77 — Trust Hardening
Section titled “77 — Trust Hardening”For each trust:
Confirm Business Need
Restrict Authentication
Review Direction
Review Transitivity
Monitor Cross-Domain Activity
Remove Legacy Trusts78 — Monitoring Strategy
Section titled “78 — Monitoring Strategy”Active Directory monitoring should cover:
Authentication
User Creation
User Modification
Group Membership Changes
Privilege Assignment
GPO Changes
Service Account Changes
Trust Changes
Administrative Logons79 — Important Windows Security Events
Section titled “79 — Important Windows Security Events”Examples:
| Event ID | Meaning |
|---|---|
| 4624 | Successful logon |
| 4625 | Failed logon |
| 4672 | Special privileges assigned |
| 4720 | User created |
| 4726 | User deleted |
| 4728 | Member added to global group |
| 4732 | Member added to local group |
| 4738 | User account changed |
| 4740 | Account locked out |
| 4756 | Member added to universal group |
| 4768 | Kerberos TGT request |
| 4769 | Kerberos service ticket request |
80 — Monitor Privileged Group Changes
Section titled “80 — Monitor Privileged Group Changes”High-value groups should receive increased monitoring.
Examples:
Domain Admins
Enterprise Admins
Administrators
Custom Tier-0 GroupsChanges should generate:
Alert
Context
Approval Validation
Investigation81 — Monitor Administrative Logons
Section titled “81 — Monitor Administrative Logons”Ask:
Where Are Tier-0 AccountsAuthenticating?
Are Privileged UsersLogging Into Workstations?
Are Administrators UsingShared Servers?Unexpected administrative logons may expose privilege paths.
82 — Cleanup
Section titled “82 — Cleanup”After completing the assessment:
Remove Test Accounts
Remove Temporary Memberships
Restore Permissions
Restore Test Objects
Remove Temporary Files
Terminate Test Sessions
Verify Domain Health
Secure Evidence83 — Retesting
Section titled “83 — Retesting”After remediation:
ORIGINAL PATH ↓REPEAT ENUMERATION ↓VERIFY PERMISSION REMOVED ↓VERIFY MEMBERSHIP REMOVED ↓VERIFY ACCESS DENIED ↓CONFIRM ATTACK PATH BROKENRetest Example
Section titled “Retest Example”Before:
helpdesk01 ↓Reset Password ↓ServerAdminAfter:
helpdesk01 ↓X ↓ServerAdmin84 — Reporting Structure
Section titled “84 — Reporting Structure”Use:
01 Executive Summary
02 Scope
03 Rules of Engagement
04 Active Directory Architecture
05 Identity Assessment
06 Group Assessment
07 Computer Assessment
08 Authentication Assessment
09 Service Accounts
10 AD Permissions
11 Administrative Delegation
12 Group Policy
13 Kerberos Delegation
14 Domain Trusts
15 Administrative Paths
16 Findings
17 Attack Paths
18 Risk Prioritization
19 Remediation
20 Retest
21 CleanupExecutive Summary Example
Section titled “Executive Summary Example”The Active Directory penetration testidentified security weaknesses involvingdelegated permissions, administrativegroup relationships, service-accountprivileges, and administrative accesspatterns.
Several findings created indirect pathsfrom lower-privileged identities towardhigher-value systems and administrativeroles.
The primary remediation priority is toreduce excessive privilege, implementadministrative tiering, strengthenservice-account governance, restrictdelegated permissions, and improvemonitoring of privileged identityactivity.Active Directory Finding Template
Section titled “Active Directory Finding Template”Finding ID:
Title:
Affected Domain:
Affected Identity:
Affected Object:
Starting Privilege:
Permission / Relationship:
Description:
Attack Path:
Evidence:
Security Impact:
Likelihood:
Severity:
Root Cause:
Recommendation:
Retest Procedure:Attack Path Worksheet
Section titled “Attack Path Worksheet”Attack Path ID:
Starting Identity:
Initial Privilege:
Group Membership:
Delegated Permission:
Controlled Resource:
Intermediate System:
Administrative Relationship:
Target Identity:
Target Asset:
Business Impact:
Existing Security Control:
Control Gap:
Recommended Path Break:Active Directory Pentest Checklist
Section titled “Active Directory Pentest Checklist”- Authorization confirmed
- Domain documented
- Forest documented
- Networks documented
- Systems documented
- Exclusions documented
- Allowed techniques documented
Domain
Section titled “Domain”- Domain context identified
- Domain controllers identified
- DNS reviewed
- Domain architecture mapped
- Users enumerated
- Administrative users identified
- Service accounts identified
- Disabled accounts reviewed
- Dormant accounts reviewed
Groups
Section titled “Groups”- Groups enumerated
- Privileged groups reviewed
- Nested memberships reviewed
- Group ownership reviewed
- Membership-control rights reviewed
Computers
Section titled “Computers”- Computers enumerated
- Domain controllers classified
- Servers classified
- Workstations classified
- Critical systems identified
Authentication
Section titled “Authentication”- Password policy reviewed
- Lockout policy reviewed
- Kerberos context reviewed
- Administrative authentication reviewed
- MFA use reviewed
Service Accounts
Section titled “Service Accounts”- Service accounts inventoried
- Privilege reviewed
- Group membership reviewed
- Password management reviewed
- Interactive use reviewed
- gMSA opportunities identified
Permissions
Section titled “Permissions”- Delegated rights reviewed
- Object ownership reviewed
- ACL inheritance reviewed
- Privileged-object permissions reviewed
Administration
Section titled “Administration”- Local administrators reviewed
- Administrative overlap reviewed
- Tiering reviewed
- Privileged logon patterns reviewed
- GPOs inventoried
- GPO scope reviewed
- GPO ownership reviewed
- Edit rights reviewed
- Link rights reviewed
- Scripts reviewed
Delegation
Section titled “Delegation”- Delegation inventoried
- Business need validated
- Controlling identities reviewed
- Legacy configurations reviewed
Trusts
Section titled “Trusts”- Trusts documented
- Direction reviewed
- Transitivity reviewed
- Authentication restrictions reviewed
- Business ownership confirmed
Attack Paths
Section titled “Attack Paths”- Relationships correlated
- Starting identities identified
- Intermediate privileges identified
- Critical targets identified
- Paths validated safely
- Path-breaking controls documented
Reporting
Section titled “Reporting”- Evidence collected
- Findings documented
- Risk assigned
- Root causes identified
- Remediation provided
- Cleanup completed
- Retest procedure defined
30 Active Directory Pentest Review Questions
Section titled “30 Active Directory Pentest Review Questions”- What is Active Directory?
- What is the difference between a domain and a forest?
- What is a domain controller?
- Why is DNS important to Active Directory?
- What is Kerberos?
- What is LDAP?
- Why should privileged groups be reviewed?
- What is nested group membership?
- Why can nested groups hide privilege?
- What is delegated administration?
- Why can excessive password-reset rights be risky?
- What is an Active Directory ACL?
- Why is object ownership security-sensitive?
- What is a service account?
- What is a gMSA?
- Why should service accounts use least privilege?
- What is Group Policy?
- Why are GPO modification rights highly sensitive?
- What is administrative tiering?
- What is Tier 0?
- Why should privileged users avoid standard workstations?
- What is Kerberos delegation?
- What is an Active Directory trust?
- Why should old trusts be reviewed?
- Why are local administrator relationships important?
- What is an Active Directory attack path?
- Why should individual findings be correlated?
- What does controlled validation mean?
- Why should privileged identity events be monitored?
- How do you confirm remediation broke an attack path?
Final Active Directory Pentest Mental Model
Section titled “Final Active Directory Pentest Mental Model”Remember:
DOMAIN ↓IDENTITIES ↓GROUPS ↓PERMISSIONS ↓COMPUTERS ↓ADMINISTRATION ↓AUTHENTICATION ↓SERVICE ACCOUNTS ↓GPO ↓DELEGATION ↓TRUSTS ↓RELATIONSHIPS ↓ATTACK PATHS ↓BUSINESS IMPACTDo not think only:
Who Is Domain Admin?Think:
WHO CAN CONTROLSOMETHING THAT CONTROLSSOMETHING ELSE?For example:
USER ↓GROUP ↓DELEGATED PERMISSION ↓SERVER ADMIN ↓CRITICAL SERVERor:
USER ↓CUSTOM ADMIN GROUP ↓APPLICATION SERVER ↓PRIVILEGED ADMIN ACTIVITY ↓HIGHER-VALUE IDENTITYA strong Active Directory penetration tester should be able to explain:
WHERE THE PATH STARTS
WHICH IDENTITY RELATIONSHIPCREATES THE RISK
WHICH SECURITY BOUNDARY FAILS
WHAT THE FINAL BUSINESSIMPACT COULD BE
WHICH CONTROL SHOULDBREAK THE PATHWhat’s Next?
Section titled “What’s Next?”➡️ Runbook 02 — Enterprise Pentest
The next runbook expands beyond Active Directory into the complete enterprise environment.
You will use a repeatable methodology covering:
SCOPE ↓NETWORK DISCOVERY ↓ASSET INVENTORY ↓SERVICE ENUMERATION ↓WINDOWS ↓LINUX ↓WEB APPLICATIONS ↓IDENTITY ↓ACTIVE DIRECTORY ↓SEGMENTATION ↓ATTACK-PATH MAPPING ↓CONTROLLED VALIDATION ↓EVIDENCE ↓REPORTINGThe objective will be to turn individual technical assessments into a complete enterprise penetration-testing methodology.