Problem Threats Stories How it works Blogs Pricing
Attack Paths

Active Directory penetration testing: the attack paths that turn one login into Domain Admin

A phished password should not be able to reach the whole domain. In most networks, it can. Here is how the path forms, and how to cut it.

By Arxiis ResearchUpdated 15 min read

Key takeaways

  • Active Directory penetration testing looks for identity attack paths: chains of small misconfigurations that let a normal user reach Domain Admin.
  • Sophos found attackers now reach the AD server in a median of about 3.4 hours after they get in, about 70 percent faster than the year before.3
  • Four weaknesses cause most full-domain takeovers: weak service account passwords (Kerberoasting), over-permissive rights, unsafe delegation, and misconfigured certificate templates.
  • Microsoft says more than 97 percent of identity attacks are password attacks, and multi-factor authentication blocks over 99 percent of them.2
  • The highest-value fix is tiering: never let Domain Admin credentials log in to an ordinary desktop, so a phished user cannot steal them.11
  • Test AD at least yearly and after big changes, and add continuous attack-path checks because the domain drifts every day.

One person clicks a link in a fake email. They type their password into a page that is not really the payroll site. That is a bad day, but it should be a small one. The attacker has a single low-level account and nothing more. In a healthy network, that is where the story ends. In most networks, it is where the story begins. Within a few hours, that one login can become full control of every server, mailbox, and backup in the company. The bridge that carries the attacker from a stolen password to total control is Active Directory, and the route they take is called an attack path.

Last reviewed on 19 October 2026 against the ASD and CISA joint AD guidance, Microsoft, Sophos, CrowdStrike, Mandiant, and SpecterOps primary sources.

What is Active Directory penetration testing?

Active Directory penetration testing is a controlled security assessment that hunts for the identity attack paths inside your domain. Testers start from a low-level position, such as one ordinary user, and try to reach Domain Admin by chaining together weak permissions, weak passwords, and unsafe trust, exactly as a real attacker would.

Active Directory, usually shortened to AD, is the system most organisations use to decide who can log in and what they can touch. It holds every user, computer, group, and policy. When you sign in to your work laptop, AD is what checks your password and hands you the keys to the shares and apps you are allowed to use. Because it sits under almost everything, it is the highest-value target in the building.

A normal network penetration test scans for open ports and unpatched software. It answers the question "what is broken?" An Active Directory security assessment asks a sharper question: "starting as a nobody, what is the shortest route to owning everything?" The difference matters. A domain can have every server patched and still hand over Domain Admin in three steps, because the weakness is not a missing patch. It is how permissions and trust have been set up over years of quiet, well-meant changes.

Attack path
A chain of individual weaknesses that, joined together, let an attacker move from a low-privilege starting point to a high-privilege goal such as Domain Admin. Each link may look harmless on its own. The danger is the chain.

Good testing does not stop at "you have a problem." It shows the exact path, ranks it by how easy it is to walk, and tells you which single fix breaks the most paths at once. That last point is the real value. You rarely need to fix everything. You need to find the few choke points that cut the most routes.

Why is Active Directory the main target in ransomware attacks?

Active Directory controls access to almost every system, so an attacker who takes it over can push ransomware to every machine at the same time. Australian and US agencies call AD the most widely used enterprise identity system, weakened by permissive defaults, complex permissions, and legacy protocols, which makes its attack surface very large.

In their joint guidance, the Australian Signals Directorate, CISA, the NSA, and partner agencies put it plainly. Active Directory is "the most widely used authentication and authorisation solution in enterprise information technology networks globally," and it is "susceptible to compromise due to its permissive default settings, its complex relationships and permissions, support for legacy protocols and a lack of tooling."1 They add that "every user in Active Directory has sufficient permission to enable them to both identify and exploit weaknesses," which makes the attack surface "exceptionally large and difficult to defend against."1

Ransomware crews have learned that the fastest way to encrypt a whole company is not to attack machines one by one. It is to seize the thing that already talks to every machine. Once you are Domain Admin, you can use the domain's own tools to deploy the payload everywhere in minutes. That is why AD is not a side quest in modern intrusions. It is the main objective.

3.4 hrsMedian time for attackers to reach the AD server after getting inSophos 2026
29 minAverage eCrime breakout time, when an attacker starts moving sidewaysCrowdStrike 2026
97%Of identity attacks are password attacks, per MicrosoftMDDR 2025
22 secMedian hand-off from initial access to a second threat groupMandiant 2026

The clock is the point. CrowdStrike measured an average "breakout time," the gap between the first foothold and the first sideways move, of just 29 minutes in 2025, with the fastest case at 27 seconds.4 Sophos found that once inside, attackers reach the AD server in a median of about 3.4 hours, roughly 70 percent faster than the year before, and that 67 percent of the incidents it handled were rooted in compromised identity.3 Mandiant reports that access is now handed from the crew that breaks in to the crew that does the damage in a median of 22 seconds, down from more than eight hours in 2022.5 The domain falls long before most teams have finished reading the first alert. If you want the wider picture of how long intruders sit undetected, see our piece on attacker dwell time and the 194 days of silence.

!

Old servers make it worse. Sophos found 62 percent of the compromised servers it examined were running operating systems past mainstream support, and in its 2026 data a further 13 percent of identified Windows Servers were already end-of-life.3 An unsupported domain controller is a gift to an attacker.

How does a typical AD attack path work?

A typical Active Directory attack path runs through six stages: foothold, enumeration, credential theft through Kerberos weaknesses, abuse of permissions or delegation, abuse of certificate services, and finally domain dominance. Each stage feeds the next, and a single misconfiguration can let the attacker skip several steps at once.

No two intrusions are identical, but the shape repeats. Below is the path most testers and real attackers follow, with the MITRE ATT&CK technique that matches each move. MITRE ATT&CK is a public catalogue of attacker behaviour, and its Enterprise version has 15 tactics as of version 19 in 2026.14

Stage 1. Foothold

The attacker gets one valid account. Usually this is phishing (ATT&CK T1566), a password sprayed across many accounts until one works (T1110.003), or a token stolen from a third party. They do not need admin rights yet. They just need to be inside as someone.

Stage 2. Enumeration

Now they map the ground. Any domain user can read most of the directory, so the attacker quietly lists accounts (T1087.002), groups (T1069.002), and trusts (T1482). This is where they find the weak spots: service accounts, accounts with special flags, and permissions that were meant to be temporary and never removed. Tools such as BloodHound turn this raw data into a graph of who can reach whom.

Stage 3. Credential theft through Kerberos weaknesses

Kerberos is the ticket system AD uses to prove identity. Two of its features can be turned against it. In Kerberoasting (T1558.003), any user can ask for a service ticket tied to a service account, then take it away and crack the account's password offline, where your lockout limits and alerts cannot see them. In AS-REP Roasting (T1558.004), accounts that have Kerberos pre-authentication switched off leak crackable data to anyone who asks. A single weak service account password can end the game here.

Stage 4. Permission and delegation abuse

Sometimes the attacker does not need to crack anything. Years of "just give them write access for now" leave permissions, called ACLs, that let one account reset another account's password or add itself to a powerful group (T1098). Kerberos delegation, a feature that lets a service act on a user's behalf, is even sharper. When it is left unconstrained, a compromised server can capture the tickets of anyone who connects to it, including a domain controller.

Stage 5. Certificate services abuse

Active Directory Certificate Services, or AD CS, signs certificates that prove who a user is. If a certificate template is misconfigured, a normal user can request a certificate that names them as an administrator, then log in as that administrator (T1649). SpecterOps mapped these template flaws in 2021 and warned that "nearly every environment with AD CS that we've examined for domain escalation misconfigurations has been vulnerable."6 The community has since catalogued escalation classes from ESC1 through ESC16 and beyond.7 Certificates are dangerous because they can outlive a password reset, so cleaning up after this attack means finding and cancelling the forged certificates, not just changing passwords.6

Stage 6. Domain dominance

With enough privilege, the attacker reaches for the crown. DCSync (T1003.006) lets them ask a domain controller to hand over password data for every account, as if they were another controller. From there they can forge a Golden Ticket (T1558.001) that grants access to anything, for as long as they like. At this point they own the domain and can deploy ransomware, delete backups, or simply sit and watch. The related move of logging in with stolen credentials rather than breaking anything is covered in our post on why attackers log in instead of breaking in.

From one login to Domain AdminKill chain · detect · fix
From one login to Domain Admin: six attack stages with what defenders can see and how to fix each A left-to-right flow of six stages. Stage 1 Foothold uses phishing T1566, detected by impossible-travel logins, fixed by phishing-resistant MFA. Stage 2 Enumeration uses domain account discovery T1087.002, detected by unusual directory queries, fixed by tiering and least privilege. Stage 3 Credential theft uses Kerberoasting T1558.003, detected by RC4 ticket requests, fixed by strong gMSA passwords and AES-only Kerberos. Stage 4 Privilege abuse uses account manipulation T1098, detected by group and ACL changes, fixed by ACL review and unconstrained delegation removal. Stage 5 Certificate abuse uses forged certificates T1649, detected by unusual certificate requests, fixed by hardening AD CS templates. Stage 6 Domain dominance uses DCSync T1003.006 and Golden Ticket T1558.001, detected by replication from non-DCs, fixed by KRBTGT rotation and Tier 0 isolation. ATTACK STAGE · MITRE ATT&CK IDWHAT DEFENDERS CAN SEEHOW TO FIX IT 01 Foothold Phishing, password spray T1566 Impossible-travel logins Phishing-resistant MFA 02 Enumerate Map users, groups, ACLs T1087.002 Bursts of directory queries Tiering, least privilege 03 Kerberos Kerberoasting T1558.003 RC4 ticket requests gMSA, AES-only Kerberos 04 Privilege ACL and delegation abuse T1098 Group and ACL changes ACL review, no unconstrained 05 Certs AD CS template abuse T1649 Unusual certificate requests Harden AD CS templates 06 Dominance DCSync, Golden Ticket T1003.006 T1558.001 Replication from a non-DC Rotate KRBTGT, isolate Tier 0 Each step a defender breaks here removes every path that depends on it. From one login to Domain Admin (phone layout) 01 · T1566 Foothold Phishing, password spray See: Impossible-travel logins Fix: Phishing-resistant MFA 02 · T1087.002 Enumerate Map users, groups, ACLs See: Bursts of directory queries Fix: Tiering, least privilege 03 · T1558.003 Kerberos Kerberoasting See: RC4 ticket requests Fix: gMSA, AES-only Kerberos 04 · T1098 Privilege ACL and delegation abuse See: Group and ACL changes Fix: ACL review, no unconstrained 05 · T1649 Certs AD CS template abuse See: Unusual certificate requests Fix: Harden AD CS templates 06 · T1003.006 · T1558.001 Dominance DCSync, Golden Ticket See: Replication from a non-DC Fix: Rotate KRBTGT, isolate Tier 0
Technique IDs from MITRE ATT&CK Enterprise v19. Detection and fix guidance drawn from the ASD, CISA and NSA joint AD guidance and Microsoft hardening docs.

A domain can have every server patched and still hand over Domain Admin in three steps, because the weakness is not a missing patch.

The most common AD misconfigurations

The most common Active Directory misconfigurations are weak service account passwords, accounts without Kerberos pre-authentication, over-permissive rights, unconstrained delegation, misconfigured certificate templates, and shared local admin passwords. Each maps to a known ATT&CK technique and each has a clear, well-documented fix.

These are the flaws testers find again and again. None is exotic. Most were created by someone trying to make a system work, not by an attacker. The table below pairs each issue with its ATT&CK technique, the risk it carries, and the fix.

Common AD misconfigurations, mapped to MITRE ATT&CK and their fixes
IssueATT&CK IDRiskFix
Service accounts with weak passwords and SPNsT1558.003Kerberoasting cracks the password offline; a privileged service account ends the gameUse gMSA with long, managed passwords; enforce AES
Accounts without Kerberos pre-authenticationT1558.004AS-REP Roasting leaks crackable data to any userRequire pre-authentication on all accounts
Over-permissive ACLs on objects and groupsT1098One account resets others or joins a powerful groupReview and remove excess rights; audit high-value objects
Unconstrained Kerberos delegationT1558A compromised host captures a domain controller's ticketRemove unconstrained delegation; use constrained or none
Vulnerable certificate templates (AD CS)T1649A normal user issues a certificate as an adminHarden templates; treat the CA as a Tier 0 asset
Reused local admin passwordsT1550.002Pass-the-hash spreads one hash across every machineDeploy Windows LAPS for unique per-host passwords
Stale privileged accountsT1078.002Forgotten admin accounts, weak and unmonitored, get reusedReview privileged group membership; disable dormant accounts
No admin tieringT1003.001Domain Admin logs in to a desktop; its credentials get stolenAdopt the tier model and privileged access workstations

Attack path simulator

This simulator shows how individual Active Directory weaknesses combine into a path to Domain Admin. Toggle the common misconfigurations on or off, and the diagram redraws to show the shortest route a phished user could take, the number of hops, the ATT&CK techniques involved, and a risk level. Turn everything off and there is no path from this set.

Interactive · conceptual

Which weaknesses build the path?

Start point is a single phished user. Switch weaknesses on to see the shortest route a real attacker could take to Domain Admin.

Weaknesses present in the domain
RISK
Shortest path to Domain Admin
2 hops

The shortest route is loading.

Indicative only. A real assessment weighs exploitability, patch level, and monitoring. This model uses the cited techniques to show how weaknesses chain, not to score any specific network.

Map the real paths in your domain

What does an AD pentest cover?

An Active Directory penetration test covers account and password hygiene, Kerberos weaknesses, permission and ACL abuse, delegation, certificate services, domain and forest trusts, privileged group membership, and the tiering of admin access. The output is a ranked set of attack paths and the specific choke points that break the most of them.

A thorough Active Directory security assessment usually works through this scope:

  • Accounts and passwords: weak, shared, stale, and never-expiring passwords; password spraying resistance; service account hygiene.
  • Kerberos weaknesses: Kerberoasting and AS-REP Roasting exposure; RC4 use; ticket lifetimes.
  • Permissions and ACLs: who can reset whose password, edit group membership, or write to high-value objects.
  • Delegation: unconstrained, constrained, and resource-based delegation set on the wrong accounts.
  • Certificate services: AD CS template flaws (the ESC classes) and CA permissions.
  • Trusts: domain and forest trusts that let one compromise cross into another.
  • Privileged access: the size and hygiene of Domain Admins and other Tier 0 groups, and whether tiering is enforced.
i

An AD test is usually assumed-breach: the tester begins with one low-level account, because that is the realistic starting point after a phish. It complements, rather than replaces, external testing. For the difference between finding flaws and proving they chain, read vulnerability assessment versus penetration testing.

How often should you test Active Directory?

Test Active Directory at least once a year and after any major change, such as a migration, merger, or new trust relationship. Because AD drifts every day as accounts and permissions change, most mature teams add continuous attack-path monitoring between full tests. In Cobalt's 2025 survey, quarterly was the most common cadence.

Active Directory is not a fixed thing you test once and forget. Every new hire, every leaver, every "temporary" permission, and every merged company changes the graph. A path that did not exist in January can appear in March because someone added an account to a group. In Cobalt's 2025 State of Pentesting survey, quarterly was the most common pentest cadence at 30 percent, with 27 percent testing annually.8

An annual test is a photo of a moving target. It is necessary, often required by regulators, but it leaves the domain unwatched for most of the year. That gap is the subject of our post on the 363-day blind spot, and it is why continuous testing and exposure management matter. For the discipline that keeps this going all year, see our explainer on continuous threat exposure management.

i

Regulated Indian entities have set rules too. This is general information, not legal advice, so check the latest text of any regulation that applies to you before acting.

How to read an attack path graph

An attack path graph shows accounts and computers as dots, called nodes, and the permissions or relationships between them as arrows, called edges. To read it, start at a low-privilege node and follow the arrows toward Domain Admin. The shortest chain of arrows is the path an attacker will take, and the busiest node is your best choke point.

Tools such as BloodHound draw this graph automatically. Once you see it, three habits make it useful:

  1. Start from the bottom, not the top. Pick a normal user or a compromised workstation and trace forward. That is the attacker's view, and it shows which everyday accounts are dangerously close to full control.
  2. Look for choke points. Some nodes appear on many paths. Fixing one of these, for example removing a bad delegation or trimming a group, can break dozens of routes at once. This is where you get the most safety for the least effort.
  3. Rank by ease, not just count. A three-hop path that needs only a weak password crack is worse than a six-hop path that needs a rare condition. Good reporting sorts paths by how easily they can be walked, so you fix the cheap wins for the attacker first.

Active Directory hardening checklist

This Active Directory hardening checklist lists the highest-value controls, from admin tiering and LAPS to AES-only Kerberos, Protected Users, AD CS template review, and KRBTGT rotation. Work top down: the earlier items break the most attack paths, and several are free changes already built into modern Windows.

  • Adopt the tier model. Keep Tier 0 identity systems separate from workstations, so Domain Admin credentials never touch an ordinary desktop.11
  • Use privileged access workstations. Admins should manage Tier 0 only from hardened, dedicated machines.11
  • Deploy Windows LAPS. It sets a unique local admin password per machine and is native to Windows since the April 2023 update, giving protection against pass-the-hash and lateral movement.9
  • Move service accounts to gMSA. Group managed service accounts let Windows manage long, random passwords, which defeats Kerberoasting.10
  • Enforce AES-only Kerberos and retire RC4. Microsoft is deprecating RC4 for Kerberos; a January 2026 update adds audit events, and from April 2026 the default becomes AES, with the rollback removed from July 2026.12
  • Add privileged users to Protected Users. The group blocks NTLM, blocks DES and RC4 in Kerberos pre-authentication, blocks delegation, and caps ticket lifetime at four hours.13
  • Require Kerberos pre-authentication on every account. This removes AS-REP Roasting exposure.
  • Review certificate templates and CA permissions. Close the ESC template flaws and treat certificate authorities as Tier 0.6
  • Remove unconstrained delegation. Replace it with constrained delegation or none, and protect accounts that must not be delegated.
  • Audit ACLs on high-value objects. Find and remove rights that let ordinary accounts reset passwords or edit powerful groups.
  • Trim privileged groups. Keep Domain Admins tiny, review membership often, and disable dormant admin accounts.
  • Rotate the KRBTGT password. Reset it twice, waiting at least the maximum ticket lifetime between resets, especially after any suspected compromise.15
  • Enforce phishing-resistant MFA. Microsoft reports MFA blocks over 99 percent of identity attacks.2
  • Retire out-of-support domain controllers. Unsupported servers are over-represented in compromises.3
  • Monitor the tell-tale events. Watch for replication from non-controllers, RC4 ticket requests, and sudden group or ACL changes.
  • Retest after every change. Confirm each fix actually broke the path, and check that no new path opened.

Frequently asked questions

What is the difference between an Active Directory pentest and a normal network pentest?

A network pentest looks for open ports and vulnerable services. An Active Directory pentest looks for identity attack paths: chains of misconfigured permissions, weak service accounts, and trust that let a low-level user reach Domain Admin. The goal is to find the shortest route to full control, not just a list of flaws.

What is kerberoasting in simple terms?

Kerberoasting is a trick that abuses how Kerberos issues service tickets. Any domain user can ask for a ticket tied to a service account, then try to crack that account's password offline, away from your logs and lockout limits. If the service account has a weak password and high privilege, one crack can hand over the domain. MITRE tracks it as T1558.003.

Does an Active Directory pentest damage my domain?

A well-run test is safe. Testers agree the scope and rules first, avoid actions that disrupt production, and never leave forged tickets or backdoors behind. The risky steps, such as password cracking, happen offline on the tester's own machine. Ask your provider for their safety controls and a clean-up plan before work starts.

How is AD CS abused to become Domain Admin?

Active Directory Certificate Services signs certificates that prove who a user is. If a certificate template is misconfigured, a normal user can request a certificate that names them as an administrator, then log in as that administrator. SpecterOps named these template flaws ESC1 through the current ESC16 and later. MITRE tracks the technique as T1649.

How often should we run an Active Directory penetration test?

Test Active Directory at least once a year and after any major change, such as a migration, merger, or new trust. Because AD drifts every day as accounts and permissions change, many teams add continuous attack-path checks between full tests. In Cobalt's 2025 survey, quarterly was the most common cadence at 30 percent.

What is the single most valuable Active Directory hardening step?

Tiering, also called the tier model, is the highest-value change. It stops Domain Admin credentials from ever logging in to ordinary desktops, so a phished user cannot capture them. Microsoft's tier model separates Tier 0 identity systems from workstations. Without it, most other fixes only slow the attacker down rather than stop them.

Why is Active Directory such a common target in ransomware?

Active Directory controls who can access almost everything, so taking it over lets an attacker push ransomware to every machine at once. Australian and US agencies call it the most widely used enterprise identity system, with permissive defaults and a large attack surface. Sophos found attackers now reach the AD server in a median of 3.4 hours.

Where Arxiis fits

Active Directory is one of the six vectors Arxiis tests

Most teams learn their AD attack paths once a year, from a report that is already out of date by the time they read it. The domain keeps changing. The paths keep forming. Arxiis was built to close that gap.

Arxiis is an autonomous AI red teaming platform with a multi-agent crew that handles OSINT, exploitation, lateral movement, and reporting. Active Directory is one of its six attack vectors, alongside ransomware, cloud, web applications, containers, and credentials. Findings come CVSS-scored and mapped to MITRE ATT&CK, with compliance overlays for frameworks including RBI, SEBI CSCRF, ISO 27001, and SOC 2.

  • Attack-path mapping that shows the shortest route from a foothold to Domain Admin, not just a list of flaws.
  • Repeatable testing so you can confirm a fix broke the path and no new path opened.
  • On-premise deployment, so your directory data never leaves your environment, on an MIT-licensed open-source core.

Sources

  1. ASD ACSC, CISA, NSA and partners, "Detecting and Mitigating Active Directory Compromises", 25 September 2024. cyber.gov.au
  2. Microsoft, "Microsoft Digital Defense Report 2025", 16 October 2025. blogs.microsoft.com
  3. Sophos, "Nowhere, man: The 2026 Active Adversary Report", February 2026. sophos.com
  4. CrowdStrike, "2026 CrowdStrike Global Threat Report", 24 February 2026. crowdstrike.com
  5. Mandiant (Google Cloud), "M-Trends 2026", 23 March 2026. cloud.google.com
  6. SpecterOps, Schroeder and Christensen, "Certified Pre-Owned: Abusing Active Directory Certificate Services", 17 June 2021. specterops.io
  7. Certipy project wiki, "Privilege Escalation (ESC1 to ESC16 and beyond)", accessed October 2026. github.com/ly4k/Certipy
  8. Cobalt, "State of Pentesting Report 2025", 14 April 2025. cobalt.io
  9. Microsoft Learn, "Windows LAPS overview", accessed October 2026. learn.microsoft.com
  10. Microsoft Learn, "Group Managed Service Accounts overview", accessed October 2026. learn.microsoft.com
  11. Microsoft Learn, "AD DS tier model for privileged access security", accessed October 2026. learn.microsoft.com
  12. Microsoft Support, "Manage Kerberos KDC usage of RC4 (CVE-2026-20833)", accessed October 2026. support.microsoft.com
  13. Microsoft Learn, "Protected Users Security Group", accessed October 2026. learn.microsoft.com
  14. MITRE ATT&CK, "Enterprise Matrix (v19)", accessed October 2026. attack.mitre.org
  15. Microsoft Learn, "AD Forest Recovery: Reset the krbtgt password", 21 May 2025. learn.microsoft.com
A
Arxiis Research

Written by the Arxiis research team. Facts checked against primary sources on 19 October 2026. Not legal advice.