Active Directory Pentest

Active Directory

Penetration Testing

Comprehensive security assessment of SS7, Diameter, GTP, and 5G infrastructure following GSMA guidelines.

Domain
Enumeration
Privilege
Escalation
Lateral
movement
What We Test

Domain Controllers

User Accounts

Group Policies (GPOs)

Kerberos Authentication

LDAP Services

Privilege Levels

Trust Relationships

Password Policies

Testing Methodology

01

Enumeration

Collecting AD information like users, groups, and domains.

Tools
BloodHound, PowerView, enum4linux

02

Credential Attacks

Testing password strength and reuse (spraying, brute force).

Tools
Hydra, Kerbrute, CrackMapExec

03

Privilege Escalation

Identifying and exploiting misconfigurations to gain higher access.

Tools
BloodHound, SharpHound, Mimikatz

04

Lateral Movement

Moving between systems inside the domain after initial access.

Tools
PsExec, WinRM, Evil-WinRM, CrackMapExec

05

Reporting

Documenting findings, attack paths, and remediation steps.

Tools
Dradis, Serpico, Jira, Markdown/Excel