Offensive engagement / 07

Identity Exposure Review.

Which paths lead from an ordinary account to control of the directory, and which of your credentials are already exposed.

Active Directory and Entra ID are assessed as one attack surface, together with the trust between them. Attack paths are mapped from a standard user to the Tier 0 assets, and the most significant are validated by controlled exploitation where agreed, so every path in the report comes with the configuration that opens it and its root cause.

The principal consultant also researches leaked and exposed credentials belonging to the organization, on the open web and the dark web, and reads each exposed account against the paths it would open. Findings are mapped to MITRE ATT&CK, so each one becomes a hardening change for the directory team and a detection priority for the SOC.

AD + Entra ID Assessed as one attack surface, with the trust between them
1 to 5 weeks Directory assessment, from one domain to a multi-forest estate
ATT&CK Findings mapped to techniques the SOC can detect
Read and validate Directory objects are not changed; exploitation only where agreed
[ PATHS, EXPOSURE, DETECTION ]

Three answers from one review.

The directory assessment and the credential research run under one scope and report together, so an exposed account is read against the paths it would open.

A

Attack paths

Routes from an ordinary user to Tier 0 are mapped across Active Directory and Entra ID, through tiering, delegation, certificate services and trusts.

What it changes
A prioritized view of how an attacker escalates.
B

Exposed credentials

Research into leaked and exposed credentials finds which of the organization's accounts are already out there, so each can be reset and protected.

What it changes
Priorities set by real exposure.
C

Detection priorities

Findings are mapped to MITRE ATT&CK, giving the SOC the identity attacks it should be detecting and the directory team the changes that close the paths.

What it changes
One review feeds hardening and detection.

Coverage

The directory, the tenant and the trust between them.

Configuration review and attack-path analysis cover the parts of identity that adversaries abuse to reach domain and tenant control.

Tiering and privileged access How administrative accounts and tiers are separated, and the paths that cross those boundaries.
Kerberos delegation Delegation configured on accounts and services, and what a compromised one could reach.
Certificate services Certificate templates and permissions in Active Directory Certificate Services (ADCS) that could give an ordinary account privileged access.
Credential hygiene Account and credential practices that widen what one compromised account can reach.
Legacy protocols Older authentication protocols still enabled, and the attacks they allow.
Groups and trusts Nested group membership and trust relationships, between forests and between Active Directory and Entra ID.

Exposed credentials

Which credentials of yours are already out there.

The principal consultant researches leaked and exposed credentials belonging to the organization's domains, on the open web and the dark web.

What is searched Credentials tied to the domains named in the written scope.
Who does it The principal consultant who leads the directory assessment.
How it is read Each exposed account is set against the attack paths mapped in the directory, so a privileged or well-connected account is reported for what it would open.
What follows Exposed accounts are reported so they can be reset and protected.

How a review runs

Five steps, from scope to debrief.

The review starts from read-only directory access or a standard-user foothold, and nothing in the directory is changed.

STEP 01

Preparation and access

Scope and rules of engagement are agreed, together with the starting access: read-only directory access, or a standard-user foothold.

STEP 02

Collection and research

Directory data is collected, and users, groups, privileges, trusts and certificate templates are enumerated across the domains and tenants in scope. The credential research for those domains is carried out in the same phase.

STEP 03

Analysis

Privilege relationships, tiering, delegation, certificate templates, credential exposure and legacy protocols are analyzed, and the viable paths to high-value assets are mapped.

STEP 04

Validation

The most significant paths are validated by controlled exploitation, within agreed limits, to confirm that the impact is real.

STEP 05

Report and debrief

Attack paths, root causes and prioritized remediation are documented and walked through with the directory and identity teams.

Deliverables

Paths, exposures and the changes that close them.

Every finding carries its evidence, its severity and its root cause.

Assessment report Findings with evidence, severity, attack-path narratives and root-cause analysis, with an executive summary of identity risk and the most critical exposures.
Attack-path diagrams Visual representations of the privilege-escalation routes identified.
Exposed-credential findings The exposed accounts found by the research, read against the mapped paths.
Prioritized hardening roadmap Sequenced recommendations across tiering, credentials, delegation, certificate services, protocols and trusts.
Detection recommendations ATT&CK-mapped guidance on the identity attacks the SOC should detect.

Boundaries and duration

Scope, limits and duration.

Boundaries are set in writing before anything starts.

Assessed Only the Active Directory domains, Entra ID tenants and supporting identity services approved in writing.
Left untouched Directory objects are not changed, and denial of service is excluded. Exploitation happens only where controlled exploitation is agreed.
Duration For the directory assessment: 1 to 2 weeks for a single domain with a modest user base, 2 to 3 weeks for multiple domains or a hybrid Active Directory and Entra ID estate, and 4 to 5 weeks for large multi-forest environments with extensive trusts and certificate services.

Who this is for

When to commission it.

Before an attacker finds the paths Organizations that want the routes to domain and tenant control found and closed first.
A hybrid estate Estates where Active Directory and Entra ID are connected and the connection has not been assessed as one surface.
Detection priorities for the SOC Teams that need to know which identity attacks to detect, mapped to MITRE ATT&CK.

What is needed to scope it

Five answers are enough to scope it.

Directory The number of Active Directory domains and forests, and the approximate user and computer count.
Entra ID Whether Entra ID and hybrid identity are in scope.
Certificate services Whether Active Directory Certificate Services is deployed and in scope.
Starting position Read-only directory access, or a standard-user foothold for attack-path validation.
Domains The domains whose credentials are researched.

Scoping starts with a conversation. If an identity review is the wrong instrument for the question, that is said plainly at the first call.

NEXT / RELATED SERVICE

Compromise Assessment

When the question is whether an intruder has already used these paths.

NEXT / SCOPING

Engage

Describe the situation. The first call is with the consultant who would do the work.