Attack paths
Routes from an ordinary user to Tier 0 are mapped across Active Directory and Entra ID, through tiering, delegation, certificate services and trusts.
Offensive engagement / 07
Which paths lead from an ordinary account to control of the directory, and which of your credentials are already exposed.
Active Directory and Entra ID are assessed as one attack surface, together with the trust between them. Attack paths are mapped from a standard user to the Tier 0 assets, and the most significant are validated by controlled exploitation where agreed, so every path in the report comes with the configuration that opens it and its root cause.
The principal consultant also researches leaked and exposed credentials belonging to the organization, on the open web and the dark web, and reads each exposed account against the paths it would open. Findings are mapped to MITRE ATT&CK, so each one becomes a hardening change for the directory team and a detection priority for the SOC.
The directory assessment and the credential research run under one scope and report together, so an exposed account is read against the paths it would open.
Routes from an ordinary user to Tier 0 are mapped across Active Directory and Entra ID, through tiering, delegation, certificate services and trusts.
Research into leaked and exposed credentials finds which of the organization's accounts are already out there, so each can be reset and protected.
Findings are mapped to MITRE ATT&CK, giving the SOC the identity attacks it should be detecting and the directory team the changes that close the paths.
Coverage
Configuration review and attack-path analysis cover the parts of identity that adversaries abuse to reach domain and tenant control.
Exposed credentials
The principal consultant researches leaked and exposed credentials belonging to the organization's domains, on the open web and the dark web.
How a review runs
The review starts from read-only directory access or a standard-user foothold, and nothing in the directory is changed.
Scope and rules of engagement are agreed, together with the starting access: read-only directory access, or a standard-user foothold.
Directory data is collected, and users, groups, privileges, trusts and certificate templates are enumerated across the domains and tenants in scope. The credential research for those domains is carried out in the same phase.
Privilege relationships, tiering, delegation, certificate templates, credential exposure and legacy protocols are analyzed, and the viable paths to high-value assets are mapped.
The most significant paths are validated by controlled exploitation, within agreed limits, to confirm that the impact is real.
Attack paths, root causes and prioritized remediation are documented and walked through with the directory and identity teams.
Deliverables
Every finding carries its evidence, its severity and its root cause.
Boundaries and duration
Boundaries are set in writing before anything starts.
Who this is for
What is needed to scope it
Scoping starts with a conversation. If an identity review is the wrong instrument for the question, that is said plainly at the first call.
NEXT / RELATED SERVICE
Compromise AssessmentWhen the question is whether an intruder has already used these paths.
NEXT / SCOPING
EngageDescribe the situation. The first call is with the consultant who would do the work.