NODUM
ESEN

Internal test / Active Directory

We start from a machine inside the network, with the credentials of any ordinary employee, and measure how far that gets.

What it includes

  • Escalation paths in Active Directory, from the workstation to control of the domain.
  • Misconfigured delegation, inherited ACLs, passwords in object descriptions and in GPOs.
  • Lateral movement between machines and extraction of credentials from memory.
  • Real segmentation: what a compromised workstation actually reaches, against what the diagram says.