Identity & access penetration testing — with Ballpoint
Prove the risk.
Fix what matters.
Ballpoint puts your access paths to the test the way a real attacker would.
Ariovis turns the findings into concrete remediation across Active Directory, IAM, PAM, Access Management and authorization.
- Penetration testing carried out by Ballpoint.
- Identity scoping, remediation and support delivered with Ariovis.
Ariovis × Ballpoint
Ballpoint is a French offensive security company and the publisher of Trapster. Ballpoint performs the penetration tests.
Ariovis owns the identity side: scoping, reading the findings through the lens of IAM and Active Directory, remediation, integration and day-two operations.
An attack path is only useful if it leads to an action plan.
A penetration test shows what an attacker can actually reach. But identifying an exploitation chain is not enough: you still need to understand why it exists, decide what to fix first, and embed the fixes into identity processes.
Ballpoint provides the offensive proof. Ariovis turns that proof into a remediation path you can actually execute.
Test
Ballpoint reproduces attacker techniques and identifies the paths that are genuinely exploitable.
Understand
Findings are tied back to identities, entitlements, applications, ownership and business impact.
Remediate
Ariovis designs and implements the fixes in AD, IAM, PAM, Access Management, entitlement models or operational processes.
A four-handed approach
Five steps, two clearly separated responsibilities, one goal: durably reduce the identity attack surface.
- 1
Scope
Ariovis and Ballpoint define the ground rules together.
- Perimeter
- Sensitive identities and populations
- Critical business assets
- Meaningful attack scenarios
- Rules of engagement
- Production constraints
- Expected outcomes
- 2
Attack
Ballpoint runs the test within the agreed frame.
- Reconnaissance
- Analysis
- Controlled exploitation
- Vulnerability chaining
- Privilege escalation and lateral movement paths
- Evidence collection
- No destructive action without explicit agreement
- 3
Prioritise
Vulnerabilities are not ranked by technical score alone.
- Exposed data
- Privileges obtained
- Business processes involved
- Propagation capability
- Ease of remediation
- Actual risk to the organisation
- 4
Remediate
Ariovis turns findings into concrete measures.
- Cleaning up groups and delegations
- Fixing excessive entitlements
- Taking back control of service accounts
- Active Directory hardening
- Joiner, Mover, Leaver process improvements
- Better RBAC or ABAC models
- Fixing authentication journeys
- Token and session handling
- PAM deployment or evolution
- Access Management evolution
- Externalising or fixing authorization policies
- Automated revocations
- Monitoring, documentation and prioritised backlog
- Change management
- 5
Re-test
Ballpoint can run a counter-audit.
- Verification of the fixes applied
- Confirmation that the identified attack paths are neutralised
The counter-audit and its certificate are Ballpoint deliverables: they are neither a regulatory certification nor an official accreditation.
Typical perimeters
The offer deliberately focuses on the ground where identity expertise plus offensive testing makes the difference. Other Ballpoint perimeters (external, application, web, API, mobile, cloud, internal, black, grey or white box) can be added when the context calls for it.
Active Directory and internal network
- Over-privileged accounts
- Sensitive groups
- Delegations
- Service accounts
- Paths to Domain Admin
- GPO, LDAP, DNS and identity services
- Lateral movement
Authentication, SSO and CIAM
- Access journey bypass
- Account recovery
- MFA
- Federation
- Sessions
- Tokens
- Tenant or population separation
- Partner and customer journeys
Authorization and APIs
- Horizontal or vertical escalation
- Inconsistent access controls
- Displayed role differing from effective entitlement
- Objects reachable without legitimate authorization
- Policies duplicated in code
- APIs and microservices
Privileged accounts and access
- Standing privileges
- Exposed secrets
- Shared administrative accounts
- Technical accounts
- Access outside the PAM
- Bypass paths
- Consistency between PAM, IAM and Active Directory
Cloud identity
- Microsoft Entra ID
- SaaS applications
- Hybrid identities
- Cloud administration accounts
- Consents
- Roles
- Federation
- Conditional access
Who does what?
Ballpoint
Offensive security
- Offensive scoping
- Reconnaissance and intrusion testing
- Controlled exploitation
- Attack chain analysis
- Technical report
- Decision-level summary
- Debrief
- Counter-audit
Ariovis
Identity, integration and remediation
- IAM and business context
- Architecture
- Identity governance
- Active Directory remediation
- Entitlement models
- Access Management and CIAM
- PAM
- Fine-grained authorization
- Integration
- Automation
- Skills transfer
- Operations and continuous improvement
Ballpoint shows how an attack progresses.
Ariovis makes sure it can no longer progress the same way.
One-off or continuous testing
The cadence depends on your context. Scope and terms are quoted case by case by Ballpoint, after scoping with Ariovis.
One-off penetration test
For a specific moment in the lifecycle.
- — A go-live
- — A major change
- — A customer or insurer audit
- — An acquisition
- — A migration
- — A targeted check on AD or an application
Continuous testing / PTaaS
For perimeters that keep moving.
- — Frequently changing applications
- — Product teams in continuous delivery
- — Regular replay of vulnerabilities
- — Prioritising new features
- — Re-tests
- — Long-term follow-up
- — Watch on vulnerabilities affecting your stack
Our offensive partner
- Ballpoint, a French offensive security company
- ISO 27001 certified by BSI Group
- Listed professional on cybermalveillance.gouv.fr
- Publisher of Trapster, a Deceptive Security solution
Frequently asked questions
Who performs the penetration test?
The penetration test and all offensive security operations are performed by Ballpoint. Ariovis handles identity-related scoping, impact analysis, remediation design and implementation.
Why go through Ariovis instead of contacting Ballpoint directly?
Because the offer does not stop at identifying vulnerabilities. Ariovis connects the findings to how IAM, Active Directory, PAM and applications actually work, then supports the fixes until they are durably embedded.
Can you fix the vulnerabilities that are found?
Ariovis can take on fixes within its areas of expertise: identity security, Active Directory, governance, authentication, authorization, privileges, integration and operations. Other fixes are scoped with the customer and the relevant teams.
Can the fixes be verified?
Yes. A counter-audit by Ballpoint can verify that the identified vulnerabilities and exploitation paths have been properly addressed.
Do you offer continuous testing?
Depending on the perimeter and the pace of change, a continuous approach can combine recurring scans, human testing, vulnerability tracking and re-tests.
Don’t choose between the finding and the fix.
Have Ballpoint test your access paths, then turn the results into concrete remediation with Ariovis.