Identity and Active Directory security
Analyse accounts, delegations and sensitive groups, then build a prioritised remediation path.
Identity security
Understand how one identity, one delegation or one misconfiguration can lead all the way to your most sensitive resources.
A list of vulnerabilities does not tell you what is actually reachable. An attack path does: it links an ordinary identity to a critical asset, and it is fixed by order of effect.
Each offer keeps its own role. Here is exactly what it brings to this situation.
Analyse accounts, delegations and sensitive groups, then build a prioritised remediation path.
Remove the standing privileges that feed the shortest attack paths.
Place decoys along the identified paths to detect progression as early as possible.
Confront the analysis with real exploitation and verify what is genuinely reachable.
Monitor sensitive changes and hold the level reached after remediation.
An Active Directory attack path rarely relies on a single misconfiguration. An attacker combines identities, rights, protocols, service accounts and trust relationships to move towards a more sensitive resource. Knowing the techniques involved helps identify the paths that are genuinely exploitable, and above all where to break them.
Service accounts
Request a service ticket for an account carrying an SPN, then attempt to crack the protecting password offline.
Kerberos configuration
Abuse accounts exempted from Kerberos pre-authentication to obtain material that can be attacked offline.
Tier 0 / critical · MITRE T1003.006
Abuse Active Directory replication rights to access domain secrets without directly extracting NTDS.dit.
Legacy protocols
Relay a legacy authentication to another service in order to act with the rights of an identity you do not control.
Lateral movement
Reuse a password hash collected on a workstation to authenticate elsewhere, without ever knowing the password.
Lateral movement
Reuse a valid Kerberos ticket to extend access or move towards a more sensitive resource.
Delegations
Divert a poorly scoped delegation to impersonate another user, sometimes up to an administrative identity.
Active Directory PKI
A misconfigured certificate template can let a low-privileged identity request a certificate usable to authenticate as another identity. ESC1 shows why an AD CS PKI can create a path towards Tier 0 without directly compromising a domain controller.
Kerberoasting, DCSync or Pass-the-Hash are not, on their own, a complete attack. They are steps an attacker chains together when the environment allows it.
The risk comes from the chain, not from the isolated technique.
Remediation is not about adding another tool. It is about removing the conditions that make the chain possible, starting with the fixes that eliminate the largest number of paths.
Map critical assets, privileged identities, delegations and the main paths leading to them.
To keep reading on situations that touch the same surface: technical identities, standing privileges, APIs and application access.
Access and privileges
Replace permanent administrative rights with proportionate, temporary and traceable access.
Access and privileges
Take back control of legacy technical identities: their owners, their secrets and their privileges.
Identity security
Stop a legitimate or compromised identity from reaching too much data, for too long, without anyone noticing.
A short format, already online, to get an objective view of your situation before committing to a project.
Gives a maturity score and prioritised risks to start the first remediations.
Real engagements whose approach sheds light on this situation.
Sector : Non-profit
A non-profit organization wanted to rationalize a heterogeneous IAM landscape, simplify operations and build a coherent identity foundation.
Illustrates a comparable approach to putting a Microsoft identity foundation back in order.
Read the case study : Rationalizing an IAM landscape around Microsoft
Our published content that speaks directly to this situation.
Replay
A useful replay on moving from a one-off assessment to change monitoring.
Field note
Shows how delegations and inherited privileges build attack paths.
Field note
A 90-day method to see, reduce and prove, in the NIS2 context.
The notions worth sharing with your teams on this topic.
Tell us about your context. Together we identify the priority capabilities and the first useful step.