✓ OSCP · OSWE · OSEP certified | Joost performs every test himself — no juniors | Response within 1 business day | Based in Haarlem

Active Directory Pentest: How Vulnerable Is Your Internal Network Really?

Many organisations spend the bulk of their security budget on the outside: the website, the firewall, the external attack surface. Understandable, since that’s what’s visible from the internet. But in the vast majority of real-world incidents, that first step is only the beginning: once an attacker has one workstation or account inside, it becomes a question of what’s possible internally. For most Dutch organisations, that’s Active Directory (AD), and its state often determines how much damage a single compromised laptop can ultimately cause.

Why Active Directory is such an attractive target

Active Directory manages users, groups, permissions and trust between systems in almost every medium to large Windows environment. That makes it simultaneously the most valuable target within a network: whoever gains control of AD effectively controls nearly the entire internal landscape. Years of historical configuration, legacy protocols kept alive for compatibility reasons, and permissions that have never been cleaned up mean that almost every AD environment we test contains a path from “regular user” to “domain admin”.

What an internal Active Directory pentest investigates

  • Kerberoasting and AS-REP roasting: intercepting and offline-cracking service account passwords via weaknesses in the Kerberos protocol.
  • Unnecessary or outdated trust relationships: trusts and delegations that grant far more access than needed.
  • Misconfigured permissions (ACLs): users or groups that, often unintentionally, have modification rights on sensitive objects such as domain admin groups.
  • Lateral movement paths: how easy is it to move from one compromised workstation to other systems, for example via reused local administrator passwords?
  • Legacy protocols: is NTLM still allowed everywhere Kerberos could be used, and is LLMNR/NBT-NS still enabled, a classic entry point for credential interception?

The difference from an external pentest

An external pentest answers the question: can someone get in from outside? An internal Active Directory pentest answers the question that comes next, and is at least as important: once someone is inside, how far can they get, and how fast? Only both tests together give a complete picture of the risk, because a perfectly secured exterior with a vulnerable internal network is still an open house the moment a single phishing email succeeds.

How realistic is this scenario?

Not hypothetical. One successful phishing email, one stolen laptop, or one supplier with overly broad access is often enough to get a foot in the door. What happens after that depends entirely on how the internal network is set up. Organisations that have this tested are regularly surprised how short the path from “regular workstation” to full control over the domain turns out to be in practice.

A real-world example

In an internal test, our testers often start with nothing more than an ordinary, low-privileged user account — exactly what an average employee would have. In a recent engagement, it turned out within a few hours that a service account, used by an application phased out years ago, was still active with a weak, never-changed password and unnecessarily broad rights within an admin group. Via Kerberoasting, that password could be cracked offline, and from there the path to domain admin was wide open. Nobody in the organisation still knew this account existed, let alone that it held that much privilege. This is the pattern we see most often: not one big mistake, but a stack of small, forgotten decisions that together form a direct route to full control.

How MonkeysICT approaches an Active Directory pentest

We simulate the scenario of an attacker who already has an initial foothold, for example via a low-privileged test account, and map out which paths to higher privileges are open. The report doesn’t just give a list of vulnerabilities — it concretely shows which combination of small misconfigurations leads to full domain takeover, so you know which one to fix first.

Scroll to Top