Your situation

Breach and attack simulation: testing Active Directory and Entra ID

You want to know how far an attacker could get with a compromised workstation or a normal user account? Our breach and attack simulation combines configuration analysis with practical attack tests – in Active Directory and in hybrid identity environments with Microsoft Entra ID.

Free of charge and without obligation.

  • TeleTrusT co-authorship · AD and Entra ID
  • BSI-certified for IS penetration testing
  • CRTO and OSCP qualifications on the team
Several hands working with compass and dividers between sticky notes on a map
Active Directory in our sights: identifying attack paths and closing them in a targeted way.

Your situation

You want to know how far an attacker gets into your Active Directory after a single wrong click?

In many Windows environments, an opened e-mail attachment or a wrong download is enough for criminals to gain initial access. From there, they penetrate deep into the corporate network and establish a permanent foothold – this is known as an advanced persistent threat (APT). The aim is extortion: by encrypting your data or by threatening to publish sensitive data.

Active Directory is at the centre of this. It manages and authenticates user accounts, computers, resources and applications. In many organisations, it is connected to Microsoft Entra ID (formerly Azure AD) to form a hybrid identity environment. Two questions usually remain open: does the protection of your workstations withstand an initial attack? And which accounts, systems and data can an attacker who is already in the network reach?

Our breach and attack simulation (BAS) answers precisely these questions with two modules: “Pre-Assumed Breach” before the intrusion and “Assumed Breach” after an assumed intrusion – for pure Active Directory environments as well as for hybrid identities. To do this, we combine configuration review and penetration testing – as an IT security service provider certified by the BSI for penetration testing.

Services & results

Breach and attack simulation in two modules: before and after the intrusion

You find out whether the protection of your workstations withstands an initial attack and which accounts, systems and data an attacker can reach in your Active Directory and your hybrid environment with Microsoft Entra ID. The basis is configuration analysis and practical attack tests; for this, you usually provide a client device and a standard user account, on site or via our pentest box.

A breach and attack simulation simulates a predefined attack on your Windows environment. It consists of two modules, “Pre-Assumed Breach” and “Assumed Breach”, each with a fixed number of person-days. Whether you commission one module or both is something we clarify in the initial consultation.

Providing access: client, user account, pentest box

For both modules, you usually provide a client device that is already part of your Active Directory, as well as a user with standard permissions. This keeps the effort on your side low.

Testing takes place on site or – much more efficiently – via our pentest box. It has only two connections: power and network. You configure network access to the test networks; the connection to us runs over a secure VPN channel, either via your internet connection or a built-in LTE card.

Authorisation and project plan

The authorisation form records the test period, target systems and contacts on both sides; the project plan records all project steps.

“Pre-Assumed Breach” module: does the client withstand an initial attack?

This module answers the question of whether an attacker could execute malware at all and thus gain access to your network. We test the protection mechanisms of the clients in use for ways to bypass them:

  • Application whitelisting
  • Antivirus solutions (AV)
  • Local misconfigurations that allow permissions to be extended
  • Local misconfigurations that allow sensitive data on the device to be read

“Assumed Breach” module: configuration analysis of Active Directory and Entra ID

Before the practical assumed breach test, we use tools to analyse the settings and configuration of your AD environment for vulnerabilities – for hybrid identities, Microsoft Entra ID as well. We include vulnerabilities already known in the environment in order to search for points of attack in a targeted way.

We then verify the tool results manually. Only then does an indication become a proven, exploitable attack path.

“Assumed Breach” module: spreading through the network (lateral movement)

Now an attacker is assumed to be in Active Directory already – for example a disgruntled employee, an intern or an external attacker. Building on the configuration analysis, we test in practice how far they get:

  • Verifying exploitable misconfigurations in the AD environment
  • Carrying out lateral movement attacks and compromising further user accounts
  • Identifying attack paths through which users can gain further access or escalate their permissions without authorisation
  • For hybrid identities: attack paths between Active Directory and Microsoft Entra ID
  • Security analysis of network shares for incorrectly set permissions
  • Optional: cracking password hashes by brute force or rule-based wordlist attacks

Report and final meeting

We document the results of the commissioned modules in a report. We rate vulnerabilities according to CVSS or your in-house standard. We report serious findings immediately to your contact, not only in the report.

In the final meeting, we discuss results and countermeasures with your team.

Your test report

Management summary and traceable findings on client protection, AD configuration, hybrid identities, attack paths and shares, with specific measures.

Our expertise

Active Directory testing is part of our penetration testing portfolio, which we have been offering since 2000. secuvera is a BSI-certified IT security service provider for penetration testing: in annual audits, the BSI examines our information security management system and our quality management manual, and our penetration testers have been technically examined.

We supplement tools with manual testing. The tool-based configuration analysis provides indications, which we verify in practice in the assumed breach test. We disclose our methodology and the tools used to you.

Our penetration testers are also familiar with standards such as ISO/IEC 27001 and IT-Grundschutz. This means that technical findings in Active Directory also allow conclusions to be drawn about weaknesses in your permission and operational processes.

Getting started

Agreeing on access, test objectives and authorisations

Define the test scope and contacts

Together we choose the scenario and the networks to be tested. Involve the people responsible for Active Directory, workstation protection and network access. In the authorisation form, we record the test period, target systems and contacts on both sides.

Provide a workstation and user account

You usually provide a client that is already part of Active Directory, plus a user account with normal permissions. We clarify in advance which network access is needed for the agreed tests.

Plan a breach and attack simulation
Dividers fixing a position on the world map
Clear test objectives from the outset for an AD pentest that takes no detours.

Agreeing on test boundaries together

We limit the test to the agreed scope and the authorised test activities. This does not amount to a complete examination of all attack paths.

Questions about breach and attack simulation

Can the Active Directory pentest be carried out remotely?

Yes, with our pentest box. It needs power and a network connection. Your team sets up access to the test networks. The connection to secuvera runs over a secured VPN channel. Alternatively, we test on site.

What insight into the results does our management get?

The report contains a management summary. It explains and assesses the identified vulnerabilities without requiring detailed technical knowledge. A management presentation is also possible on request.

How do we find out about serious security problems during the test?

We inform the agreed contact immediately about serious findings. We discuss the next steps for remediation with the people responsible on your side.

Do you also test hybrid identities with Microsoft Entra ID?

Yes. If you use Active Directory together with Microsoft Entra ID (formerly Azure AD), we include the hybrid identity environment in the breach and attack simulation. We agree on the exact scope in the initial consultation.

How is a breach and attack simulation billed?

The two modules “Pre-Assumed Breach” and “Assumed Breach” are each offered with a fixed number of person-days. You can commission one module individually or both together.

How can we support you with breach and attack simulation?