Remote AD penetration testing
Through a secure VPN or internal test host, with access and testing windows agreed in advance.
Manage your cookie choices
By clicking "Accept all", you agree to the storing of cookies on your device to analyze site usage.
We can't find the internet
Attempting to reconnect
Something went wrong!
Hang in there while we get back on track
Microsoft Active Directory Your domain. Under scrutiny.
Hire experienced BlackSight specialists to manually test your Active Directory setup. Get validated attack paths, clear evidence, and fixes your IT team can act on.
Call to discuss your AD scope +1 (615) 200-7888Forest root
company.example
West domain
Trusted regional domain
East domain
Trusted regional domain
Experienced specialists. Manual testing.
Remote and on-site testing worldwide
Completion certificate includedFollow the access. Find the risk.
Our specialists manually investigate accounts, permissions, trusts, and systems, then validate what an attacker could reach within your agreed scope.
Standard domain account
The agreed starting point
Privileged access
Critical systems. Business impact.
AD Certificate Services, Entra ID, and hybrid identity can be included in the agreed scope.
Inside your environment.
Testing that fits how you operate
Through a secure VPN or internal test host, with access and testing windows agreed in advance.
At your premises worldwide, with travel and site access agreed in advance. Internal network and wireless testing can be scoped alongside AD.
Evidence for the people who need it
A completion certificate you can submit to your cyber insurance provider after the AD pentest.
Documented attack paths, technical evidence, and an executive summary.
Prioritized fixes and a results walkthrough. Retesting is defined in your proposal.
blacksight.
Security assessment
Certificate
of completion
Active Directory penetration testing
Prepared for
Your organization
Scope
Agreed AD environment
Assessment date
Your engagement dates
Documented assessment.
Issued by BlackSight.
AD testing pricing
Request a quote for manual Active Directory testing. We’ll follow up to confirm the scope and price. No technical details needed to get started.
Want to discuss pricing first?
Discuss pricing with an expertFrom the blog
Recent attack reports and authentication changes, with practical checks for your IT team.
Report:
Microsoft's September 2026 investigation connects fake IT support to AD reconnaissance and lateral movement. Learn which internal boundaries to test.
Read the analysisUpdate:
July 2026 updates remove the Kerberos RC4 audit-mode rollback. Review service accounts, AES compatibility, and remaining exceptions in Active Directory.
Read the analysisAnnouncement:
Microsoft's 2026 NTLM roadmap gives AD teams a reason to audit legacy authentication. Map dependencies, test Kerberos, and plan changes without blind spots.
Read the analysisExperienced BlackSight specialists carry out manual testing of your agreed AD environment, validate attack paths, and document the evidence and remediation priorities.
Our specialists manually investigate whether an attacker could turn a standard domain account or internal network access into greater access. We validate attack paths within your authorized scope and report evidence, impact, and fixes.
Yes. After your AD pentest, BlackSight provides a completion certificate you can submit to your cyber insurance provider, alongside your assessment report. Share any insurer-specific evidence requirements during scoping so we can confirm what the engagement will document.
Yes, through an agreed secure connection such as a VPN and an internal test host. We confirm access, accounts, and testing windows together. Domain controllers do not need to be exposed to the public internet.
Choose on-site testing when access must stay local or your scope includes work across locations and network segments. We travel worldwide and agree site access and travel costs in your proposal.
A health check reviews configuration and operational health. A pentest investigates how weaknesses combine into attack paths and validates their impact within agreed boundaries.
These can be included when explicitly scoped. Tell us about Entra ID, hybrid identity, federation, or AD Certificate Services during scoping so your proposal covers the right systems.
Your quote depends on domains and forests, access, testing depth, delivery, and travel. We confirm pricing, timing, deliverables, and any retesting before work begins.
We agree starting access, systems, exclusions, testing windows, and escalation contacts with your team. A standard domain account can support an assumed-breach scenario. Privileged access and disruptive techniques require separate agreement.
Need broader coverage? Explore our penetration testing services.