Active Directory and identity penetration testing

Find the identity paths that can turn one compromised account into control of the environment.

Damocles Active Directory & Identity Penetration Testing assesses credential exposure, privilege escalation, delegation, trust relationships, administrative paths and identity controls that can allow a standard or compromised identity to reach high-value systems.

Active Directory privilege pathsCredential and secret exposureDelegation and trust abuseAdministrative control paths
Why customers buy this test

Expose identity paths that lead to privileged control.

Directory and identity compromise is rarely caused by one dramatic flaw. Excessive group membership, delegated rights, service accounts, credential exposure, stale privilege, trust relationships and administrative design can combine into a reliable path to high privilege.

Damocles tests the agreed identity environment from a supplied starting position and maps practical escalation paths so remediation can remove the relationships that provide the most attacker leverage.

01

Expose privilege paths

Identify how standard identities can reach administrative roles, systems or control-plane capability.

02

Find credential risk

Assess exposed secrets, reusable credentials and service-account conditions that expand attacker access.

03

Prioritise identity remediation

Focus on the delegation, membership, trust and administrative relationships that break the highest-value attack paths.

What we test

Directory objects, identities, privilege relationships and administrative infrastructure in the agreed domain or tenant context.

The exact scope depends on the identity platforms, supplied account, trust model and systems the customer identifies as high value.

ID

Users and groups

Standard, privileged and service identities, group membership and privilege inheritance.

SP

Service identities

Service accounts, service principals, scheduled tasks and credentials associated with automated access.

DL

Delegation

Delegated rights, object control, administrative delegation and privilege relationships.

TR

Trust relationships

Domain, forest or other identity trust paths included in the authorised scope.

CR

Credential exposure

Passwords, hashes, tokens, cached access and secrets encountered through authorised testing.

AD

Administrative paths

Management hosts, privileged workstations, remote administration and identity control-plane access.

Technical assurance

Expose the identity paths that lead to privileged control.

Review and test representative Active Directory access to identify credential, delegation, permission and trust paths that could expand one account into wider administrative control.

Identity exposure

Users, groups, computers and services visible to an attacker.

Credential paths

Weak, reusable or recoverable credential material.

Permission chains

ACLs, group membership and delegated rights that enable escalation.

Service accounts

Privileges, configuration and authentication risks around services.

Administrative tiers

Separation between ordinary, server and domain administration.

Domain and forest trusts

Paths that cross identity or organisational boundaries.

Policy and hardening

Controls that reduce common identity attack techniques.

13governed test areas
3authorised testing perspectives
6controlled evidence outputs
13framework / control evidence mappings
What we actually test

Representative technical coverage with the evidence produced.

These are governed procedures from the service assurance profile—not generic marketing categories. The complete matrix below records applicability, access requirements and limitations for every coverage area.

Jump to full coverage matrix ↓
Coverage area

Supplied starting identity

Damocles records the supplied identity, workstation, network position, group membership and expected trust context before directory queries begin.

Evidence producedEvidence records the principal, group, ACL, permission, host, session or ordered privilege-path evidence relevant to supplied starting identity.
Framework references
Technical Guide to Information Security Testing and Assessment SP 800-115
Coverage area

Users and groups

Damocles enumerates authorised users, groups, nesting, privileged membership and directory ACLs to identify unexpected identity relationships.

Evidence producedEvidence records the principal, group, ACL, permission, host, session or ordered privilege-path evidence relevant to users and groups.
Framework references
Technical Guide to Information Security Testing and Assessment SP 800-115
Coverage area

Service accounts

Damocles examines service-account privilege, delegation, logon rights, credential handling, ownership and lifecycle evidence.

Evidence producedEvidence records the principal, group, ACL, permission, host, session or ordered privilege-path evidence relevant to service accounts.
Framework references
Technical Guide to Information Security Testing and Assessment SP 800-115
Coverage area

Credential exposure

Damocles inspects authorised hosts, shares, directory attributes, scripts and configuration for exposed or reusable credential material without bulk harvesting.

Evidence producedEvidence records the principal, group, ACL, permission, host, session or ordered privilege-path evidence relevant to credential exposure.
Framework references
Technical Guide to Information Security Testing and Assessment SP 800-115
Coverage area

Delegation

Damocles analyses constrained, unconstrained and resource-based delegation and validates only the minimum safe identity transition needed to prove risk.

Evidence producedEvidence records the principal, group, ACL, permission, host, session or ordered privilege-path evidence relevant to delegation.
Framework references
Technical Guide to Information Security Testing and Assessment SP 800-115
Coverage area

Trust relationships

Damocles identifies trust direction, scope, authentication behaviour, filtering and reachable principals or resources across authorised domains or forests.

Evidence producedTrust direction and scope record with observed authentication and reachable principal or resource evidence.
Framework references
Technical Guide to Information Security Testing and Assessment SP 800-115

Showing 6 representative areas. The full governed matrix contains 13 coverage areas.

Standards and assurance coverage

See how this engagement is structured, classified and mapped before opening the full evidence matrix.

References are shown according to the role they play in the engagement. Methodologies guide testing, taxonomies classify findings, severity methods support consistent scoring, and control mappings connect scoped evidence to broader assurance work.

01 · Test method

How testing is structured

Approved methodology, verification and testing guidance used to select and structure relevant procedures within the authorised scope.

Technical Guide to Information Security Testing and Assessment SP 800-115
02 · Finding language

How weaknesses and severity are classified

Approved risk, weakness and severity references provide a consistent language for confirmed findings without replacing customer-specific business impact.

Common Weakness Enumeration 4.20Common Vulnerability Scoring System 4.0
03 · Control evidence

What maps into compliance and assurance work

13governed evidence mappings across 7 approved frameworks and 12 referenced controls.
4 directly assessed5 supporting evidence4 contextual
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0Directly assessed
AC-3

Tests representative directory access enforcement through group membership, ACLs, delegated rights, trusts and management paths using authorised identities and queries.

Security and Privacy Controls for Information Systems and Organizations Release 5.2.0Directly assessed
AC-6

Tests representative least-privilege and privilege-escalation boundaries across standard identities, service accounts, administrative groups, tiers and safe privilege paths.

Security and Privacy Controls for Information Systems and Organizations Release 5.2.0Supporting evidence
AC-2IA-5

Reviews sampled user, group, computer and service-account relationships together with exposed or reusable credential material and relevant lifecycle conditions.

+ 10 additional governed mappings in the full control matrix.

Jump to full control mapping ↓
04 · Evidence package

What the customer can use after the engagement

An identity attack-path report with validated evidence, affected principals, prioritised remediation and retest results.

  • Authorised scope and rules of engagement
  • Coverage matrix
  • Retest and residual-risk record
  • + 3 additional controlled outputs

What this means: technical evidence may support risk, compliance and audit activity where the mapping is applicable. It does not by itself certify the organisation, establish complete compliance or assess controls outside the authorised scope.

How we test

Manual validation backed by controlled evidence.

Damocles analyses directory identities, groups, ACLs, delegation, trusts, credentials and sessions from the supplied foothold, validating only the minimum safe step needed to prove a privilege path. Directory exports support but do not replace live evidence; protected accounts and disruptive credential activity remain excluded.

How to read the mapping

Evidence is mapped to the part of a control we can actually assess.

Directly assessed means the engagement tests the relevant behaviour. Supporting evidence means the result can contribute to a broader control assessment. Contextual references explain relevance without claiming that the control was tested.

All relevant frameworks
Technical Guide to Information Security Testing and Assessment SP 800-115Information Security Manual June 2026Common Weakness Enumeration 4.20Common Vulnerability Scoring System 4.0Security and Privacy Controls for Information Systems and Organizations Release 5.2.0Prudential Standard CPS 234 Information Security effective 1 July 2019Prudential Practice Guide CPG 234 Information Security published June 2019ISO/IEC 27001 2022 with Amendment 1:2024ISO/IEC 27002 2022Payment Card Industry Data Security Standard 4.0.1
Testing perspectives3 authorised viewpoints and access models

Assumed internal foothold

Queries authorised directory and host information from the supplied compromise position.

Included when
Used to identify relationships and opportunities available before a domain identity is supplied.
Access required
A controlled internal host or connection, scope boundaries and approved directory endpoints.
Limitations
Represents one foothold and does not imply access from every segment or host.

Standard domain user or workstation

Uses a dedicated domain user and representative workstation to inspect groups, credentials, delegation, sessions and reachable administration paths.

Included when
Used for identity and privilege behaviour available to an ordinary principal.
Access required
A test user, workstation context, domain scope and protected-account exclusions.
Limitations
Findings apply to the supplied group membership, workstation and current directory state.

Directory privilege-path reviewer

Analyses group nesting, ACLs, delegation, service accounts, trusts, certificate services and administrative relationships to construct privilege paths.

Included when
Used where directory evidence can substantiate escalation or tier-boundary findings.
Access required
Authorised directory queries or exports, representative identities and system ownership data.
Limitations
Does not imply every domain object or privileged relationship was validated.
Exact test coverage and evidence13 governed coverage areas
What Damocles tests, the evidence produced and the scope boundary for each controlled coverage area.
Coverage areaWhat Damocles testsPerspective and accessEvidence producedReferences and limits
Supplied starting identityDamocles records the supplied identity, workstation, network position, group membership and expected trust context before directory queries begin.Assumed internal foothold
Assessment requires a supplied foothold or domain identity, authorised directory queries, representative hosts and protected-account exclusions, selected specifically for supplied starting identity.
Evidence records the principal, group, ACL, permission, host, session or ordered privilege-path evidence relevant to supplied starting identity.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Applies to Supplied starting identity when the directory relationship or authorised system is present in scope.

Limit: The conclusion is limited to the sampled supplied starting identity; validation stops at minimum proof and excludes protected accounts, persistence and uncontrolled credential activity.

Users and groupsDamocles enumerates authorised users, groups, nesting, privileged membership and directory ACLs to identify unexpected identity relationships.Assumed internal foothold
Assessment requires a supplied foothold or domain identity, authorised directory queries, representative hosts and protected-account exclusions, selected specifically for users and groups.
Evidence records the principal, group, ACL, permission, host, session or ordered privilege-path evidence relevant to users and groups.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Applies to Users and groups when the directory relationship or authorised system is present in scope.

Limit: The conclusion is limited to the sampled users and groups; validation stops at minimum proof and excludes protected accounts, persistence and uncontrolled credential activity.

Service accountsDamocles examines service-account privilege, delegation, logon rights, credential handling, ownership and lifecycle evidence.Assumed internal foothold
Assessment requires a supplied foothold or domain identity, authorised directory queries, representative hosts and protected-account exclusions, selected specifically for service accounts.
Evidence records the principal, group, ACL, permission, host, session or ordered privilege-path evidence relevant to service accounts.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Applies to Service accounts when the directory relationship or authorised system is present in scope.

Limit: The conclusion is limited to the sampled service accounts; validation stops at minimum proof and excludes protected accounts, persistence and uncontrolled credential activity.

Credential exposureDamocles inspects authorised hosts, shares, directory attributes, scripts and configuration for exposed or reusable credential material without bulk harvesting.Assumed internal foothold
Assessment requires a supplied foothold or domain identity, authorised directory queries, representative hosts and protected-account exclusions, selected specifically for credential exposure.
Evidence records the principal, group, ACL, permission, host, session or ordered privilege-path evidence relevant to credential exposure.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Applies to Credential exposure when the directory relationship or authorised system is present in scope.

Limit: The conclusion is limited to the sampled credential exposure; validation stops at minimum proof and excludes protected accounts, persistence and uncontrolled credential activity.

DelegationDamocles analyses constrained, unconstrained and resource-based delegation and validates only the minimum safe identity transition needed to prove risk.Assumed internal foothold
Assessment requires a supplied foothold or domain identity, authorised directory queries, representative hosts and protected-account exclusions, selected specifically for delegation.
Evidence records the principal, group, ACL, permission, host, session or ordered privilege-path evidence relevant to delegation.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Applies to Delegation when the directory relationship or authorised system is present in scope.

Limit: The conclusion is limited to the sampled delegation; validation stops at minimum proof and excludes protected accounts, persistence and uncontrolled credential activity.

Trust relationshipsDamocles identifies trust direction, scope, authentication behaviour, filtering and reachable principals or resources across authorised domains or forests.Standard domain user or workstation, Directory privilege-path reviewer
Directory trust configuration, authorised identities in each relevant domain or forest, and filtering or selective-authentication settings.
Trust direction and scope record with observed authentication and reachable principal or resource evidence.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Applies to Trust relationships when the directory relationship or authorised system is present in scope.

Limit: Testing does not traverse excluded domains or alter trust configuration, and observed reachability does not establish all possible identities.

Local privilege pathsDamocles inspects local groups, endpoint rights, services, scheduled tasks, stored credentials and administrative access for a safe local privilege path.Standard domain user or workstation, Directory privilege-path reviewer
A supplied workstation or server foothold, standard identity, local policy and permission evidence.
Host, identity, group, permission and configuration evidence supporting each local privilege step.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Applies to authorised domain-joined endpoints where local privilege assessment is included.

Limit: Validation stops after the minimum safe proof; excluded hosts, destructive service changes and persistence are not tested.

Domain privilege pathsDamocles analyses group nesting, ACLs, delegation, service accounts, certificate services, trusts and sessions and validates the least invasive domain privilege step.Standard domain user or workstation, Directory privilege-path reviewer
A standard domain identity, authorised directory queries, relevant ACL and certificate-service data, and named protected-account exclusions.
A step-by-step identity and permission path with affected principals, ACLs, delegation and the safely validated transition.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Applies to Domain privilege paths when domain privilege escalation is authorised from the supplied starting identity.

Limit: The result does not prove every directory path; password changes, persistence and impact to protected accounts are prohibited.

Administrative tiersDamocles compares administrative identities, systems, group membership and permitted logon paths with the supplied tiering model.Standard domain user or workstation, Directory privilege-path reviewer
The intended tier model, administrative group membership, permitted logon matrix, representative admin identities and system inventory.
Tier exception record identifying the principal, system, logon right or observed session that crosses the intended boundary.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Applies to Administrative tiers when the customer operates an administrative tiering or privileged-access model.

Limit: A point-in-time sample cannot prove continuous adherence; Damocles does not use production privileged credentials beyond approved validation.

Management systemsDamocles identifies privileged management systems and tests whether representative identities can reach or authenticate to them contrary to intended administration paths.Directory privilege-path reviewer
Current configuration export or read-only access, diagrams, owners and representative validation endpoints.
Configuration excerpts, object or rule identifiers and observed validation results.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Performed when current configuration evidence and a representative endpoint or device are included in the review.

Limit: A configuration snapshot cannot prove continuous enforcement across excluded nodes; validation avoids changes unless implementation work is authorised.

Authentication protocolsDamocles reviews and safely tests directory authentication protocols, signing, channel protection, delegation and fallback behaviour.Standard domain user or workstation, Directory privilege-path reviewer
A standard domain identity and workstation, domain policy, protocol configuration and approved authentication endpoints.
Protocol negotiation, policy and delegation evidence tied to the tested identity and endpoint.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Applies to the directory authentication protocols reachable from the authorised foothold.

Limit: Credential relay, downgrade or coercion attempts stop at agreed safety thresholds and excluded accounts or systems are not targeted.

Identity attack-path chainingDamocles connects credential, delegation, group, ACL, service-account and session observations into an ordered, reproducible identity privilege path.Standard domain user or workstation, Directory privilege-path reviewer
The supplied foothold, directory query access, authorised endpoints and the evidence gathered from preceding identity procedures.
An ordered attack-path chain naming each principal, permission, credential, session or administrative relationship and the validated transition.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Applies to Identity attack-path chaining when multiple in-scope observations form a credible route to additional privilege or a sensitive identity.

Limit: The chain is bounded to observed conditions and approved proof steps; it does not assert untested alternatives or authorise persistence.

Protected accounts and credential-testing limitsDamocles applies protected-account, authentication-attempt and credential-handling exclusions and records how they limit privilege-path coverage.Assumed internal foothold
Assessment requires a supplied foothold or domain identity, authorised directory queries, representative hosts and protected-account exclusions, selected specifically for protected accounts and credential-testing limits.
Evidence records the principal, group, ACL, permission, host, session or ordered privilege-path evidence relevant to protected accounts and credential-testing limits.
Technical Guide to Information Security Testing and Assessment SP 800-115

Applicability: Applies to Protected accounts and credential-testing limits when the directory relationship or authorised system is present in scope.

Limit: The conclusion is limited to the sampled protected accounts and credential-testing limits; validation stops at minimum proof and excludes protected accounts, persistence and uncontrolled credential activity.

Framework and control mappings13 governed evidence mappings
Where scoped technical evidence maps to approved security frameworks and control objectives.
Framework and controlsMapping typeWhat Damocles assessesEvidence producedApplicability and limits
Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
AC-3
Directly assessedTests representative directory access enforcement through group membership, ACLs, delegated rights, trusts and management paths using authorised identities and queries.Principal, group, ACL, permission, trust and observed access evidence tied to the sampled identity path.

Applies: Applies to directory relationships and authorised systems represented in scope.

Limit: Does not establish access enforcement for every principal, object, ACL, trust or directory service and validation stops at minimum proof.

Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
AC-6
Directly assessedTests representative least-privilege and privilege-escalation boundaries across standard identities, service accounts, administrative groups, tiers and safe privilege paths.Ordered privilege-path chains, affected principals, memberships, delegated rights and safely validated transitions.

Applies: Applies where privileged group, tiering, service-account or escalation analysis is authorised.

Limit: Does not establish least privilege for every identity or system and no persistence, destructive change or uncontrolled privileged use is authorised.

Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
AC-2IA-5
Supporting evidenceReviews sampled user, group, computer and service-account relationships together with exposed or reusable credential material and relevant lifecycle conditions.Identity relationship map, group and account evidence, credential-handling observations and findings.

Applies: Applies to the supplied directory scope, representative accounts and authorised credential-handling procedures.

Limit: Does not establish complete account-management or authenticator-management processes, lifecycle governance or continuous operation.

Security and Privacy Controls for Information Systems and Organizations Release 5.2.0
CA-8
Supporting evidencePerforms an authorised identity penetration test and records identity discovery, privilege relationships and minimum safe validation steps.Rules of engagement, identity relationship map, privilege-path chain, findings, remediation guidance and retest evidence where included.

Applies: Relevant where the customer uses identity penetration testing within a broader assessment program.

Limit: Does not establish testing frequency, enterprise coverage or completeness of the broader program.

Information Security Manual June 2026
ISM-1927
Directly assessedTests representative access paths to in-scope Active Directory infrastructure and whether lower-privilege identities can reach protected management systems contrary to intended access.Identity, host, management-path and observed authentication or reachability evidence.

Applies: Applies only when relevant AD DS, AD CS, AD FS or Entra Connect systems and representative identities are in scope.

Limit: Does not establish access restrictions for every privileged user, management path or Active Directory service.

Information Security Manual June 2026
ISM-1939ISM-1940ISM-1941
Directly assessedReviews observed membership of Domain Admins, Enterprise Admins and other customer-identified highly privileged groups for user, service and computer accounts.Privileged-group membership records, account type and relationship evidence, plus findings for unexpected or excessive membership.

Applies: Applies where privileged group membership and relevant account classes are available within the authorised directory query scope.

Limit: Point-in-time membership review does not establish ongoing governance, approval, recertification or all privileged groups across excluded domains.

Information Security Manual June 2026
ISM-1508
Supporting evidenceProduces sampled technical evidence about whether privileged identities, delegated rights and administrative paths exceed the access required for their represented role.Privilege-path evidence, group and ACL observations, administrative tier exceptions and findings.

Applies: Relevant where the customer uses the engagement to support review of privileged access within the assessed directory scope.

Limit: The engagement cannot determine business necessity for every entitlement and does not establish complete privileged-access governance or continuous compliance.

Information Security Manual June 2026
ISM-2118
Supporting evidenceProvides scoped identity penetration-test evidence that can support an organisation's security-assurance testing program.Authorised scope, identity relationship and privilege-path evidence, findings, remediation guidance and retest results where included.

Applies: Relevant where the organisation uses the engagement within its vulnerability-assessment and penetration-testing program.

Limit: A single engagement does not establish required testing cadence, full directory coverage or compliance with ISM-2118.

Prudential Standard CPS 234 Information Security effective 1 July 2019
CPS 234 paragraph 27
Supporting evidenceProduces scoped Active Directory and identity penetration-testing evidence that may support an APRA-regulated entity's systematic testing of information-security control effectiveness.Governed scope, identity relationship and privilege-path evidence, findings, remediation guidance and retest results where included.

Applies: Relevant only where the customer determines that the assessed identity systems and evidence are applicable to its assurance or compliance scope. For APRA-regulated entities, the customer determines how the engagement contributes to its broader systematic control-testing program.

Limit: A scoped engagement does not by itself establish the customer's systematic testing program, testing frequency, full control population, specialist independence, governance, reporting or compliance with other CPS 234 requirements.

Prudential Practice Guide CPG 234 Information Security published June 2019
Framework-level context
ContextualProduces scoped Active Directory and identity penetration-testing evidence consistent with CPG 234 guidance that testing techniques should be selected for the control and risk being assessed.Governed scope, identity relationship and privilege-path evidence, findings, remediation guidance and retest results where included.

Applies: Relevant only where the customer determines that the assessed identity systems and evidence are applicable to its assurance or compliance scope. APRA-regulated customers determine how this evidence contributes to their broader assurance program.

Limit: CPG 234 is prudential guidance rather than a standalone certification target; this mapping does not claim assessment of the complete guidance or customer compliance.

ISO/IEC 27001 2022 with Amendment 1:2024
Framework-level context
ContextualProduces scoped Active Directory and identity penetration-testing evidence that may support customer assurance activities organised around ISO/IEC 27001 where the assessed systems and behaviours are relevant.Governed scope, identity relationship and privilege-path evidence, findings, remediation guidance and retest results where included.

Applies: Relevant only where the customer determines that the assessed identity systems and evidence are applicable to its assurance or compliance scope.

Limit: Licensed ISO/IEC 27001 control or requirement identifiers and text are intentionally withheld. The engagement does not establish ISO/IEC 27001 certification, attestation or whole-framework conformity.

ISO/IEC 27002 2022
Framework-level context
ContextualProduces scoped Active Directory and identity penetration-testing evidence that may support customer assurance activities organised around ISO/IEC 27002 where the assessed systems and behaviours are relevant.Governed scope, identity relationship and privilege-path evidence, findings, remediation guidance and retest results where included.

Applies: Relevant only where the customer determines that the assessed identity systems and evidence are applicable to its assurance or compliance scope.

Limit: Licensed ISO/IEC 27002 control or requirement identifiers and text are intentionally withheld. The engagement does not establish ISO/IEC 27002 certification, attestation or whole-framework conformity.

Payment Card Industry Data Security Standard 4.0.1
Framework-level context
ContextualProduces scoped Active Directory and identity penetration-testing evidence that may support customer assurance activities organised around PCI DSS where the assessed systems and behaviours are relevant.Governed scope, identity relationship and privilege-path evidence, findings, remediation guidance and retest results where included.

Applies: Relevant only where the customer determines that the assessed identity systems and evidence are applicable to its assurance or compliance scope.

Limit: Licensed PCI DSS control or requirement identifiers and text are intentionally withheld. The engagement does not establish PCI DSS certification, attestation or whole-framework conformity.

Assurance boundary: Damocles maps assessed coverage and findings to agreed security frameworks and control objectives. This provides traceable technical evidence that may support risk, assurance and audit activities. A penetration test does not by itself certify an organisation, establish complete compliance with a framework or confirm the effectiveness of controls outside the authorised scope.

Report and evidence outputs6 controlled output types

Authorised scope and rules of engagement

Records authorised scope and rules of engagement produced from the authorised Active Directory and identity penetration testing work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Coverage matrix

Records coverage matrix produced from the authorised Active Directory and identity penetration testing work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Retest and residual-risk record

Records retest and residual-risk record produced from the authorised Active Directory and identity penetration testing work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Identity relationship map

Records identity relationship map produced from the authorised Active Directory and identity penetration testing work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Privilege-path chain

Records privilege-path chain produced from the authorised Active Directory and identity penetration testing work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.

Affected principal and permission evidence

Records affected principal and permission evidence produced from the authorised Active Directory and identity penetration testing work.

Included when
Included in the final deliverable when the relevant procedure is performed.
Limitations
Contains only evidence gathered from authorised systems, identities and review material.
What you receive

An identity attack-path report with validated evidence, affected principals, prioritised remediation and retest results.

Attack paths we look for

Identity attack paths that turn delegated or standard access into high privilege.

Testing follows practical graph and trust relationships rather than treating every directory object as an isolated finding.

PE

Privilege escalation

Paths from standard or delegated access into higher-privilege roles or control.

CR

Credential compromise

Exposed, reusable or over-privileged credentials that enable broader identity access.

DG

Delegation abuse

Delegated object or administrative rights that provide unintended control over privileged identities or systems.

TR

Trust abuse

Misused trust relationships or inherited access that expands privilege across identity boundaries.

SP

Service-account abuse

Service identities and permissions that can be used to gain persistent or elevated access.

AP

Administrative-path compromise

Control of management systems or privileged access paths that leads to wider environment compromise.

Engagement options

Choose the starting identity and the privilege boundary that must be tested.

The statement of work identifies the supplied user, domain or tenant scope, protected accounts, excluded systems and acceptable credential-testing techniques.

Standard user
SU

Standard-user identity test

Start with a normal approved user and assess escalation and access paths.

Compromised account
SC

Assumed compromised identity

Model a known compromised account and assess blast radius and privilege growth.

Privilege
PA

Privileged-access review and test

Focus on administrative groups, delegated control, service identities and privileged management paths.

Integrated
IT

Identity + internal network test

Combine directory privilege paths with host, service and segmentation testing.

What you receive

An identity attack-path map the customer can use to remove the relationships that create compromise.

Findings are prioritised around attacker leverage and protected systems rather than object count.

AP

Privilege attack-path narrative

Step-by-step identity path from the supplied foothold to elevated control or sensitive systems.

PR

Privilege relationship findings

Affected users, groups, services, delegation or trust relationships and the condition that creates risk.

CR

Credential-risk findings

Evidence of exposed or reusable secrets and the privilege they enable.

AR

Administrative-path findings

Management and privileged-access conditions that expose broader environment control.

RP

Prioritised identity remediation

Changes to group membership, delegation, service identities, credential practices and administrative architecture.

RR

Retest evidence

Verification that agreed privilege and identity paths were removed or constrained.

Remediation and retesting

Retesting follows the original identity path and confirms whether the privilege relationship was removed.

Damocles can repeat agreed identity attack paths after group, delegation, credential or administrative changes and record whether the escalation condition remains possible.

Large identity redesigns and new domains or tenants can require new assessment scope beyond the original retest.

Testing delivery

A controlled technical engagement without turning the service page into a methodology manual.

The commercial scope comes first. Delivery is then controlled through written authority, agreed safety boundaries and a clear retest path.

01

Scope and authorise

Confirm targets, ownership, attacker perspective, accounts, exclusions, timing, contacts and prohibited activity.

02

Test and validate

Perform the authorised manual and technical testing required to prove or disprove the attack paths in scope.

03

Report and brief

Provide evidence, impact, affected scope, remediation priorities and a technical walkthrough with the people responsible for the fix.

04

Retest

Reproduce agreed findings after remediation and record whether they are resolved, reduced or still exploitable.

Scope boundaries

Identity testing is limited to approved accounts, domains, tenants and credential techniques.

Uncontrolled password spraying, destructive changes, production account disruption and access to specially protected identities require explicit written approval or are excluded.

Cloud identity, SaaS identity and on-premises Active Directory can be combined where required, but the exact platforms and trust relationships must be included in scope.

Scope the right test

Tell us the identity environment, starting account and privileged systems you need protected.

We will define the domain or tenant scope, supplied identities, prohibited accounts, credential-testing boundaries, deliverables and retest allowance.