Expose privilege paths
Identify how standard identities can reach administrative roles, systems or control-plane capability.
Damocles Active Directory & Identity Penetration Testing assesses credential exposure, privilege escalation, delegation, trust relationships, administrative paths and identity controls that can allow a standard or compromised identity to reach high-value systems.
Directory and identity compromise is rarely caused by one dramatic flaw. Excessive group membership, delegated rights, service accounts, credential exposure, stale privilege, trust relationships and administrative design can combine into a reliable path to high privilege.
Damocles tests the agreed identity environment from a supplied starting position and maps practical escalation paths so remediation can remove the relationships that provide the most attacker leverage.
Identify how standard identities can reach administrative roles, systems or control-plane capability.
Assess exposed secrets, reusable credentials and service-account conditions that expand attacker access.
Focus on the delegation, membership, trust and administrative relationships that break the highest-value attack paths.
The exact scope depends on the identity platforms, supplied account, trust model and systems the customer identifies as high value.
Standard, privileged and service identities, group membership and privilege inheritance.
Service accounts, service principals, scheduled tasks and credentials associated with automated access.
Delegated rights, object control, administrative delegation and privilege relationships.
Domain, forest or other identity trust paths included in the authorised scope.
Passwords, hashes, tokens, cached access and secrets encountered through authorised testing.
Management hosts, privileged workstations, remote administration and identity control-plane access.
Review and test representative Active Directory access to identify credential, delegation, permission and trust paths that could expand one account into wider administrative control.
Users, groups, computers and services visible to an attacker.
Weak, reusable or recoverable credential material.
ACLs, group membership and delegated rights that enable escalation.
Privileges, configuration and authentication risks around services.
Separation between ordinary, server and domain administration.
Paths that cross identity or organisational boundaries.
Controls that reduce common identity attack techniques.
These are governed procedures from the service assurance profile—not generic marketing categories. The complete matrix below records applicability, access requirements and limitations for every coverage area.
Damocles records the supplied identity, workstation, network position, group membership and expected trust context before directory queries begin.
Damocles enumerates authorised users, groups, nesting, privileged membership and directory ACLs to identify unexpected identity relationships.
Damocles examines service-account privilege, delegation, logon rights, credential handling, ownership and lifecycle evidence.
Damocles inspects authorised hosts, shares, directory attributes, scripts and configuration for exposed or reusable credential material without bulk harvesting.
Damocles analyses constrained, unconstrained and resource-based delegation and validates only the minimum safe identity transition needed to prove risk.
Damocles identifies trust direction, scope, authentication behaviour, filtering and reachable principals or resources across authorised domains or forests.
Showing 6 representative areas. The full governed matrix contains 13 coverage areas.
References are shown according to the role they play in the engagement. Methodologies guide testing, taxonomies classify findings, severity methods support consistent scoring, and control mappings connect scoped evidence to broader assurance work.
Approved methodology, verification and testing guidance used to select and structure relevant procedures within the authorised scope.
Approved risk, weakness and severity references provide a consistent language for confirmed findings without replacing customer-specific business impact.
Tests representative directory access enforcement through group membership, ACLs, delegated rights, trusts and management paths using authorised identities and queries.
Tests representative least-privilege and privilege-escalation boundaries across standard identities, service accounts, administrative groups, tiers and safe privilege paths.
Reviews sampled user, group, computer and service-account relationships together with exposed or reusable credential material and relevant lifecycle conditions.
+ 10 additional governed mappings in the full control matrix.
Jump to full control mapping ↓An identity attack-path report with validated evidence, affected principals, prioritised remediation and retest results.
What this means: technical evidence may support risk, compliance and audit activity where the mapping is applicable. It does not by itself certify the organisation, establish complete compliance or assess controls outside the authorised scope.
Damocles analyses directory identities, groups, ACLs, delegation, trusts, credentials and sessions from the supplied foothold, validating only the minimum safe step needed to prove a privilege path. Directory exports support but do not replace live evidence; protected accounts and disruptive credential activity remain excluded.
Directly assessed means the engagement tests the relevant behaviour. Supporting evidence means the result can contribute to a broader control assessment. Contextual references explain relevance without claiming that the control was tested.
Queries authorised directory and host information from the supplied compromise position.
Uses a dedicated domain user and representative workstation to inspect groups, credentials, delegation, sessions and reachable administration paths.
Analyses group nesting, ACLs, delegation, service accounts, trusts, certificate services and administrative relationships to construct privilege paths.
| Coverage area | What Damocles tests | Perspective and access | Evidence produced | References and limits |
|---|---|---|---|---|
| Supplied starting identity | Damocles records the supplied identity, workstation, network position, group membership and expected trust context before directory queries begin. | Assumed internal foothold Assessment requires a supplied foothold or domain identity, authorised directory queries, representative hosts and protected-account exclusions, selected specifically for supplied starting identity. | Evidence records the principal, group, ACL, permission, host, session or ordered privilege-path evidence relevant to supplied starting identity. | Technical Guide to Information Security Testing and Assessment SP 800-115 Applicability: Applies to Supplied starting identity when the directory relationship or authorised system is present in scope. Limit: The conclusion is limited to the sampled supplied starting identity; validation stops at minimum proof and excludes protected accounts, persistence and uncontrolled credential activity. |
| Users and groups | Damocles enumerates authorised users, groups, nesting, privileged membership and directory ACLs to identify unexpected identity relationships. | Assumed internal foothold Assessment requires a supplied foothold or domain identity, authorised directory queries, representative hosts and protected-account exclusions, selected specifically for users and groups. | Evidence records the principal, group, ACL, permission, host, session or ordered privilege-path evidence relevant to users and groups. | Technical Guide to Information Security Testing and Assessment SP 800-115 Applicability: Applies to Users and groups when the directory relationship or authorised system is present in scope. Limit: The conclusion is limited to the sampled users and groups; validation stops at minimum proof and excludes protected accounts, persistence and uncontrolled credential activity. |
| Service accounts | Damocles examines service-account privilege, delegation, logon rights, credential handling, ownership and lifecycle evidence. | Assumed internal foothold Assessment requires a supplied foothold or domain identity, authorised directory queries, representative hosts and protected-account exclusions, selected specifically for service accounts. | Evidence records the principal, group, ACL, permission, host, session or ordered privilege-path evidence relevant to service accounts. | Technical Guide to Information Security Testing and Assessment SP 800-115 Applicability: Applies to Service accounts when the directory relationship or authorised system is present in scope. Limit: The conclusion is limited to the sampled service accounts; validation stops at minimum proof and excludes protected accounts, persistence and uncontrolled credential activity. |
| Credential exposure | Damocles inspects authorised hosts, shares, directory attributes, scripts and configuration for exposed or reusable credential material without bulk harvesting. | Assumed internal foothold Assessment requires a supplied foothold or domain identity, authorised directory queries, representative hosts and protected-account exclusions, selected specifically for credential exposure. | Evidence records the principal, group, ACL, permission, host, session or ordered privilege-path evidence relevant to credential exposure. | Technical Guide to Information Security Testing and Assessment SP 800-115 Applicability: Applies to Credential exposure when the directory relationship or authorised system is present in scope. Limit: The conclusion is limited to the sampled credential exposure; validation stops at minimum proof and excludes protected accounts, persistence and uncontrolled credential activity. |
| Delegation | Damocles analyses constrained, unconstrained and resource-based delegation and validates only the minimum safe identity transition needed to prove risk. | Assumed internal foothold Assessment requires a supplied foothold or domain identity, authorised directory queries, representative hosts and protected-account exclusions, selected specifically for delegation. | Evidence records the principal, group, ACL, permission, host, session or ordered privilege-path evidence relevant to delegation. | Technical Guide to Information Security Testing and Assessment SP 800-115 Applicability: Applies to Delegation when the directory relationship or authorised system is present in scope. Limit: The conclusion is limited to the sampled delegation; validation stops at minimum proof and excludes protected accounts, persistence and uncontrolled credential activity. |
| Trust relationships | Damocles identifies trust direction, scope, authentication behaviour, filtering and reachable principals or resources across authorised domains or forests. | Standard domain user or workstation, Directory privilege-path reviewer Directory trust configuration, authorised identities in each relevant domain or forest, and filtering or selective-authentication settings. | Trust direction and scope record with observed authentication and reachable principal or resource evidence. | Technical Guide to Information Security Testing and Assessment SP 800-115 Applicability: Applies to Trust relationships when the directory relationship or authorised system is present in scope. Limit: Testing does not traverse excluded domains or alter trust configuration, and observed reachability does not establish all possible identities. |
| Local privilege paths | Damocles inspects local groups, endpoint rights, services, scheduled tasks, stored credentials and administrative access for a safe local privilege path. | Standard domain user or workstation, Directory privilege-path reviewer A supplied workstation or server foothold, standard identity, local policy and permission evidence. | Host, identity, group, permission and configuration evidence supporting each local privilege step. | Technical Guide to Information Security Testing and Assessment SP 800-115 Applicability: Applies to authorised domain-joined endpoints where local privilege assessment is included. Limit: Validation stops after the minimum safe proof; excluded hosts, destructive service changes and persistence are not tested. |
| Domain privilege paths | Damocles analyses group nesting, ACLs, delegation, service accounts, certificate services, trusts and sessions and validates the least invasive domain privilege step. | Standard domain user or workstation, Directory privilege-path reviewer A standard domain identity, authorised directory queries, relevant ACL and certificate-service data, and named protected-account exclusions. | A step-by-step identity and permission path with affected principals, ACLs, delegation and the safely validated transition. | Technical Guide to Information Security Testing and Assessment SP 800-115 Applicability: Applies to Domain privilege paths when domain privilege escalation is authorised from the supplied starting identity. Limit: The result does not prove every directory path; password changes, persistence and impact to protected accounts are prohibited. |
| Administrative tiers | Damocles compares administrative identities, systems, group membership and permitted logon paths with the supplied tiering model. | Standard domain user or workstation, Directory privilege-path reviewer The intended tier model, administrative group membership, permitted logon matrix, representative admin identities and system inventory. | Tier exception record identifying the principal, system, logon right or observed session that crosses the intended boundary. | Technical Guide to Information Security Testing and Assessment SP 800-115 Applicability: Applies to Administrative tiers when the customer operates an administrative tiering or privileged-access model. Limit: A point-in-time sample cannot prove continuous adherence; Damocles does not use production privileged credentials beyond approved validation. |
| Management systems | Damocles identifies privileged management systems and tests whether representative identities can reach or authenticate to them contrary to intended administration paths. | Directory privilege-path reviewer Current configuration export or read-only access, diagrams, owners and representative validation endpoints. | Configuration excerpts, object or rule identifiers and observed validation results. | Technical Guide to Information Security Testing and Assessment SP 800-115 Applicability: Performed when current configuration evidence and a representative endpoint or device are included in the review. Limit: A configuration snapshot cannot prove continuous enforcement across excluded nodes; validation avoids changes unless implementation work is authorised. |
| Authentication protocols | Damocles reviews and safely tests directory authentication protocols, signing, channel protection, delegation and fallback behaviour. | Standard domain user or workstation, Directory privilege-path reviewer A standard domain identity and workstation, domain policy, protocol configuration and approved authentication endpoints. | Protocol negotiation, policy and delegation evidence tied to the tested identity and endpoint. | Technical Guide to Information Security Testing and Assessment SP 800-115 Applicability: Applies to the directory authentication protocols reachable from the authorised foothold. Limit: Credential relay, downgrade or coercion attempts stop at agreed safety thresholds and excluded accounts or systems are not targeted. |
| Identity attack-path chaining | Damocles connects credential, delegation, group, ACL, service-account and session observations into an ordered, reproducible identity privilege path. | Standard domain user or workstation, Directory privilege-path reviewer The supplied foothold, directory query access, authorised endpoints and the evidence gathered from preceding identity procedures. | An ordered attack-path chain naming each principal, permission, credential, session or administrative relationship and the validated transition. | Technical Guide to Information Security Testing and Assessment SP 800-115 Applicability: Applies to Identity attack-path chaining when multiple in-scope observations form a credible route to additional privilege or a sensitive identity. Limit: The chain is bounded to observed conditions and approved proof steps; it does not assert untested alternatives or authorise persistence. |
| Protected accounts and credential-testing limits | Damocles applies protected-account, authentication-attempt and credential-handling exclusions and records how they limit privilege-path coverage. | Assumed internal foothold Assessment requires a supplied foothold or domain identity, authorised directory queries, representative hosts and protected-account exclusions, selected specifically for protected accounts and credential-testing limits. | Evidence records the principal, group, ACL, permission, host, session or ordered privilege-path evidence relevant to protected accounts and credential-testing limits. | Technical Guide to Information Security Testing and Assessment SP 800-115 Applicability: Applies to Protected accounts and credential-testing limits when the directory relationship or authorised system is present in scope. Limit: The conclusion is limited to the sampled protected accounts and credential-testing limits; validation stops at minimum proof and excludes protected accounts, persistence and uncontrolled credential activity. |
| Framework and controls | Mapping type | What Damocles assesses | Evidence produced | Applicability and limits |
|---|---|---|---|---|
| Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 AC-3 | Directly assessed | Tests representative directory access enforcement through group membership, ACLs, delegated rights, trusts and management paths using authorised identities and queries. | Principal, group, ACL, permission, trust and observed access evidence tied to the sampled identity path. | Applies: Applies to directory relationships and authorised systems represented in scope. Limit: Does not establish access enforcement for every principal, object, ACL, trust or directory service and validation stops at minimum proof. |
| Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 AC-6 | Directly assessed | Tests representative least-privilege and privilege-escalation boundaries across standard identities, service accounts, administrative groups, tiers and safe privilege paths. | Ordered privilege-path chains, affected principals, memberships, delegated rights and safely validated transitions. | Applies: Applies where privileged group, tiering, service-account or escalation analysis is authorised. Limit: Does not establish least privilege for every identity or system and no persistence, destructive change or uncontrolled privileged use is authorised. |
| Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 AC-2IA-5 | Supporting evidence | Reviews sampled user, group, computer and service-account relationships together with exposed or reusable credential material and relevant lifecycle conditions. | Identity relationship map, group and account evidence, credential-handling observations and findings. | Applies: Applies to the supplied directory scope, representative accounts and authorised credential-handling procedures. Limit: Does not establish complete account-management or authenticator-management processes, lifecycle governance or continuous operation. |
| Security and Privacy Controls for Information Systems and Organizations Release 5.2.0 CA-8 | Supporting evidence | Performs an authorised identity penetration test and records identity discovery, privilege relationships and minimum safe validation steps. | Rules of engagement, identity relationship map, privilege-path chain, findings, remediation guidance and retest evidence where included. | Applies: Relevant where the customer uses identity penetration testing within a broader assessment program. Limit: Does not establish testing frequency, enterprise coverage or completeness of the broader program. |
| Information Security Manual June 2026 ISM-1927 | Directly assessed | Tests representative access paths to in-scope Active Directory infrastructure and whether lower-privilege identities can reach protected management systems contrary to intended access. | Identity, host, management-path and observed authentication or reachability evidence. | Applies: Applies only when relevant AD DS, AD CS, AD FS or Entra Connect systems and representative identities are in scope. Limit: Does not establish access restrictions for every privileged user, management path or Active Directory service. |
| Information Security Manual June 2026 ISM-1939ISM-1940ISM-1941 | Directly assessed | Reviews observed membership of Domain Admins, Enterprise Admins and other customer-identified highly privileged groups for user, service and computer accounts. | Privileged-group membership records, account type and relationship evidence, plus findings for unexpected or excessive membership. | Applies: Applies where privileged group membership and relevant account classes are available within the authorised directory query scope. Limit: Point-in-time membership review does not establish ongoing governance, approval, recertification or all privileged groups across excluded domains. |
| Information Security Manual June 2026 ISM-1508 | Supporting evidence | Produces sampled technical evidence about whether privileged identities, delegated rights and administrative paths exceed the access required for their represented role. | Privilege-path evidence, group and ACL observations, administrative tier exceptions and findings. | Applies: Relevant where the customer uses the engagement to support review of privileged access within the assessed directory scope. Limit: The engagement cannot determine business necessity for every entitlement and does not establish complete privileged-access governance or continuous compliance. |
| Information Security Manual June 2026 ISM-2118 | Supporting evidence | Provides scoped identity penetration-test evidence that can support an organisation's security-assurance testing program. | Authorised scope, identity relationship and privilege-path evidence, findings, remediation guidance and retest results where included. | Applies: Relevant where the organisation uses the engagement within its vulnerability-assessment and penetration-testing program. Limit: A single engagement does not establish required testing cadence, full directory coverage or compliance with ISM-2118. |
| Prudential Standard CPS 234 Information Security effective 1 July 2019 CPS 234 paragraph 27 | Supporting evidence | Produces scoped Active Directory and identity penetration-testing evidence that may support an APRA-regulated entity's systematic testing of information-security control effectiveness. | Governed scope, identity relationship and privilege-path evidence, findings, remediation guidance and retest results where included. | Applies: Relevant only where the customer determines that the assessed identity systems and evidence are applicable to its assurance or compliance scope. For APRA-regulated entities, the customer determines how the engagement contributes to its broader systematic control-testing program. Limit: A scoped engagement does not by itself establish the customer's systematic testing program, testing frequency, full control population, specialist independence, governance, reporting or compliance with other CPS 234 requirements. |
| Prudential Practice Guide CPG 234 Information Security published June 2019 Framework-level context | Contextual | Produces scoped Active Directory and identity penetration-testing evidence consistent with CPG 234 guidance that testing techniques should be selected for the control and risk being assessed. | Governed scope, identity relationship and privilege-path evidence, findings, remediation guidance and retest results where included. | Applies: Relevant only where the customer determines that the assessed identity systems and evidence are applicable to its assurance or compliance scope. APRA-regulated customers determine how this evidence contributes to their broader assurance program. Limit: CPG 234 is prudential guidance rather than a standalone certification target; this mapping does not claim assessment of the complete guidance or customer compliance. |
| ISO/IEC 27001 2022 with Amendment 1:2024 Framework-level context | Contextual | Produces scoped Active Directory and identity penetration-testing evidence that may support customer assurance activities organised around ISO/IEC 27001 where the assessed systems and behaviours are relevant. | Governed scope, identity relationship and privilege-path evidence, findings, remediation guidance and retest results where included. | Applies: Relevant only where the customer determines that the assessed identity systems and evidence are applicable to its assurance or compliance scope. Limit: Licensed ISO/IEC 27001 control or requirement identifiers and text are intentionally withheld. The engagement does not establish ISO/IEC 27001 certification, attestation or whole-framework conformity. |
| ISO/IEC 27002 2022 Framework-level context | Contextual | Produces scoped Active Directory and identity penetration-testing evidence that may support customer assurance activities organised around ISO/IEC 27002 where the assessed systems and behaviours are relevant. | Governed scope, identity relationship and privilege-path evidence, findings, remediation guidance and retest results where included. | Applies: Relevant only where the customer determines that the assessed identity systems and evidence are applicable to its assurance or compliance scope. Limit: Licensed ISO/IEC 27002 control or requirement identifiers and text are intentionally withheld. The engagement does not establish ISO/IEC 27002 certification, attestation or whole-framework conformity. |
| Payment Card Industry Data Security Standard 4.0.1 Framework-level context | Contextual | Produces scoped Active Directory and identity penetration-testing evidence that may support customer assurance activities organised around PCI DSS where the assessed systems and behaviours are relevant. | Governed scope, identity relationship and privilege-path evidence, findings, remediation guidance and retest results where included. | Applies: Relevant only where the customer determines that the assessed identity systems and evidence are applicable to its assurance or compliance scope. Limit: Licensed PCI DSS control or requirement identifiers and text are intentionally withheld. The engagement does not establish PCI DSS certification, attestation or whole-framework conformity. |
Assurance boundary: Damocles maps assessed coverage and findings to agreed security frameworks and control objectives. This provides traceable technical evidence that may support risk, assurance and audit activities. A penetration test does not by itself certify an organisation, establish complete compliance with a framework or confirm the effectiveness of controls outside the authorised scope.
Records authorised scope and rules of engagement produced from the authorised Active Directory and identity penetration testing work.
Records coverage matrix produced from the authorised Active Directory and identity penetration testing work.
Records retest and residual-risk record produced from the authorised Active Directory and identity penetration testing work.
Records identity relationship map produced from the authorised Active Directory and identity penetration testing work.
Records privilege-path chain produced from the authorised Active Directory and identity penetration testing work.
Records affected principal and permission evidence produced from the authorised Active Directory and identity penetration testing work.
An identity attack-path report with validated evidence, affected principals, prioritised remediation and retest results.
Testing follows practical graph and trust relationships rather than treating every directory object as an isolated finding.
Paths from standard or delegated access into higher-privilege roles or control.
Exposed, reusable or over-privileged credentials that enable broader identity access.
Delegated object or administrative rights that provide unintended control over privileged identities or systems.
Misused trust relationships or inherited access that expands privilege across identity boundaries.
Service identities and permissions that can be used to gain persistent or elevated access.
Control of management systems or privileged access paths that leads to wider environment compromise.
The statement of work identifies the supplied user, domain or tenant scope, protected accounts, excluded systems and acceptable credential-testing techniques.
Start with a normal approved user and assess escalation and access paths.
Model a known compromised account and assess blast radius and privilege growth.
Focus on administrative groups, delegated control, service identities and privileged management paths.
Combine directory privilege paths with host, service and segmentation testing.
Findings are prioritised around attacker leverage and protected systems rather than object count.
Step-by-step identity path from the supplied foothold to elevated control or sensitive systems.
Affected users, groups, services, delegation or trust relationships and the condition that creates risk.
Evidence of exposed or reusable secrets and the privilege they enable.
Management and privileged-access conditions that expose broader environment control.
Changes to group membership, delegation, service identities, credential practices and administrative architecture.
Verification that agreed privilege and identity paths were removed or constrained.
Damocles can repeat agreed identity attack paths after group, delegation, credential or administrative changes and record whether the escalation condition remains possible.
Large identity redesigns and new domains or tenants can require new assessment scope beyond the original retest.
The commercial scope comes first. Delivery is then controlled through written authority, agreed safety boundaries and a clear retest path.
Confirm targets, ownership, attacker perspective, accounts, exclusions, timing, contacts and prohibited activity.
Perform the authorised manual and technical testing required to prove or disprove the attack paths in scope.
Provide evidence, impact, affected scope, remediation priorities and a technical walkthrough with the people responsible for the fix.
Reproduce agreed findings after remediation and record whether they are resolved, reduced or still exploitable.
Uncontrolled password spraying, destructive changes, production account disruption and access to specially protected identities require explicit written approval or are excluded.
Cloud identity, SaaS identity and on-premises Active Directory can be combined where required, but the exact platforms and trust relationships must be included in scope.
We will define the domain or tenant scope, supplied identities, prohibited accounts, credential-testing boundaries, deliverables and retest allowance.