Tier 0 holds
everything.
A single misconfiguration in Active Directory — a stray ACL, an unprotected delegation, a service account in Domain Admins — is enough for a takeover. We review forest, domains, group policy and privileged accounts, and map several attack paths, not only the first.
What is included.
Review the identity backbone before an attacker takes it over.
Forest and domains
OU design, trusts, delegation model, domain controller configuration, replication protection.
Privileged accounts
Protected groups, AdminSDHolder, service accounts, Kerberoasting and ASREPRoasting targets, password policy.
Delegation and ACLs
Unconstrained and constrained delegation, ACL misconfiguration, GPO permissions, shadow admins.
Attack paths
Several escalation routes to Tier 0, prioritised by exploitability; a hardening plan with a sequence.
Five steps,
one deliverable.
Scoping
Forests, domains, access, time windows.
Collection
Export configuration read-only.
Analysis
Map misconfigurations and paths.
Prioritisation
Rank by exploitability and impact.
Report
Technical report, summary for management, hardening plan.