secureskies
Cyber Security/Harden/Active Directory Security Assessment

Tier 0 holds
everything.

A single misconfiguration in Active Directory — a stray ACL, an unprotected delegation, a service account in Domain Admins — is enough for a takeover. We review forest, domains, group policy and privileged accounts, and map several attack paths, not only the first.

FormatAssessmentread-only access, own tooling
ScopeForest · domains · GPOtrusts · Entra Connect
ModelMITRE ATT&CKMicrosoft tiering
OutcomeAttack-path mapplus hardening plan
01 · Service

What is included.

Review the identity backbone before an attacker takes it over.

Forest and domains

OU design, trusts, delegation model, domain controller configuration, replication protection.

Privileged accounts

Protected groups, AdminSDHolder, service accounts, Kerberoasting and ASREPRoasting targets, password policy.

Delegation and ACLs

Unconstrained and constrained delegation, ACL misconfiguration, GPO permissions, shadow admins.

Attack paths

Several escalation routes to Tier 0, prioritised by exploitability; a hardening plan with a sequence.

02 · Process

Five steps,
one deliverable.

01

Scoping

Forests, domains, access, time windows.

02

Collection

Export configuration read-only.

03

Analysis

Map misconfigurations and paths.

04

Prioritisation

Rank by exploitability and impact.

05

Report

Technical report, summary for management, hardening plan.

03 · Who it fits

When this service
applies.

After a merger or acquisition that adds trusts
Ahead of PAM or tiering projects
As the annual review of Tier 0
More services · Harden

How many paths lead
into your Tier 0?