Eleven attack paths to domain admin, closed by four changes
A 40-site Active Directory estate had accumulated a decade of delegation. Attack chain analysis reduced 11 domain-admin paths to zero without a migration project.
- Customer
- Freight and warehousing operator
- Industry
- Logistics & Supply Chain
- Published
- February 19, 2026
At a glance
Customer profile
- Industry
- Freight and warehousing
- Company size
- 18,000 employees, 40 sites
- Environment
- Hybrid AD, Entra ID, on-site systems
- Engagement
- Quarterly internal, continuous external
Challenge
What was not working
Twenty years of acquisitions had produced one forest, six domains and a delegation model nobody fully understood. External testing was clean. Internal testing had never been attempted at scale, because nobody could scope it.
Privilege had accumulated with nobody removing any
Service accounts from decommissioned systems still held delegated rights. Every acquisition added a trust and none had ever been retired.
Findings without paths were not actionable
Previous audits produced hundreds of individual misconfigurations with no indication of which ones chained. The list was accurate, unranked and consequently untouched for two years.
Site networks were flat behind the perimeter
A warehouse floor terminal and the domain controller sat in the same broadcast domain at several sites, so the blast radius of any single compromised endpoint was the entire site.
No safe way to test internally
Warehouse operations run continuously. Anything that risked locking accounts or disrupting a scanner terminal was politically impossible to schedule.
Solution
What AIPTx did about it
The engagement was framed around reachability rather than compliance: not which settings deviate from a baseline, but which sequences of them get an attacker from a warehouse laptop to a domain controller.
- 1
Graph the estate before testing it
Read-only, 2 daysUsers, groups, machines, ACLs, delegations, trusts, GPO links and local admin membership were collected read-only across six domains and rendered as a single reachability graph.
- 2
Attack path enumeration
11 paths foundEvery route from a standard user context to Tier 0 was enumerated, then each hop was validated in a controlled window: Kerberoastable service accounts, unconstrained delegation, ACL abuse and certificate template misconfiguration among them.
- 3
Choke point analysis
4 changesRather than ranking the misconfigurations, the graph was analysed for nodes that many paths depend on. Four changes sat on all eleven paths, which turned a two-year backlog into a two-sprint plan.
- 4
Lockout-safe credential testing
0 lockoutsPassword attacks ran under the domain lockout policy with a deliberate margin, and account state was checked before every attempt. No production account was locked during the engagement.
- 5
Continuous re-verification of closed paths
MonthlyAfter remediation the paths were replayed monthly. Two reopened within a quarter (one from a new service account, one from a restored group membership) and both were caught before the next audit.
Results
What changed
Measured from the first internal assessment through two quarters of remediation and re-verification.
- 11 → 0
- Paths to domain adminVerified by replay after remediation
- 4
- Changes that closed all of themChoke points shared across every path
- 0
- Accounts locked during testingLockout-aware credential testing
- 340
- Stale privileged rights removedService accounts from decommissioned systems
- 2
- Paths that reopened, caught earlyBoth found by monthly replay, not by audit
- 6 weeks
- From first graph to zero pathsAgainst a two-year-old untouched backlog
Internal assessment
BeforeNever completed at scale
AfterQuarterly, with monthly path replay
Output
BeforeHundreds of unranked misconfigurations
After11 paths, 4 blocking changes
Remediation progress
BeforeStalled for 2 years
AfterComplete in 6 weeks
Regression detection
BeforeNext annual audit
AfterWithin a month, automatically
Key takeaways
The part that transfers
Every environment differs. These are the conclusions that hold outside this one.
Rank by reachability, not by severity
The two-year backlog was not an engineering failure; it was an ordering failure. Nobody could tell which of 400 findings mattered. Eleven paths and four changes was a plan someone could actually commit to.
Choke points beat severity every time
None of the four blocking changes was individually the highest-severity finding in the report. They were the ones every path ran through.
Closed is a state that decays
Two paths reopened within a quarter through routine administration. Without monthly replay, both would have been discovered by the next annual audit, or by someone else.
Operational safety is a testing requirement
The engagement was only possible because credential testing respected the lockout policy. The constraint that had blocked internal testing for years was solvable in configuration.
Related
Other programmes, other starting points
Finding the dependency risk that a vulnerability count kept hiding
A 4,100-package dependency tree produced 900 CVE alerts. Reachability analysis showed 23 were exploitable, and one was in a build tool nobody had inventoried.
ReadFinancial ServicesHow a financial services platform went from two pentests a year to one on every release
Six-to-eight week manual assessments at $50,000 each were gating releases. Continuous AI pentesting cut testing time 85% and moved security left of the deploy.
ReadHealthcareHIPAA-ready security testing for a patient platform that cannot go offline
A 24/7 clinical platform needed continuous testing without touching patient data or availability. Non-destructive assessments found 200+ issues with zero scan-induced downtime.
ReadSee Your Attack Surface in Real-Time
Run a comprehensive VAPT assessment powered by advanced security tools. Get actionable findings in hours, not weeks. No credit card required.