- SituationActive Directory in production · no current map of paths into Tier Zero · privilege hidden in ordinary groups
- RiskSession and local-admin paths nobody reviews · a tool dump treated as a finding list · collection access left in place after the review
- OutcomeShort client list · each path marked real or noise · collection account and data handling closed with the review
The situation
Tier Zero is the set of assets that can take the domain: domain controllers, the accounts that control them, and the groups those accounts sit in. Most of the dangerous paths to that set do not look like a stolen domain-admin password. They look like a helpdesk group, a server where too many people are local administrators, or a session that was still open.
The useful review is small. It confirms the data is complete enough to trust, works backward from Tier Zero, and throws away edges that are stale. Handing a client the entire graph and wishing them luck is not an assessment.
What we did
- Agreed the collection account, the window, and how the data would be handled before anything was gathered
- Checked the ingest before analysis, so a partial collection was not treated as a complete directory
- Worked backward from Tier Zero in BloodHound instead of browsing every edge the tool could draw
- Judged each candidate path against current membership, real sessions, and real local admin — a stale edge did not become a finding
- Wrote each client item so someone who does not live in the graph could act on it
- Closed the review: collection access removed, results handed off, no standing copy left behind as an afterthought
Results
The client received a short list of paths worth fixing, with the noise left out. They also got the end of the collection window, which matters as much as the findings: an assessment account is not a permanent administrator.
Client identity is withheld. Specific paths are withheld with it. The pattern is one we repeat: Tier Zero first, prove the path, then write the item.
Related
See our Network Security practice and the conditional access case study, or contact us if “who can become a domain admin?” does not have a current answer.
Ready to talk through the next step?
Projects, managed services, or an honest read on your environment. You reach a principal consultant.