Mapping Active Directory & Kerberos Attack Paths with Lory | Lorikeet Security Skip to main content
Enterprise Internal Pentesting

Mapping Active Directory & Kerberos Attack Paths with Lory

September 23, 2026 8 min read Active Directory & Kerberos

In mature enterprise environments, 90 percent of breaches do not originate from an external zero-day flaw. They unfold internally: an adversary or malicious insider gains low-privilege access and traverses misconfigured Active Directory (AD) access control lists (ACLs) and Kerberos delegation trusts until reaching Domain Admin dominance.

Historically, auditing these internal lateral movement paths required deploying manual penetration testing consultants on site for weeks. Today, Lorikeet Security's autonomous engine Lory executes comprehensive internal Active Directory assessments over encrypted Lory Mesh connections. Here is how Lory safely models Kerberos attack paths, enumerates directory misconfigurations, and highlights critical escalation risks.

Secure Internal Ingress via Lory Mesh

Conducting an internal directory assessment without exposing internal ports to the internet requires dedicated tunneling. Lory operates over Lory Mesh:

Automated Kerberos Vector Analysis

Once inside the network segment, Lory initiates non-destructive enumeration against Domain Controllers and Kerberos Key Distribution Centers (KDCs):

Active Directory Attack Graph Mapping: [Standard Domain User] │ (Lory Mesh tunnel) ▼ [LDAP / SMB Enumeration] ──► Identify SPNs & Pre-Auth Flags │ ├─► AS-REP Roasting ───► Crackable TGT for user with DONT_REQ_PREAUTH ├─► Kerberoasting ───► Request TGS Ticket for MSSQL/HTTP SPN ├─► Delegation Path ───► Unconstrained Delegation / S4U2self Trust ▼ [BloodHound Attack Path] ──► Shortest path: Standard User ──► Workstation Admin ──► Domain Controller

1. AS-REP Roasting Identification

Lory queries Active Directory for user accounts configured with the `DONT_REQ_PREAUTH` (Do not require Kerberos pre-authentication) flag. For these accounts, any domain user can request an AS-REP ticket without knowing the target account's password. Lory extracts the cryptographic hash safely, validating whether the account can be cracked offline without generating multiple failed logon events on the domain controller.

2. Kerberoasting and SPN Analysis

Any authenticated domain user can request a Kerberos Ticket Granting Service (TGS) ticket for any Service Principal Name (SPN) registered within the forest. Lory's Active Directory subagent queries LDAP to catalogue all user accounts with registered SPNs (such as SQL Server or IIS service accounts), checks whether weak RC4 encryption (Ticket Type 23) is enabled, and evaluates the risk of offline password cracking.

3. Delegation & Constrained Protocol Transitions

Kerberos delegation allows services to impersonate users when accessing back-end resources. Lory audits:

Lory Enumeration Toolsuite

Lory executes targeted, non-disruptive internal auditing tools wrapped in automated telemetry:

Internal Tool Target Protocol Audit Function Safety Guardrails
smb_enum SMB (Port 445) Checks SMB signing requirements, anonymous share access, and SMBv1 exposure. Read-only metadata inspection, zero file modifications.
ldap_search LDAP / LDAPS (389/636) Maps domain trusts, ACL permissions, nested groups, and DCSync replication rights. Strict pagination and rate limiting to prevent DC CPU spikes.
snmp_enum SNMP (Port 161) Sweeps for default public/private community strings revealing network topologies. Single UDP query per community string.
bloodhound_parser Graph ACLs Computes transitive object relationships (GenericAll, WriteDacl, ForceChangePassword). Analyzes graph representations in memory without DC interaction.
Zero-Lockout Safety Guarantee

Lory is engineered specifically to prevent service interruptions. Lory never executes high-volume password spray attacks that could exceed your organization's Account Lockout Threshold. All Kerberos and LDAP evaluations rely exclusively on legitimate single-query ticket acquisitions and directory lookups.

Human-in-the-Loop Attack Path Verification

When Lory identifies a complete escalation path from an entry-level workstation to Domain Admin privileges, the finding is routed to Lorikeet Security's credentialed offensive engineers (OSCP/CISSP). Our human experts inspect the graph edges, confirm the technical exploitability, and draft precise remediation guidance-such as disabling RC4, enforcing AES-256 for Kerberos, and removing dangerous `GenericAll` rights from non-admin security groups.

Audit Your Active Directory Environment Today

Eliminate hidden Kerberos escalation paths and Active Directory misconfigurations before malicious actors discover them.

-- views
Link copied!
Lorikeet Security

Lorikeet Security Team

Penetration Testing & Cybersecurity Consulting

Lorikeet Security helps modern engineering teams ship safer software. Our work spans web applications, APIs, cloud infrastructure, and AI-generated codebases — and everything we publish here comes from patterns we see in real client engagements.

Lory waving

Hi, I'm Lory! Need help finding the right service? Click to chat!