From Low-Privileged User to Multiple Domain Admin Paths - In Hours
- Komodo Research
- 20 hours ago
- 3 min read

How KomodoSec’s AigentX Penetration Tester and Red Teamer mapped an assumed-breach Active Directory environment, proposed an operator-approved attack plan, and autonomously demonstrated multiple routes toward full domain compromise inside a large enterprise company.
Human-controlled strategy. Autonomous execution. Evidence-backed results.
THE CHALLENGE
One ordinary domain account. Multiple routes toward Domain Admin.
AigentX was used in an authorized internal red team engagement against a large enterprise company. The assumed-breach starting point was intentionally limited: a low-privileged domain identity with access to standard domain-joined workstations.
The engagement objective was to determine how far a realistic internal attacker could progress from that foothold, including local privilege escalation, lateral movement, access to sensitive assets, and privilege escalation within Active Directory.
THE RESULT
INTERNAL RED TEAM. HOW IT WORKS
Objective-led. Human-gated before offense. Autonomous after approval.
AigentX’s Internal Red Team mode, also known as an Assumed Breach Scenario, is designed for authorized Active Directory engagements that begin from a trusted internal foothold. It starts with a trusted internal foothold and works toward the business outcomes and agreed-upon trophies defined for the engagement rather than scanning everything reachable.
VALIDATED ATTACK PATH #1
LAPS → privileged domain account → Domain Admin session → Pass-the-Hash
The primary compromise path was not a single exploit. It was a sequence of security weaknesses and trust relationships that AigentX connected into a working intrusion path.
Validated compromise chain
TECHNICAL WALKTHROUGH
Stage 1. LAPS opened the first privilege boundary
The low-privileged user could read LAPS passwords for multiple systems. After identifying an affected system and its local administrator account, AigentX used the exposed password to obtain local administrative access.
From that position, Windows registry hives were extracted and analyzed for stored credential material.
Stage 2. Credential exposure created the lateral-movement pivot
Analysis of the extracted security material revealed plaintext credentials tied to a Windows service. Those credentials belonged to a domain account with powerful access to the environment.
That account was not the Domain Admin ultimately compromised. Its importance was that it enabled the next lateral-movement step by providing local administrative access to another internal server.
Stage 3. The second server exposed the final privilege opportunity
After moving laterally, AigentX found that endpoint protection was disabled on the second server. A Domain Admin service account also had an active session on that system.
With local administrative access already established, AigentX captured LSASS memory and recovered the Domain Admin account’s NTLM hash.
Stage 4. Pass-the-Hash completed the compromise
The recovered NTLM hash was used to authenticate to the Domain Controller through Pass-the-Hash. The authentication succeeded, resulting in full compromise of the Active Directory environment.
WHY THIS CHAIN MATTERS
ATTACK PATH #2
ADCS ESC6: a separate, much shorter path toward Domain Admin
AigentX also identified an Active Directory Certificate Services misconfiguration that allowed a standard authenticated domain user to request a certificate asserting another account’s identity.
The engagement demonstrated the issue by successfully obtaining a certificate representing the built-in Administrator identity using only the original low-privileged domain account.
Demonstrated ADCS path
THE AGENTIC DIFFERENCE
The value is not running tools. It is deciding what the last result means for the next move.
AigentX is objective-led rather than coverage-led. Scope, rules of engagement, and goals remain binding. The agent first maps and prioritizes realistic attack paths, then presents the proposed offensive plan for human approval.
Only after approval does autonomous execution begin. From that point, AigentX can validate a permission issue, use the resulting access to inspect the next system, reassess the environment, and continue toward the defined objective without requiring the operator to manually drive every step.
SPEED
Work that could take a human red team roughly two weeks, compressed into hours
Internal Active Directory red teaming is inherently iterative. Each new identity or administrative foothold changes what can be reached next, requiring repeated enumeration, relationship analysis, credential validation, session review, and lateral-movement decisions.
In this case, AigentX completed the red-team workflow in a few hours. Work KomodoSec estimates could require roughly two weeks of human red-team effort.
That timing comparison is an operational estimate, not a measurement contained in the penetration-test report.
Human operators still define the engagement, approve the attack plan before offense, enforce the rules of engagement, and validate the final findings. AigentX compresses the repetitive and iterative execution between those decision points.
CONCLUSION
One foothold. Multiple Domain Admin paths.
AigentX began with a low-privileged internal domain identity, mapped and prioritized realistic attack paths, presented its offensive plan for human approval, and then executed the approved testing autonomously.
The outcome included a fully validated Domain Admin compromise through LAPS, credential exposure, lateral movement, LSASS and Pass-the-Hash; a separately demonstrated ADCS certificate path representing the built-in Administrator identity; and an additional Kerberoasting exposure affecting a Domain Admin service account.
AigentX Internal Red Team
See how far a real adversary could go from an assumed breach toward the outcomes that matter, under your rules, with your approval before offensive execution.



Comments