Prove whether an attacker can own your domain before one does
Active Directory and Entra ID are the crown of enterprise trust, and the single most common path from a foothold to full compromise. Prancer Identity runs the complete identity kill chain — anonymous enumeration to domain dominance — and shows you exactly where it breaks.
The problem
Most organizations have never had their identity fabric tested end to end. They know they should rotate krbtgt and fix delegation, but no one has proven what an attacker can actually chain together from an unauthenticated starting point. Assume-breach tabletop exercises guess. Prancer Identity demonstrates.
21+ identity capabilities
- Enumeration and credential production — anonymous LDAP/SMB enumeration, lockout-aware Kerbrute, AS-REP roasting, Kerberoasting, and LDAP password spray that respects lockout thresholds.
- Escalation and abuse — DCSync for the krbtgt hash, NTLM capture, coercion (PrinterBug, PetitPotam), relay and downgrade, ADCS ESC1–ESC15, delegation abuse (unconstrained, constrained, RBCD), LAPS and gMSA reads, shadow credentials, GPO abuse and cross-forest trust exploitation.
- Domain dominance — native pass-the-hash lateral movement across DCERPC (SCMR, WMI, DCOM, AtSvc, WSMan), Kerberos ticket forging (Golden, Silver, Diamond, Sapphire), and SAM/LSA secret extraction.
- Beyond the domain — WinRM lateral execution, the full SCCM takeover chain, and Entra ID hybrid attacks including PRT replay, Seamless-SSO silver tickets and AAD Connect / PHS sync-account compromise.
Built for safety
Zerologon and noPac are config-gated off by default, each requiring an explicit operator flag, a blast-radius declaration and an environment variable. Zerologon ships a state-restore module. Refusals surface as gated-capability notices, never silent skips.
What you get
Every proven step arrives with captured evidence, graded for authenticity, mapped to MITRE ATT&CK, and delivered as an OCSF report plus an interactive attack-path graph walking the chain from anonymous access to domain dominance. Captured secrets pass through in full so your team can verify and rotate immediately.
Related reading
- Active Directory capability detail — the full technique breakdown.
- Prancer Core — the surface that produces the first foothold.
- Tutorial: AD attacks — run an internal engagement step by step.