Active Directory attack-path audits

What can one compromised user actually reach?

JC Hunt maps the relationships that turn ordinary AD access into privileged compromise—then explains the path in language your technical team and leadership can act on.

One real path. Fifteen minutes. Free. Not a full assessment.

$ path --to tier0 --shortest
illustrative path
USERj.smithCOMPROMISED
MemberOf
GROUPHelpdesk-L2
GenericAll
COMPUTERMGMT-02
HasSession
USERsvc_backup
AdminTo
TIER 0DC-01
4 relationships1 path to Tier 0CRITICAL CHAIN
ACTIVE DIRECTORYATTACK PATHSTIER 0ACLsDELEGATIONIDENTITYREMEDIATIONBLOODHOUND-LED ANALYSIS
01 / ATTACK PATHS

The finding is not the risk.

Find the path,
not the pile.

A forgotten group membership. A stale session. One permissive ACL. Alone, each can look like background noise. Chained together, they can become a route from an employee workstation to Domain Admin.

That chain is what matters. JC Hunt analyzes Active Directory as a graph of relationships—not a checklist of isolated misconfigurations—so you can see which permissions matter because of what they connect to.

Can an ordinary user reach your most privileged systems?What does one compromised workstation expose?Which relationships create the shortest path to Tier 0?
RAW RELATIONSHIPS
Domain UsersHelpdeskMGMT-02Tier 0 Session
WHAT IT MEANSA phished employee can become a privileged identity compromise.
THE FREE ENTRY POINT
ONE

real attack path.
Fifteen minutes.
Free.

This is not a teaser scan and it is not a free full assessment. I review your SharpHound data and select one meaningful, explainable path that shows how risk can compound inside your AD environment.

Then we spend 15 minutes on the path that matters: where it starts, why the chain works, what privileged target it reaches, and how I would think about breaking it.

Start the free review
02 / ZERO-FRICTION REVIEW

Three moves.
No sales maze.

Run SharpHound, send the resulting ZIP through JC Hunt's Dropbox file request, then book the 15-minute review. No account portal and no multi-step intake form.

  1. 01

    Collect

    Run SharpHound in the environment you want reviewed and keep the resulting ZIP intact.

    Standard SharpHound collection
  2. 02

    Upload

    Send the SharpHound ZIP directly through the JC Hunt Dropbox File Request.

    Dropbox handles the file transfer
  3. 03

    Debrief

    Book 15 minutes. I walk one real path from initial foothold to privileged impact.

    Board-level clarity, technical receipts

Free attack-path review

Send the data.
Book the review.

There is nothing to upload to this website. Dropbox handles the collection transfer and Cal.com handles scheduling.

Keep the handoff easy to match.
Use the same work email when you upload to Dropbox and when you book the review.
01
Run SharpHoundCollect the environment you want reviewed

Generate a standard SharpHound collection and keep the resulting ZIP intact.

02
Upload the collectionDropbox File Request

Send the SharpHound ZIP directly to JC Hunt through Dropbox. This website never receives the file.

Upload SharpHound collection
03
Book the debrief15 minutes · one attack path

After uploading, pick a time for the review. Use the same work email so I can match your booking to your collection.

Book my free review
03 / THE BROADER PICTURE

Methodology

Built around how
AD compromise actually chains.

01

Attack-path first

Relationships are evaluated in context, not as isolated red/yellow/green findings.

02

Tier 0 aware

Analysis stays anchored to privileged identity, administrative control, and the systems that define your security boundary.

03

Remediation aware

The goal is not merely to prove reachability. It is to identify where breaking a relationship meaningfully reduces exposure.

04

Explainable

Every path should survive two audiences: the engineer who needs the technical chain and the executive who needs the consequence.

04 / FAQ

The obvious
questions.

What exactly is free?+

One meaningful Active Directory attack path selected from the SharpHound collection you provide, plus a 15-minute review of that path. It is deliberately not a full AD assessment, exhaustive findings report, or remediation project.

What do I provide?+

A standard SharpHound collection ZIP for the environment you want reviewed. Upload it through the JC Hunt Dropbox File Request, then book your review through Cal.com.

Is this a vulnerability scan?+

No. The focus is attack-path context: how permissions, group membership, sessions, delegation, ACLs, identities, and systems combine into routes toward privileged compromise.

Who is this for?+

Organizations with traditional or hybrid Active Directory that want enterprise-quality identity attack-path insight without standing up a large identity security program—especially SMB and mid-market IT, security, and infrastructure teams.

What happens after the 15-minute review?+

If the path is useful, we can discuss a broader engagement to map more of the environment, identify high-value chokepoints, and prioritize remediation. If not, you still leave with one concrete path and a clearer picture of the risk.

Your AD is already a graph.

See where one path leads.

One real attack path. One focused debrief. Zero commitment.

Start free review