Why case studies, not CVE dumps
Security buyers are saturated with scanner dashboards that list hundreds of findings and leave the hard question unanswered: what can an adversary actually do from here?
This article documents a composite, fully authorized engagement (names, networks, and tooling details redacted). The goal is not to teach exploitation. It is to show how AgentRidge—Azuro Software’s autonomous pentest agent— builds attack graphs: connected, validated paths from weak signals to business-critical impact.
What we show: complexity of the path, time-to-impact, and remediable outcomes.
What we deliberately omit: exact payloads, internal scripts, and module
configuration.
Engagement snapshot
| Dimension | Value (anonymized) |
|---|---|
| Engagement type | Authorized external + limited internal follow-on |
| Industry | Mid-market B2B SaaS with hybrid AD |
| Scope | Two public web apps, corporate DNS/mail footprint, in-scope AD forest |
| Rules of engagement | No destructive writes; rate-limited probing; change window notified |
| Agent mode | Pro / attacker (scoped) |
| Wall-clock to primary impact | 18 minutes from mission start to validated AD path |
| Primary outcome | Four-hop chain: public leak → identity foothold → lateral → AD control path |
The problem the client brought
The security team already ran quarterly vulnerability scans. Reports routinely flagged:
- outdated libraries on a marketing subdomain;
- “informational” TLS and header findings;
- a handful of medium CVEs that never quite justified sprint priority.
Leadership’s question was sharper: If a motivated attacker starts only from what is public, how close are we to Active Directory compromise—and how fast?
That is a path question, not a CVE count question.
What AgentRidge did differently
AgentRidge was given a mission brief: authorized targets, engagement limits, and a Definition of Done focused on demonstrable business impact with safe proof—not a raw port dump.
The agent’s behavior (observed in Mission Control) followed an attacker-shaped loop:
- Orient on public and in-scope surfaces without treating every banner as equal.
- Correlate weak signals that scanners typically file as “info.”
- Validate exploitability before promoting a finding.
- Chain validated steps into a coherent graph toward identity systems.
- Stop at proof of path under RoE—no smash-and-grab, no out-of-scope drift.
No operator sat in a terminal stitching tools by hand for this primary path. The operator supervised scope, authorization, and report acceptance.
The four-hop attack graph (sanitized)
The reconstructed path is best read as a graph of decisions, not a recipe:
[Public OSINT / exposed metadata]
│ Hop 1 — information disclosure with identity relevance
▼
[Identity-adjacent foothold on in-scope app]
│ Hop 2 — authenticated or trust-boundary crossing (validated)
▼
[Internal service with excessive trust]
│ Hop 3 — lateral movement within authorized CIDR
▼
[AD-relevant privilege path]
│ Hop 4 — control-plane exposure demonstrated safely
▼
[Domain Admin path proven · engagement halted per RoE]
Hop 1 — Public leakage that scanners under-weight
A conventional scan labeled the first signal as low/informational: exposed metadata and mis-structured public content that revealed identity and environment clues. Alone, it was not a “critical CVE.” In AgentRidge’s graph, it became the entry node because it reduced uncertainty for the next hop.
Hop 2 — Turning context into a foothold
Rather than blasting credentials or spraying blindly, the agent used the context from Hop 1 to pursue a narrow, in-scope verification against an authorized application surface. The foothold was confirmed with a non-destructive proof suitable for the report—enough for engineers to reproduce the class of issue without publishing weaponized detail.
Hop 3 — Lateral movement inside the fence
With a foothold, scanners often stop or spawn unrelated CVE noise. AgentRidge asked the attacker question: what trusts this identity or host? Within the approved internal ranges, it identified an excessively trusting service and validated a lateral step. Load stayed within engagement rate limits; no DoS behavior was used.
Hop 4 — Active Directory relevance
The fourth hop connected the lateral position to an AD-relevant privilege path. The agent demonstrated that the chain reached a control-plane impact class that would justify executive attention—then halted per rules of engagement instead of completing a noisy takeover.
Elapsed time for the validated primary chain: 18 minutes.
Secondary findings continued to accumulate afterward for the full report; the headline path was already clear.
Results & impact (what leadership cared about)
| Outcome | Detail |
|---|---|
| Narrative | From “informational leak” to “AD control path” as one story |
| Prioritization | One graph beat 200+ undifferentiated scanner rows |
| Engineering action | Three remediations mapped to specific hops (identity hygiene, trust boundary, AD exposure class) |
| Assurance | Proof of exploitability, not banner matching |
| Time value | Primary path in minutes; full PDF deliverable same engagement day |
The client’s post-engagement change was organizational as much as technical: findings without a path to impact were demoted; paths with validated hops were scheduled immediately.
What this proves about the agent
AgentRidge is not valuable because it “runs more tools.” It is valuable because it:
- Selects which weak signals deserve escalation;
- Validates before alerting;
- Composes hops into graphs that mirror how real adversaries plan;
- Stops when the business question is answered and RoE says enough.
Isolated CVEs create tickets. Attack graphs create decisions.
Limits and honesty
This write-up is a synthesized composite of authorized work. Timing and hop counts will vary by environment. AgentRidge does not replace human judgment on legal scope, production risk, or executive communication—it accelerates the technical discovery those humans must stand behind.
Exact exploits, scripts, and module knobs remain unpublished by design. The proof is the shape of the outcome, not the ammunition.
Takeaway
If your program still ranks risk by CVE severity alone, you are optimizing for scanner comfort. AgentRidge’s case for the enterprise is simpler:
Show me the shortest validated path from what is public to what would hurt— then show me how to break that path.
That is Results & Impact. Everything else is noise.
Cite this article
Azuro Consulting & Julien Mercier (2026). Four Hops to Domain Admin: How AgentRidge Chains Public Leakage into Active Directory Takeover. Azuro Insights, Azuro Software. https://insights.azurosoft.com/research/agentridge-case-study-attack-graphs-active-directory/
@techreport{azuro2026agentridgecasestudyattackgraphsactivedirectory,
title = {Four Hops to Domain Admin: How AgentRidge Chains Public Leakage into Active Directory Takeover},
author = {Azuro Consulting & Julien Mercier},
institution = {Azuro Software — Azuro Insights},
year = {2026},
url = {https://insights.azurosoft.com/research/agentridge-case-study-attack-graphs-active-directory/}
}