Autoattack
Start free

AutoAttack and Pentest Copilot on GOAD

Pentest Copilot documents multiple routes through GOAD. AutoAttack's published campaign shows how its attack chain accomplished the assigned goal.

← Research
On this page

AutoAttack directs its capabilities toward the goal you give it. That goal determines where the agent spends its time and which access matters. Finding another weakness has value when it helps accomplish the objective; expanding a findings list is no reason to spend campaign time.

For our published GOAD campaign, the objective was Domain Admin in every domain. GOAD, the Game of Active Directory lab, contains two forests, three domains and five Windows hosts. We needed to demonstrate control of NORTH, SEVENKINGDOMS and ESSOS.

BugBase's Pentest Copilot Enterprise writeup, published on 16 June 2026, presents the lab through attack-path coverage. Its account documents domain compromise and several alternative routes into the hosts. Both publications report domain control, with different routes and test conditions.

The routes Pentest Copilot published

Pentest Copilot's NORTH chain began with captured network authentication. Recovered credentials enabled access to the NORTH domain controller and extraction of domain credentials. The child-to-parent trust then provided a route to administrator access in SEVENKINGDOMS.

In ESSOS, a recovered user password enabled abuse of certificate enrollment permissions. The resulting certificate yielded ESSOS administrator credentials. The article also records SQL Server execution paths and, separately, SYSTEM-level execution through PrintNightmare on meereen.

Those are distinct results. The certificate route establishes ESSOS administrator access independently of the PrintNightmare result. The SQL paths show additional ways into systems for which the article also reports administrator access. BugBase's article explains those relationships host by host.

How AutoAttack reached the goal

Our published hardened GOAD runs followed a chain through exposed passwords and domain trusts.

An initial recovered password enabled directory access. A password exposed in a SYSVOL script then provided local administrator access to castelblack. Reading that host's stored service credentials exposed the password for NORTH\sql_svc.

The same password worked for the separate account ESSOS\sql_svc, which had Domain Admin privileges. That reuse turned access to one member server into control of another domain.

ESSOS domain access exposed the trust material used to reach SEVENKINGDOMS. Access to that forest root then enabled replication of NORTH's directory credentials. The chain had reached every domain named in the objective.

Additional SQL execution or certificate enrollment paths were unnecessary to establish that result. AutoAttack's purpose is to accomplish the assigned goal without spending time on unrelated coverage. Its capabilities serve that objective throughout the campaign.

The conditions behind the result

Our hardened GOAD deployment used Windows Server 2016 and 2019, patched through March 2026. Windows Defender was enabled on every host. LLMNR and the provisioning accounts were disabled. Each run started after a fresh VM rollback, with no supplied credentials.

Across ten runs on this configuration, AutoAttack reached Domain Admin in all three domains every time. The median time to the final domain was 51 seconds. Each run had a three-minute execution window; the 51-second figure measures the access milestone, not the whole campaign's duration. The original experiment contains the individual timings and full method.

We did not run Pentest Copilot in our lab. BugBase's article gives no campaign elapsed time, so these publications do not support a speed ranking. They describe separate experiments on GOAD, rather than a test against a shared snapshot.

For AutoAttack, the result was a demonstrated route from no supplied credentials to control of every named domain. That was the goal the campaign had to accomplish.

Start a free campaign → ← All research
Autoattack