Just Released!
Real-time threat detection and change monitoring with single pane‑of‑glass visibility across AD and Entra ID.
Threat Directory
Welcome to the Cayosoft Threat Directory— a continuously updated hub of intelligence on hybrid identity attack techniques and detection patterns. It’s designed to empower security teams to turn alerts into actionable insights with detailed remediation steps, enabling fast, confident response across Active Directory, Entra ID, Intune, and Microsoft 365.
Windows Local Administrator Password Solution (Windows LAPS) helps protect local administrator accounts by automatically rotating passwords and backing them up to Windows Server Active Directory or Microsoft Entra ID. Windows LAPS is built into supported Windows 10, Windows 11, and Windows Server versions that have the April 11, 2023 update or later.
If Windows LAPS is not configured, if the required policy is missing, or if Active Directory prerequisites are incomplete, local administrator passwords might not be rotated or backed up securely. This can leave devices using static or reused local administrator passwords and increase the risk of credential reuse, pass-the-hash attacks, and lateral movement.
For Active Directory backup, the Windows LAPS schema attributes must be added to the forest. To use encrypted password storage in Active Directory, the domain must run at Windows Server 2016 domain functional level or later. Hybrid-joined devices can back up Windows LAPS passwords to either Microsoft Entra ID or Windows Server Active Directory, but not both.
Legacy Microsoft LAPS is deprecated on newer Microsoft operating systems. Organizations should plan migration to Windows LAPS to use modern capabilities such as native OS support, password encryption in Active Directory, password history, and Microsoft Entra ID integration.
Active Directory Certificate Services (AD CS) is a critical identity infrastructure component used to issue and manage certificates. If AD CS auditing is not configured, certificate requests, issuance, revocation, configuration changes, and access attempts may not be logged. As a result, malicious or unauthorized certificate operations may go undetected, increasing the risk of privilege escalation, credential theft, and persistence.
For example, an attacker who compromises a user account could abuse a misconfigured certificate template to request a certificate that can be used for authentication as a privileged identity. Without AD CS auditing, this certificate request and issuance may not be recorded, making the activity difficult to detect, investigate, or report for compliance purposes.
Using passwords that match the samAccountName creates a predictable and vulnerable login combination. Attackers commonly attempt such patterns during brute-force or dictionary attacks to compromise user accounts.
Cayosoft detects and alerts when an account's password hash matches a hash derived from its samAccountName, signaling the use of weak, easily deducible credentials.
Cayosoft Guardian is designed with strict security principles to protect sensitive credential data within customer environments. Cayosoft Guardian does not store or transmit password hashes. All password-related comparison operations are executed locally on your domain controllers, ensuring that password hashes remain within your secure environment and are never sent to the internet or external systems.
This architecture ensures that password hashes are not collected, exported, or exposed outside your Active Directory domain controllers during backup, recovery, or change monitoring operations.
This indicator looks for principals (computers or users) that have constrained delegation enabled for a service running on a domain controller. If an attacker can create such a delegation, they can authenticate to that service using any user that is not protected against delegation.
A threat actor can gain control over a domain controller service account configured for constrained authentication delegation and exploit this access to escalate privileges within the network. By compromising this service account, which is trusted for constrained authentication delegation, the threat can impersonate users and access sensitive resources as specified by the delegation settings. This level of control can be leveraged to perform lateral movements, escalate privileges, and potentially gain domain administrator rights, thus significantly compromising the security and integrity of the entire network.
This rule checks if the domain's federation settings were recently modified.
When you federate your on-premises environment with Microsoft Entra ID, you establish a trust relationship between the on-premises identity provider and Microsoft Entra ID.
Due to this established trust, Microsoft Entra ID honours the security token issued by the on-premises identity provider post-authentication, to grant access to resources protected by Microsoft Entra ID. A malicious user might modify federation settings to get access to resources in Microsoft Entra ID.
In Active Directory, computer objects, including Delegated Managed Service Accounts (dMSAs), are securable and governed by Access Control Lists (ACLs). Improper delegation of permissions at the Organizational Unit (OU) level can allow unprivileged users to gain write access to these sensitive objects.
Windows Server 2025 introduces the msDS-DelegatedManagedServiceAccount class, which enables new service account capabilities, including successor inheritance. This functionality, while powerful, can be abused to simulate a migration from a privileged identity, allowing an attacker to craft a dMSA that inherits the access of a privileged account without needing to compromise the original.
Cayosoft Guardian considers both direct and indirect (nested) group permissions when evaluating risks. If a regular user is granted permissions such as GenericWrite, WriteDacl, or WriteProperty on OUs containing dMSAs, they could exploit this to escalate privileges, evade detection, and maintain long-term persistence.
NOTE: This threat applies only in environments with at least one Windows Server 2025 Domain Controller and the corresponding schema upgrade, which introduces the msDS-DelegatedManagedServiceAccount object class.
This can include promoting itself or other service principals to members of privileged roles, such as administrators or owners. This means that a threat actor who has gained access to a previously created service principal with the 'AppRoleAssignment.ReadWrite.All' permission could use it to persist in the environment and elevate their privileges when needed.
The Common Vulnerabilities and Exposures (CVEs) CVE-2021-42278 and CVE-2021-42287 are security flaws that can be exploited by a threat actor who has obtained access to low-privileged domain user credentials. These vulnerabilities enable the attacker to obtain a Kerberos Service Ticket for a Domain Controller computer account, which provides elevated privileges within a domain.
This escalation of privileges enables the attacker to take control of the domain controller, thereby compromising the security of the entire domain. The domain controller is a critical component of a Windows domain-based network and has a crucial role in managing and enforcing security policies, as well as controlling access to network resources.
Therefore, exploitation of these vulnerabilities can have serious consequences for organizations that are running vulnerable systems, including data breaches, unauthorized access to sensitive information, and the spread of malware. It is highly recommended that organizations apply the necessary patches and updates to protect their systems against these vulnerabilities.
A Microsoft Entra tenant configured to allow partner access through Delegated Administrative Privileges (DAP) poses a high-severity threat if not tightly monitored and restricted. This access model grants external partners elevated rights within the tenant, potentially including Global Administrator or other privileged roles.
The existence of DAP allows a partner organization to act on behalf of your tenant without needing per-activity approval or just-in-time access, which increases the attack surface. If a partner organization is compromised or acts maliciously, the threat actor could gain control over sensitive resources within your environment, bypass Conditional Access policies, or disable security configurations.
Furthermore, partner access may not show up in standard user audit logs, complicating the detection of misuse. If DAP accounts are unnecessary, it is highly recommended to eliminate them and implement Least Privilege Access, opting for more secure alternatives like Granular Delegated Admin Privileges (GDAP) instead.
Multiple failed authentication attempts from invalid users via NTLM might be an indication of a threat actor performing a Password Spraying attack against an Active Directory environment to obtain initial access or elevate privileges. Detection mechanism uses the event 4776 and error code 0xC0000064 meaning that `The username you typed does not exist` (the attempted user is a legitimate domain user).
NOTE: This threat rule includes a built-in lookback parameter set to 25 hours. Only events that occurred within this timeframe are processed by the rule.
If one source endpoint tries to authenticate with different unique user accounts using the Kerberos protocol, it might be a threat actor performing a Password Spraying attack against an Active Directory environment. The detection mechanism uses native events from Security Log. The event 4771 is generated when the Key Distribution Center fails to issue a Kerberos Ticket Granting Ticket (TGT) and failure code 0x18 means `wrong password provided` while the attempted user is a legitimate domain user.
NOTE: This threat rule includes a built-in lookback parameter set to 25 hours. Only events that occurred within this timeframe are processed by the rule.
Encrypting Active Directory backups adds an extra layer of security to sensitive data like user credentials, group policies, and other sensitive data. Encrypting backups ensures that even if threat actors gain access to the backup files, they won't be able to read or misuse the information.
Encrypted backups are much safer in the event of a data breach. Even if threat actors manage to access the backup files, they won't be able to decipher the information without the encryption key, minimizing the impact of the breach. In addition, they guard against insider threats. Even employees with access to backup files won't be able to misuse the data if it's encrypted without the necessary decryption keys.
When transferring backup files over networks or storing them in cloud services, encryption ensures that the data remains secure throughout the transmission and storage, protecting it from interception or unauthorized access.
A threat actor with permissions to link Group Policy objects at the AD site, Domain controllers OU, or domain can elevate their permissions.
NOTE: Cayosoft Guardian considers both direct and indirect (nested) group permissions when evaluating risks. Privileged users are defined in Active Directory as users with AdminCount=1. By design, Active Directory uses this attribute to protect members of administrative groups.
According to security best practices, it is not recommended to reuse admin accounts; instead, these accounts must be de-provisioned. If an account has administrative permissions, it may also gain access to other resources using these permissions and retain this access even after it is removed from the administrative groups. Learn more about AdminSdHolder and SDProp - Microsoft Community Hub.
If one source endpoint tries to authenticate with different unique user accounts against a single domain controller, it might be a threat actor performing a Password Spraying attack against an Active Directory environment. The detection mechanism uses native events from Security Log. The event 4625 documents failed attempts to log on to the computer and Logon Type value 3 describes a remote authentication attempt.
NOTE: This threat rule includes a built-in lookback parameter set to 25 hours. Only events that occurred within this timeframe are processed by the rule.
In a hybrid scenario, identities are synchronized from the on-premises AD to Microsoft Entra ID, with the on-premises AD being the authoritative source. Normally, lateral movement from the compromised on-premises AD to Microsoft Entra ID is more common, as information flows from on-premises to the cloud.
However, the Cloud Kerberos Trust model creates trust from the on-premises AD to Microsoft Entra ID, allowing authentication based on information from Microsoft Entra ID. A threat actor who obtains Global Admin privileges in Microsoft Entra ID can abuse this trust to escalate their privileges to Domain Admin. This means that the attacker, starting with control over Microsoft Entra ID, can gain control over the on-premises AD and potentially compromise the entire environment.
NOTE: Cayosoft Guardian defines privileged users in Active Directory as users with adminCount=1. By design Active Directory uses this attribute to protect members of administrative groups.
According to security best practices it is not recommended re-using admin accounts, instead these accounts must be de-provisioned. If an account has administrative permissions, it might also obtain access to other resources using these administrative permissions and keep this access even after it is removed from the administrative groups. Learn more about AdminSdHolder and SDProp - Microsoft Community Hub.
Failed logon attempts with multiple disabled domain users might be an indication of a threat actor trying to perform a Password Spraying attack against an Active Directory environment using Kerberos to obtain initial access or elevate privileges. The detection mechanism uses the event 4768 with the failure code 0x6 stands for `client not found in Kerberos database` (the attempted user is not a valid domain user).
NOTE: This threat rule includes a built-in lookback parameter set to 25 hours. Only events that occurred within this timeframe are processed by the rule.
Read-Only Domain Controllers (RODCs) in an inconsistent state pose significant risks to the integrity and security of an Active Directory environment. RODCs are intended to provide a read-only replica of the Active Directory database, often in less secure locations. Inconsistent states due to replication failures, partial updates, or misconfigurations, can lead to outdated or incorrect data being served to clients, undermining authentication, authorization, and policy application. Additionally, threat actors may exploit this inconsistency to escalate privileges, bypass security controls, or compromise sensitive credentials cached on the RODC.
Unauthorized changes to compliance policies weaken your organization's security by potentially allowing non-compliant or compromised devices to access corporate resources. Such changes may indicate that a threat actor has gained administrative access and is attempting to bypass security controls. Monitoring compliance policy changes ensures that the integrity of your device management environment remains intact.
A threat actor who gains administrative access could alter compliance policies to reduce security requirements, allowing non-compliant devices (such as those lacking encryption or updated software) to access critical systems. By detecting these unauthorized changes, the organization can quickly respond and restore secure policies, mitigating the risk of compromised devices accessing sensitive resources.
A threat actor who gains access to an Exchange Online mailbox may create multiple inbox rules to conceal emails - tactics commonly used in Business Email Compromise (BEC) attacks to evade detection and maintain access.
The threat is detected based on the creation of multiple new inbox rules in a given period of time.
Detection is scheduled to run regularly across all Entra tenants and will trigger an alert when particular number of new inbox rules are created in a particular period of time. Both the minimum rules number and the time period are adjustable in the Rule settings.
A threat actor who gains access to an Exchange Online mailbox may create a new inbox rule to delete, move, or forward incoming emails - tactics commonly used in Business Email Compromise (BEC) attacks to evade detection and maintain access.
The threat is detected based on the creation of new inbox rules that meet any of the following criteria:
- Move emails to Deleted Items
- Mark emails as Read
- Forward emails to external domains
Detection is scheduled to run regularly across all Entra tenants and will trigger an alert when:
- A new inbox rule with one or more of the above suspicious actions is created
- The rule is created by someone other than the mailbox owner (e.g., via delegated access or compromised credentials)
NOTE: This threat rule includes a built-in lookback parameter set to 25 hours. Only events that occurred within this timeframe are processed by the rule.
A threat actor who gains access to an Exchange Online mailbox may create a new inbox rule to delete, move, or forward incoming emails - tactics commonly used in Business Email Compromise (BEC) attacks to evade detection and maintain access.
The threat is detected based on the creation of new inbox rules that meet any of the following criteria:
- Move emails to Deleted Items
- Mark emails as Read
- Forward emails to external domains
Detection is scheduled to run regularly across all Entra tenants and will trigger an alert when:
- A new inbox rule with one or more of the above suspicious actions is created
- The rule is created by someone other than the mailbox owner (e.g., via delegated access or compromised credentials)
NOTE: This threat rule includes a built-in lookback parameter set to 25 hours. Only events that occurred within this timeframe are processed by the rule.
Bulk device wipes executed within a short time frame pose a serious threat to an organization's devices and data integrity. If an attacker gains access to administrative credentials, they could carry out large-scale wipes to eliminate evidence or disrupt business operations. This rule identifies instances where more than N device wipe or reset actions occur within a default 10-minute window (with both the value of N defaulting to 3 and the time interval set in the threat settings). Such activity is unusual and may indicate a coordinated attack targeting multiple devices.
If a threat actor gains access to administrative credentials, they could initiate multiple device wipes at the same time, resulting in significant data loss and operational disruption. In this situation, the malicious actor can erase several devices simultaneously, complicating efforts to recover data or track their activities. Early detection of bulk device wipes is crucial, as it minimizes the potential for widespread impact. This allows security teams to intervene and mitigate the damage before it spreads throughout the network.
NOTE: This threat rule includes a built-in lookback parameter set to 25 hours. Only events that occurred within this timeframe are processed by the rule.
When a device is successfully enrolled in Intune but never performs a compliance check-in, it may indicate one of the following: the management agent failed to initialize, the user uninstalled the MDM profile, or the device was enrolled solely to satisfy Conditional Access requirements and was subsequently abandoned or hidden from management.
This rule detects Kerberos pre-authentication failures targeting a honey account. Such failures may indicate that an attacker is attempting to brute-force credentials or enumerate accounts using Kerberos authentication. Monitoring failed attempts against decoy (honey) accounts can help identify suspicious activity before real accounts are compromised.
For more information, see Microsoft's documentation on Event ID 4771 - Kerberos pre-authentication failed.
A threat actor who gains access to an Exchange Online mailbox may create a new inbox rule to delete, move, or forward incoming emails - tactics commonly used in Business Email Compromise (BEC) attacks to evade detection and maintain access.
The threat is detected based on the creation of new inbox rules that meet any of the following criteria:
- Move emails to Deleted Items
- Mark emails as Read
- Forward emails to external domains
Detection is scheduled to run regularly across all Entra tenants and will trigger an alert when:
- A new inbox rule with one or more of the above suspicious actions is created
- The rule is created by someone other than the mailbox owner (e.g., via delegated access or compromised credentials)
NOTE: This threat rule includes a built-in lookback parameter set to 25 hours. Only events that occurred within this timeframe are processed by the rule.
Bulk changes might be a result of threat activities. Also, it could be a mistake. Deletions or modifications of Microsoft Entra objects can lead to service outages.
NOTE: This threat rule includes a built-in lookback parameter set to 25 hours. Only events that occurred within this timeframe are processed by the rule.
A regular user account or group with an AdminCount attribute set to any value might indicate potential threat activities. In particular, accounts with AdminCount=1 do not inherit permissions from parent containers. Active Directory employs the AdminSDHolder object, protected groups, and the Security Descriptor Propagator (SDProp) to safeguard privileged users and groups. SDProp is a process that runs every 60 minutes by default on the domain controller hosting the domain's PDC Emulator (PDCE). During this process, SDProp compares the permissions on the domain's AdminSDHolder object with those on the protected accounts and groups. If there is a discrepancy, SDProp resets the permissions on the protected accounts and groups to match those of the AdminSDHolder object.
An unexpected AdminCount value in a regular object may indicate potential threat activities. User accounts with previous administrative permissions should not be reused and should be deprovisioned.
NOTE: Cayosoft Guardian considers both direct and indirect (nested) group permissions when evaluating risks. Privileged groups are defined in Active Directory as groups with adminCount=1 and a well-known Security Identifier (SID). Any potential target objects are identified as members (including indirect ones) of previously identified built-in privileged groups. By design, Active Directory uses this attribute to protect members of administrative groups.
According to security best practices, it is not recommended to reuse admin accounts; instead, these accounts must be de-provisioned. If an account has administrative permissions, it may also gain access to other resources using these permissions and retain this access even after it is removed from the administrative groups. Learn more about AdminSdHolder and SDProp - Microsoft Community Hub.
In certain scenarios, threat actors who have gained control of a domain controller in a trusted domain can exploit the SID history attribute (sIDHistory) to associate SIDs with new user accounts, thereby granting themselves unauthorized access. SID filter quarantining is enabled by default on all external trusts to mitigate this risk. This security feature ensures that only SIDs from the directly trusted domain or forest are considered valid by removing any SID references that do not pertain to them from inbound access requests.
However, administrators can turn off this setting, and older Active Directory trusts may not enable SID filtering. Threat actors can insert spoofed SIDs into access requests without SID filtering, potentially gaining unauthorized access. While SID filtering significantly enhances security by blocking such attacks, it can also cause operational issues if legitimate access relies on SID history or Universal Groups, potentially leading to denied access.
Enabling SID filter quarantining on a trust relationship restricts the trust to the specific domains on either side, breaking its transitivity. This means only SIDs from the directly trusted domain are valid, strengthening security by ensuring only authorized SIDs are accepted.
Passwords in Group Policy Preferences (GPP) Compromise refers to a security vulnerability that occurs when Group Policy Preferences (GPP) in Active Directory are used to configure settings like local user accounts or service accounts, and passwords are stored in GPP XML files. These passwords are often stored in plain text or are weakly encrypted using a reversible encryption scheme. Attackers can exploit this vulnerability by accessing these files (typically found in SYSVOL, which is accessible to all domain users), decrypting the password, and using it to gain unauthorized access to privileged accounts or systems.
Microsoft has since disabled the use of passwords in GPP, but the vulnerability still poses a risk in environments where legacy GPP settings or files may exist. If the password field is empty, no alert should be triggered; alerts should only occur when the password field contains an actual password.
The Migrate sIDHistory permission in Active Directory allows an account to add or modify the sIDHistory attribute of a user or group. Delegating this permission to a regular user poses significant security threats. A threat actor can exploit this by migrating the SID of a high-privilege account into their own account, effectively gaining the same access rights and privileges. They can also add SIDs to access restricted resources, maintain persistence by hiding elevated privileges in a stealthy account, and evade security monitoring by masking their activities.
To mitigate these risks, restrict sIDHistory permissions to trusted administrative accounts, conduct regular audits, and monitor changes to the sIDHistory attribute.
NOTE: Cayosoft Guardian defines privileged users in Active Directory as users with adminCount=1. By design, Active Directory uses the attribute to protect members of administrative groups.
According to security best practices, it is not recommended to re-use admin accounts. Instead, these accounts must be de-provisioned. If an account has administrative permissions, it might also obtain access to other resources using these administrative permissions and keep this access even after it is removed from the administrative groups. Learn more about AdminSdHolder and SDProp - Microsoft Community Hub.
NOTE: Cayosoft Guardian defines privileged users in Active Directory as users with adminCount=1. By design Active Directory uses this attribute to protect members of administrative groups.
According to security best practices it is not recommended re-using admin accounts, instead these accounts must be de-provisioned. If an account has administrative permissions, it might also obtain access to other resources using these administrative permissions and keep this access even after it is removed from the administrative groups. Learn more about AdminSdHolder and SDProp - Microsoft Community Hub.
Bulk changes might be a result of threat activities. Also, it could be a mistake. Deletions or modifications of AD objects can lead to service outages.
NOTE: This threat rule includes a built-in lookback parameter set to 25 hours. Only events that occurred within this timeframe are processed by the rule.
Bulk changes might be a result of threat activities. Also, it could be a mistake. Deletions or modifications of AD objects can lead to service outages.
NOTE: This threat rule includes a built-in lookback parameter set to 25 hours. Only events that occurred within this timeframe are processed by the rule.
Bulk changes might be a result of threat activities. Also, it could be a mistake. Deletions or modifications of Microsoft Entra objects can lead to service outages.
NOTE: This threat rule includes a built-in lookback parameter set to 25 hours. Only events that occurred within this timeframe are processed by the rule.
When multiple accounts share the same password, it significantly increases the risk of lateral movement in the event of a compromise. If a single account is breached, identical passwords allow attackers to access other accounts without additional effort.
Cayosoft analyzes password hashes, and when identical hashes are detected across accounts, it flags them as duplicate passwords to encourage the use of unique, strong credentials for each account.
Duplicate password detection operates across all managed domains in Guardian. We do not expose the specific user accounts with duplicate passwords to further protect sensitive information.
Cayosoft Guardian is designed with strict security principles to protect sensitive credential data within customer environments.
Cayosoft Guardian does not store or transmit password hashes. All password-related comparison operations are executed locally on your domain controllers, ensuring that password hashes remain within your secure environment and are never sent to the internet or external systems.
This architecture ensures that password hashes are not collected, exported, or exposed outside your Active Directory domain controllers during backup, recovery, or change monitoring operations.
The 'Return of Coppersmith's attack' or ROCA vulnerability is a cryptographic weakness in a widely used cryptographic library. A threat actor can get access to secret keys using this library and use this keys for authentication. Domain controllers should be configured to block authentications with such vulnerable keys.
Anomalous account creation can indicate a potential security issue, especially when accounts are created outside of expected processes. Alerts are triggered when account creation records are detected that were not made by a known initiator with more than two weeks of inactivity. Note that after two weeks of inactivity, any inactive known initiators are removed from the "known initiators" list.
NOTE: This threat rule includes a built-in lookback parameter set to 12 hours. Only events that occurred within this timeframe are processed by the rule.
Multicast Name Resolution (LLMNR) is a legacy protocol for name resolution in networks without DNS servers. In an Active Directory domain, LLMNR can expose the environment to spoofing and credential-harvesting attacks, such as responder attacks. Attackers can intercept and manipulate LLMNR requests to gain user credentials or redirect traffic.
Disabling LLMNR mitigates these security risks by preventing unauthorized interception of name resolution requests. However, this change may impact legacy applications or older systems that rely on LLMNR or NetBIOS for network communication.
This detection identifies Conditional Access policies that include private IP address ranges (for example, 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) in Named Locations. Because these ranges are non-routable and not globally unique, they provide an unreliable basis for enforcing access control boundaries.
Such configurations may enable threat actors to bypass Conditional Access restrictions if they are:
- Operating from within corporate or partner networks,
- Spoofing internal IPs through VPNs, or
- Leveraging misconfigured proxies.
In addition, Microsoft Entra ID does not natively resolve internal IP addresses to hostnames, nor does it differentiate between multiple users behind a NAT device. As a result, private IP ranges are unsuitable for precise or secure access enforcement.
This detection identifies valid internal domain suffixes used in Entra user and tenant objects and checks whether any of these domains appear in known public breaches using the HaveIBeenPwned (HIBP) domain search API. Public email providers are excluded from the threat settings' predefined list.
When a matching breach is found, Cayosoft Guardian evaluates only breaches that include compromised passwords, ensuring results are limited to cases where user credentials were actually exposed. For each affected user, Cayosoft Guardian compares the breach data with the date the user last changed their password. If the password has never been changed or was last changed before the breach date, an alert is triggered.
If internal domains are found in breach data containing compromised passwords, and affected users have not rotated their credentials since the breach, this represents a significant threat vector. Compromised credentials may be exploited for phishing, credential stuffing, or unauthorized access.
This detection enables organizations to proactively assess and mitigate domain-level exposure risks by identifying users whose passwords remain vulnerable after a known breach.
This detection identifies valid internal domain suffixes used in Entra user and tenant objects and checks whether any of these domains appear in known public breaches using the HaveIBeenPwned (HIBP) domain search API. Public email providers are excluded from the threat settings' predefined list.
When a matching breach is found, Cayosoft Guardian evaluates only breaches that include compromised passwords, ensuring results are limited to cases where user credentials were actually exposed. For each affected user, Cayosoft Guardian compares the breach data with the date the user last changed their password. If the password has never been changed or was last changed before the breach date, an alert is triggered.
If internal domains are found in breach data containing compromised passwords, and affected users have not rotated their credentials since the breach, this represents a significant threat vector. Compromised credentials may be exploited for phishing, credential stuffing, or unauthorized access.
This detection enables organizations to proactively assess and mitigate domain-level exposure risks by identifying users whose passwords remain vulnerable after a known breach.
PowerShell is a legitimate administrative and automation framework, but it is frequently exploited by attackers using tools such as Mimikatz, PowerView, Empire, and Cobalt Strike. When PowerShell Script Block Logging and Module Logging are disabled, malicious activity executed through PowerShell remains invisible to security monitoring solutions such as SIEM and EDR platforms.
Enabling comprehensive PowerShell logging through Group Policy ensures that all script executions—including obfuscated, encoded, or dynamically generated commands - are captured in the Windows Event Log (Event IDs 4103 and 4104). These logs provide critical telemetry for identifying suspicious activity, enabling timely investigation, threat hunting, and detection of advanced adversary techniques.
The activity where a sign-in from a Global Administrator account in Entra ID has been detected is considered a high-risk security event. Global Administrator accounts have unrestricted privileges across the tenant, making them prime targets for threat actors attempting to obtain full control over cloud resources and identity infrastructure. Any unexpected or unusual sign-in activity involving these accounts may indicate credential compromise or malicious reconnaissance and should be investigated promptly.
This activity warrants immediate scrutiny - especially if it occurs:
- Outside of normal business hours,
- From an unusual or untrusted geographic location or IP address,
- On an unfamiliar device or user agent, or
- Following a prolonged period of account inactivity.
Such anomalies may indicate account compromise, credential theft, or early-stage reconnaissance by an adversary. Unauthorized access to a Global Admin account can rapidly lead to full tenant takeover, configuration tampering, and lateral movement across integrated services.
Organizations must treat all Global Admin sign-ins as high-risk events until verified. Proactive mitigation includes enforcing strict Conditional Access policies (e.g., requiring MFA, compliant devices, and named locations), implementing just-in-time access via Privileged Identity Management (PIM), and maintaining vigilant monitoring through Microsoft Entra ID Protection and audit logs. Rapid validation and response are essential to prevent catastrophic cloud environment compromise.
NOTE: This threat rule includes a built-in lookback parameter set to 25 hours. Only events that occurred within this timeframe are processed by the rule.
A password reset or account unlock for a privileged account can indicate a security incident when it occurs outside an approved change window, is performed by an unexpected initiator, or is not supported by an authorized change request. These actions can restore access to an account that was locked, disabled, or previously compromised.
If abused, a privileged reset/unlock can enable privilege escalation, credential abuse, and lateral movement. For example, an attacker with access to helpdesk workflows may reset a highly privileged account (such as a domain admin) and use the new credentials to access sensitive systems and make follow-on changes.
Threat actors are known to target service desk processes using social engineering to trigger unauthorized password resets and unlocks. Campaigns associated with groups such as Scattered Spider have specifically leveraged helpdesk interaction to obtain password resets (and related identity control changes) to facilitate account takeover.
NOTE: Cayosoft Guardian defines privileged users in Active Directory as users with adminCount=1. By design Active Directory uses this attribute to protect members of administrative groups.
According to security best practices it is not recommended re-using admin accounts, instead these accounts must be de-provisioned. If an account has administrative permissions, it might also obtain access to other resources using these administrative permissions and keep this access even after it is removed from the administrative groups. Learn more about AdminSdHolder and SDProp - Microsoft Community Hub.
NOTE: This threat rule includes a built-in lookback parameter set to 25 hours. Only events that occurred within this timeframe are processed by the rule.
A password reset for a privileged account can indicate a security incident when it occurs outside an approved change window, is performed by an unexpected initiator, or is not supported by an authorized change request. These actions can restore access to an account that was locked, disabled, or previously compromised.
If abused, a privileged reset can enable privilege escalation, credential abuse, and lateral movement. For example, an attacker with access to helpdesk workflows may reset a highly privileged account (such as a Global admin) and use the new credentials to access sensitive systems and make follow-on changes.
Threat actors are known to target service desk processes using social engineering to trigger unauthorized password resets. Campaigns associated with groups such as Scattered Spider have specifically leveraged helpdesk interaction to obtain password resets (and related identity control changes) to facilitate account takeover.
NOTE: This threat rule includes a built-in lookback parameter set to 25 hours. Only events that occurred within this timeframe are processed by the rule.
A user may be assigned both the Organizational Messages Writer and Organizational Messages Approver roles in Microsoft Entra ID. This removes dual control, a key security principle, and allows the same identity to both create and approve organizational messages without independent review.
An intentional or compromised account with both roles could publish misleading or malicious organizational messages to users without oversight.
NTLM is a legacy authentication protocol that is susceptible to credential relay, brute-force attacks, and lateral movement. If NTLM auditing is not enabled, administrators may not be able to identify systems, applications, or accounts that still rely on NTLM authentication.
A threat actor can exploit NTLM-dependent systems to relay credentials, access resources, and move laterally across the environment. Enabling NTLM auditing helps organizations detect NTLM usage before restricting or blocking NTLM authentication.
This threat identifies an Intune tenant where no Multi Admin Approval access policies are configured.
Without Multi Admin Approval access policies, a compromised or malicious administrator account can perform sensitive actions without independent validation.
For example, if a threat actor compromises an Intune administrator account and no Multi Admin Approval access policies exist, the attacker could deploy a malicious line-of-business app, weaken compliance requirements, or initiate device wipe actions without approval from another administrator.
This threat identifies Active Directory security principals, such as users, computer objects, and service accounts, that either currently have RC4-HMAC enabled (indicator of exposure) or were recently modified to enable RC4-HMAC through changes to the msDS-SupportedEncryptionTypes attribute (indicator of attack).
RC4 is deprecated, cryptographically weak, and commonly associated with attacks such as password cracking, Kerberoasting, and forged Kerberos tickets. Enabling RC4-HMAC may indicate an encryption downgrade attempt in which an adversary weakens Kerberos protections to obtain service tickets that are easier to crack.
In Active Directory, Service Connection Points (SCPs) are special objects that help domain-joined devices discover services such as Configuration Manager, Exchange Autodiscover, and custom applications. These SCPs are stored in the System container and can include connection details such as server names, ports, and protocols. To function correctly, clients must be able to trust the information stored in these SCPs.
A common security oversight is applying overly permissive Access Control Lists (ACLs) to these objects, allowing broad groups such as Authenticated Users or Domain Users to modify them. This is risky because attackers who gain access to a standard user account can exploit these permissions to change SCP values—especially attributes such as serviceBindingInformation. By doing so, they can redirect domain-joined clients to attacker-controlled systems that clients may trust implicitly. As a result, clients may unknowingly send credentials, sensitive data, or service traffic to rogue endpoints, enabling man-in-the-middle (MitM) attacks, credential theft, and lateral movement across the environment.
This detection identifies Conditional Access policies in Entra ID that do not enforce Continuous Access Evaluation (CAE). CAE enables near real-time policy enforcement by revoking tokens when events such as user disablement, location changes, or role elevation occur.
Without CAE, OAuth access and refresh tokens remain valid until their expiration, even if a user's risk state or session conditions change. This extends the window for attackers to maintain access after privilege elevation or credential compromise.
A threat actor with permissions to modify schema might compromise your Active Directory forest or make it inoperable.
Accounts with blank passwords pose a critical security risk. Without any form of authentication, these accounts are highly vulnerable to unauthorized access. Attackers can easily exploit such accounts to bypass password policies, gain access to sensitive data, and escalate privileges within the environment.
Cayosoft identifies accounts with empty password fields and flags them to ensure that no user account remains unsecured due to the absence of a password.
Cayosoft Guardian is designed with strict security principles to protect sensitive credential data within customer environments. Cayosoft Guardian does not store or transmit password hashes. All password-related comparison operations are executed locally on your domain controllers, ensuring that password hashes remain within your secure environment and are never sent to the internet or external systems.
This architecture ensures that password hashes are not collected, exported, or exposed outside your Active Directory domain controllers during backup, recovery, or change monitoring operations.
Honey accounts are non-operational, decoy accounts intentionally created to attract and monitor unauthorized access attempts by threat actors. A series of failed logon attempts targeting these accounts may indicate brute-force attacks, reconnaissance activity, or the presence of an unauthorized user probing the environment. Such activity often precedes lateral movement or privilege escalation attempts. Because honey accounts are not used in legitimate operations, any authentication attempt against them is considered inherently suspicious.
For more information, see Microsoft's documentation on Event ID 4625 - An account failed to log on..
NOTE: This threat rule includes a built-in lookback parameter set to 25 hours. Only events that occurred within this timeframe are processed by the rule.
A threat actor can exploit weak or vulnerable certificates by exploiting several inherent weaknesses, particularly random number generation, key size, and susceptibility to side-channel attacks. Replacing vulnerable keys with more modern and secure cryptographic algorithms mitigates these risks. To secure your environment, it’s essential to phase out secure certificates, revoke any currently issued weak certificates, and replace them with certificates using stronger algorithms and key sizes.
Misconfigured permissions on certificate templates for Windows authentication can pose significant security risks. If unprivileged users are granted permission to request certificates where they can supply arbitrary subject information, they could potentially obtain certificates for any user, including high-privilege accounts like domain admins.
To mitigate this risk, reviewing and adjusting the delegations on these certificate templates is crucial. Specifically, ensure that permissions are not granted to broad groups such as Authenticated Users, Domain Users, or Domain Computers. Instead, permissions should be limited to specific, trusted accounts, and additional security measures should be implemented, such as manager approval or required authorized signatures.
An Active Directory object with privileged SIDs in its sIDHistory attribute might be an indication of the threat actor's activities.
SID (Security Identifier) is a unique identifier that Active Directory uses to identify objects as security principals in security descriptors and access tokens. In most cases, the SID History attribute is only populated with SIDs during migrations. SID History injection is an attack technique that allows a threat actor to add privileged SIDs to regular accounts and escalate privileges. For example, adding Enterprise Admin SID in the SID History of a regular user allows elevating access for the user account to an effective Domain Admin in all domains in the forest.
NOTE: Cayosoft Guardian defines privileged users in Active Directory as users with adminCount=1. By design Active Directory uses this attribute to protect members of administrative groups.
According to security best practices it is not recommended re-using admin accounts, instead these accounts must be de-provisioned. If an account has administrative permissions, it might also obtain access to other resources using these administrative permissions and keep this access even after it is removed from the administrative groups. Learn more about AdminSdHolder and SDProp - Microsoft Community Hub.
Accounts that do not use multi-factor authentication (MFA) are vulnerable to modern identity-based attacks. Password-only authentication provides insufficient protection against threats such as phishing, password spraying, and credential reuse.
Administrative accounts without MFA pose a high risk. If compromised, attackers can establish persistence, access sensitive data, escalate privileges, and cause significant damage within the environment.
Microsoft reports that MFA blocks more than 99.9% of account compromise attempts. MFA enhances security by requiring an additional verification step during sign-in, such as a one-time passcode, push notification, or biometric factor. Even if a password is exposed, MFA significantly reduces the likelihood of unauthorized access.
Where supported and enabled, remediation for this threat may be automated to help ensure MFA enforcement. For more information, view the automated remediation section in the Remediation advice tab. Otherwise, this threat provides visibility and guidance for manual remediation.NOTE: This threat definition supports only Microsoft's native MFA. Accounts protected by third-party MFA providers—such as Okta, Duo Security, Ping Identity, RSA SecurID, OneLogin, or CyberArk Identity—may be flagged as lacking MFA.
If your organization uses third-party MFA, consider disabling this threat or configuring exceptions to prevent false positives.
Kerberoasting attacks involve scanning an Active Directory environment to generate a list of user accounts that have Kerberos Service Principal Name (SPN). Attackers then request these SPN to grant Kerberos Service Tickets to these accounts. The tickets are dumped from memory using various tools like Mimikatz and then exfiltrated for offline brute forcing on the encrypted segment of the tickets. If successful, attackers can identify the passwords associated with the accounts, which they then use to remotely sign into machines or access resources.
To reduce the impact of possible kerberoasting attacks make sure that service accounts do not have administrative privileges.
NOTE: Cayosoft Guardian defines privileged users in Active Directory as users with adminCount=1. By design Active Directory uses this attribute to protect members of administrative groups.
According to security best practices it is not recommended re-using admin accounts, instead these accounts must be de-provisioned. If an account has administrative permissions, it might also obtain access to other resources using these administrative permissions and keep this access even after it is removed from the administrative groups. Learn more about AdminSdHolder and SDProp - Microsoft Community Hub.
- Golden ticket attacks: By obtaining the KRBTGT password, a threat actor can generate a "golden ticket", which is a forged Kerberos ticket that can be used to gain unrestricted access to any resource in the AD environment. This allows the attacker to impersonate any user or service in the domain and carry out any action they desire.
- Pass-the-hash attacks: The KRBTGT password is also used to derive the hash values of other AD account passwords. If a threat actor obtains the KRBTGT password, they can use it to perform "pass-the-hash" attacks, where they use the hash values of other user passwords to authenticate and gain access to resources in the domain.
- Persistence: If a threat actor gains access to the KRBTGT password, they can use it to create persistent backdoors into the AD environment, making it easier for them to maintain access and carry out further attacks in the future.
Shared, service, and emergency access accounts that authenticate using a password and are assigned to highly privileged administrative roles such as Global administrator or Security administrator should have their passwords rotated for multiple reasons.
Since multiple people have access to these accounts' credentials, the credentials should be regularly changed to ensure that people that have left their roles can no longer access the accounts.
Bulk changes might be a result of threat activities. Also, it could be a mistake. Deletions or modifications of Microsoft Entra objects can lead to service outages.
NOTE: This threat rule includes a built-in lookback parameter set to 25 hours. Only events that occurred within this timeframe are processed by the rule.
NOTE: Cayosoft Guardian defines privileged users in Active Directory as users with adminCount=1. By design Active Directory uses this attribute to protect members of administrative groups.
According to security best practices it is not recommended re-using admin accounts, instead these accounts must be de-provisioned. If an account has administrative permissions, it might also obtain access to other resources using these administrative permissions and keep this access even after it is removed from the administrative groups. Learn more about AdminSdHolder and SDProp - Microsoft Community Hub.
The Application Owner attribute in Entra ID specifies the account responsible for managing an application's lifecycle. When this attribute is set to a hybrid user account synchronized from the on-premises Active Directory, it introduces significant risks. These hybrid accounts are typically subject to legacy authentication protocols, shared account usage, or administrative roles not intended for cloud application management. A compromise of this account provides attackers a persistent foothold in your environment, with the ability to reconfigure or exploit applications in Entra ID for malicious purposes.
A user added to a privileged role can indicate unauthorized or suspicious activity. This includes direct membership changes, membership granted through nested groups, and membership granted through role-assignable groups. Such changes may be used to escalate privileges, establish persistence, or gain access to sensitive systems and data.
NOTE: This threat rule includes a built-in lookback parameter set to 48 hours. Only events that occurred within this timeframe are processed by the rule.
An attacker could exploit an OAuth consent attack to provide a malicious service principal with privileged access, enabling long-term persistence.
NOTE: This threat rule includes a built-in lookback parameter set to 25 hours. Only events that occurred within this timeframe are processed by the rule.
Active Directory environments operating at Windows Server 2012 R2 or lower functional levels lack foundational security features, such as robust encryption, advanced authentication methods, and recovery mechanisms. These limitations expose the environment to critical vulnerabilities, including outdated cryptographic standards, unprotected credentials, and the difficulty to recover from accidental deletions. Forests and domains at these levels are highly susceptible to exploitation by attackers leveraging deprecated protocols and privilege escalation techniques.
Computers that utilize gMSAs request the current password from Active Directory to initiate services. The gMSAs can be configured to allow computer accounts to access the password. A potential security issue arises when a threat actor takes control of a computer hosting a service that uses a gMSA, or an account with the necessary permissions to request a gMSA password, thereby compromising the gMSA.
NOTE: Cayosoft Guardian defines privileged users in Active Directory as users with adminCount=1. By design Active Directory uses this attribute to protect members of administrative groups.
According to security best practices it is not recommended re-using admin accounts, instead these accounts must be de-provisioned. If an account has administrative permissions, it might also obtain access to other resources using these administrative permissions and keep this access even after it is removed from the administrative groups. Learn more about AdminSdHolder and SDProp - Microsoft Community Hub.
Modifying the msDS-AllowedToActOnBehalfOfOtherIdentity attribute can have security implications. So, it's important to refrain from assigning tasks to privileged resources like DCS. Resource-based constrained delegation is configured on the target resource, unlike other delegation types configured on the accounts accessing the resource.
When a threat actor gains control over a service account, the potential for exploitation of improperly configured Resource-Based Constrained Delegation (RBCD) settings is significant. These misconfigurations can be leveraged to delegate credentials from a lower-privileged account to a higher-privileged resource, thereby escalating their privileges.
Configuring RBCD on domain controllers allows specific accounts to impersonate other users when accessing particular resources. This approach gives administrators granular control over delegation permissions, focusing on the resources rather than the service accounts. However, if misconfigured, RBCD can be a significant security risk.
Modification of privileged group membership might be an indication of a privilege escalation attempt by a threat actor. This activity could signal unauthorized access or an attempt to gain elevated permissions within the system.
Users can configure alerts based on AdminCount or sAMAccountName to monitor and detect suspicious changes to privileged group memberships. However, the built-in privileged groups will always trigger an alert, regardless of user configuration, ensuring that critical security events are not overlooked.
NOTE: Cayosoft Guardian considers both direct and indirect (nested) group permissions when evaluating risks. Privileged users are defined in Active Directory as groups with adminCount=1 and a well-known SID.
NOTE: This threat rule includes a built-in lookback parameter set to 48 hours. Only events that occurred within this timeframe are processed by the rule.
This rule detects inactive and never used user and computer accounts in Active Directory (AD) based on the LastLogonTimestamp attribute. This attribute records the latest time an account successfully logged into the domain. However, it only replicates across domain controllers about every 9 to 14 days, making it a more performance-friendly option for identifying dormant accounts.
By identifying these accounts, administrators can prevent the unauthorized use of stale credentials or deactivate accounts that are no longer needed.
NOTE: Cayosoft Guardian defines privileged users in Active Directory as users with adminCount=1. By design Active Directory uses this attribute to protect members of administrative groups.
According to security best practices it is not recommended re-using admin accounts, instead these accounts must be de-provisioned. If an account has administrative permissions, it might also obtain access to other resources using these administrative permissions and keep this access even after it is removed from the administrative groups. Learn more about AdminSdHolder and SDProp - Microsoft Community Hub.
VMware ESXi contains an authentication bypass vulnerability.
A threat actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management by re-creating the configured AD group ('ESX Admins' by default) after it was deleted from AD.
Multiple MFA failures in a short period may indicate a brute-force attempt or an MFA fatigue attack, where attackers spam the user with repeated MFA requests until one is accepted.
This threat detects all tenants that do not have mail-flow rules restricting attachments with executables.
The threat actor may execute code or a script using the attachments in the email.Bulk changes might be a result of threat activities. Also, it could be a mistake. Deletions or modifications of AD objects can lead to service outages.
NOTE: This threat rule includes a built-in lookback parameter set to 25 hours. Only events that occurred within this timeframe are processed by the rule.
A process failing to authenticate with multiple users might be an indication of a threat actor trying to obtain initial access or elevate their privileges by performing a Password Spraying attack against an Active Directory environment. The detection mechanism uses native events from Security Log. The event 4625 documents failed attempts to log on to the computer and Logon Type value 2 describes an interactive logon attempt.
NOTE: This threat rule includes a built-in lookback parameter set to 25 hours. Only events that occurred within this timeframe are processed by the rule.
An AD user who has been added to and then removed from a privileged group may indicate potential threat activities.
NOTE: Cayosoft Guardian defines built-in privileged groups, either direct or indirect (nested) groups in Active Directory as groups with adminCount=1 and a well-known Security Identifier (SID). Any potential target objects are identified as previously identified built-in privileged groups. By design, Active Directory uses this attribute to protect members of administrative groups.
According to security best practices, it is not recommended to reuse admin accounts; instead, these accounts must be de-provisioned. If an account has administrative permissions, it may also gain access to other resources using these permissions and retain this access even after it is removed from the administrative groups. Learn more about AdminSdHolder and SDProp - Microsoft Community Hub.
NOTE: Cayosoft Guardian defines privileged users in Active Directory as users with adminCount=1. By design Active Directory uses this attribute to protect members of administrative groups.
According to security best practices it is not recommended re-using admin accounts, instead these accounts must be de-provisioned. If an account has administrative permissions, it might also obtain access to other resources using these administrative permissions and keep this access even after it is removed from the administrative groups. Learn more about AdminSdHolder and SDProp - Microsoft Community Hub.
Note: If the ms-DS-Logon-Time-Sync-Interval Active Directory Schema attribute is greater than the Time Interval parameter defined in the threat rule, the accuracy of the threat rule results may be compromised. This discrepancy can lead to inaccurate detection outcomes, such as false positives or false negatives.
NOTE: Cayosoft Guardian defines privileged users in Active Directory as users with adminCount=1. By design Active Directory uses this attribute to protect members of administrative groups.
According to security best practices it is not recommended re-using admin accounts, instead these accounts must be de-provisioned. If an account has administrative permissions, it might also obtain access to other resources using these administrative permissions and keep this access even after it is removed from the administrative groups. Learn more about AdminSdHolder and SDProp - Microsoft Community Hub.
- If a treat actor gains control of a root CA trusted by Microsoft Entra ID, the threat actor can impersonate any user without knowing their password.
- Configuring Certificate-Based Authentication and impersonating a Global Admin doesnt require Global Admin rights. The threat actor might use this technique to elevate his privileges without being noticed.
- A redirect URI, or reply URL, is the location where the authorization server sends the user once the app has been successfully authorized and granted an authorization code or access token. The authorization server sends the code or token to the redirect URI, so it's important you register the correct location as part of the app registration process.
- If the corresponding App Service is deleted, but redirect URI is not deleted from the Microsoft Entra app registration, a threat actor could discover the dangling URI and register the App service instance. After registering the new App Server instance, threat actor will be able to get user sessions authorization tokens.
Apps with risky permissions pose a threat to your Microsoft Entra tenant. Threat actors can use such Microsoft Entra apps for long-term lowered visibility access to contacts, mail, notes, mailbox settings, user directory, and files. Microsoft describes the consent grant attack:
- An attacker registers an app with an OAuth 2.0 provider, such as Microsoft Entra ID.
- The app is configured in a way that makes it seem legitimate. For example, attackers might use the name of a popular product available in the same ecosystem.
- The attacker gets a link directly from users, which may be done through conventional email-based phishing, by compromising a non-malicious website, or through other techniques.
- The user selects the link and is shown an authentic consent prompt asking them to grant the malicious app permissions to data.
- If a user selects 'Accept', they will grant the app permissions to access sensitive data. The app gets an authorization code, which it redeems for an access token, and potentially a refresh token. The access token is used to make API calls on behalf of the user.
- If the user accepts, the attacker can gain access to the user's mails, forwarding rules, files, contacts, notes, profile, and other sensitive data and resources.
- The Microsoft's recommendation is to to require a secure password change when user risk level is High. Microsoft Entra multifactor authentication is required before the user can create a new password with password writeback to remediate their risk.
- Identity Protection analyzes signals about user accounts and calculates a risk score based on the probability that the user has been compromised. If a user has risky sign-in behavior, or their credentials have been leaked, Identity Protection will use these signals to calculate the user risk level. Administrators can configure user risk-based Conditional Access policies to enforce access controls based on user risk, including requirements such as:
- Block access
- Allow access but require a secure password change.
- A secure password change will remediate the user risk and close the risky user event to prevent unnecessary noise for administrators.
NTLM and NTLMv2 authentication is vulnerable to various malicious attacks, including SMB replay, man-in-the-middle attacks, and brute force attacks. Reducing and eliminating NTLM authentication from your environment forces the Windows operating system to use more secure protocols, such as the Kerberos version 5 protocol, or different authentication mechanisms, such as smart cards.
Malicious attacks on NTLM authentication traffic resulting in a compromised server or domain controller can occur only if the server or domain controller handles NTLM requests. If those requests are denied, this attack vector is eliminated.
Anomalous account creation can indicate a potential security issue, especially when accounts are created outside of expected processes. Alerts are triggered when account creation records are detected that were not made by a known initiator with more than two weeks of inactivity. Note that after two weeks of inactivity, any inactive known initiators are removed from the "known initiators" list.
NOTE: This threat rule includes a built-in lookback parameter set to 12 hours. Only events that occurred within this timeframe are processed by the rule.
The Lightweight Directory Access Protocol (LDAP) is used by clients and services to query and interact with Active Directory. When LDAP signing is not enforced, authentication traffic between clients and domain controllers is transmitted in clear text and can be intercepted or modified by attackers. This exposes the environment to man-in-the-middle (MitM) and LDAP relay attacks, which can result in credential theft, privilege escalation, or user impersonation.
To mitigate these risks, Microsoft strongly recommends configuring domain controllers to require LDAP signing. Enforcing signed LDAP communication ensures data integrity and authenticity, preventing unauthorized entities on the network from tampering with or relaying LDAP requests.
Group Managed Service Accounts (gMSAs) depend on the Key Distribution Service (KDS) and its Root Key to securely generate and distribute account passwords. The KDS Root Key enables domain controllers to create cryptographically strong, automatically managed passwords for gMSAs.
If the domain lacks a KDS Root Key, gMSA functionality is disabled, and any attempt to create or use gMSAs will fail. This misconfiguration forces services to rely on traditional accounts with manually rotated passwords, increasing administrative overhead and expanding the potential attack surface through weak or stale credentials.
Domain Controllers (DCs) host the SYSVOL and NETLOGON shared folders via SMB, which are critical for distributing Group Policy and logon scripts. If Hardened UNC Paths are not enforced on DCs, these shares become vulnerable to NTLM relay, man-in-the-middle, and SMB downgrade attacks. Such attacks can enable adversaries to intercept or manipulate authentication traffic, steal user credentials, impersonate domain controllers, or distribute malicious Group Policy objects across the environment.
The Schema Admins group holds forest-wide privileges that allow modification of the Active Directory schema which is one of the most sensitive operations in an AD environment. Members can create or alter object classes and attributes, potentially introducing unauthorized or malicious schema changes.
Persistent membership in the Schema Admins group significantly increases the risk of privilege escalation and long-term persistence by threat actors. Best practice is to keep this group empty under normal conditions and grant only temporary membership during controlled operations (e.g., schema extensions or directory upgrades), then remove access immediately after completion.
- By default, the ms-DS-MachineAccountQuota attribute is set to 10, which means that any user in Active Directory can create up to 10 computer accounts associated with them. The legitimate usage of this attribute is to allow users to have multiple devices on a network that belong to them that they can then manage. However, if a compromised user doesnt have 10 actual devices associated with their account, an attacker can create an account for a non-existing device that will be an object in Active Directory. This fake computer account isnt associated with a real device but can perform Active Directory authentication requests as if it were.
- Organizations should also consider setting the ms-DS-MachineAccountQuota attribute to 0 to make it more difficult for an attacker to leverage the attribute for attacks. Setting the attribute to 0 stops non-admin users from adding new devices to the domain, blocking the most effective method to carry out the attacks first step and forcing threat actors to choose more complex methods to acquire a suitable resource.
Non-configurable settings to the TGTs expiration are established for every account in the Protected Users group. Normally, the domain controller sets the TGTs lifetime and renewal, based on the domain policies, Maximum lifetime for user ticket and Maximum lifetime for user ticket renewal. For the Protected Users group, 600 minutes is set for these domain policies. Using Protected Users for privileged user accounts limits attack surface, eliminating some of the attack paths that can be employed by a threat actor.
NOTE: Cayosoft Guardian defines privileged users in Active Directory as users with adminCount=1. By design Active Directory uses this attribute to protect members of administrative groups.
According to security best practices it is not recommended re-using admin accounts, instead these accounts must be de-provisioned. If an account has administrative permissions, it might also obtain access to other resources using these administrative permissions and keep this access even after it is removed from the administrative groups. Learn more about AdminSdHolder and SDProp - Microsoft Community Hub.
The absence of Conditional Access Policies to block legacy authentication poses a significant security vulnerability. Legacy authentication protocols like POP, IMAP, and SMTP do not support modern authentication methods such as multifactor authentication (MFA). These protocols are frequently exploited by threat actors for credential stuffing, brute force, and phishing attacks. Enforcing a block on legacy authentication greatly diminishes the risk of unauthorized access and enhances the overall security posture.
- FullControl
- WriteDACL
- ForceChangePassword
- AddMember
If an Exchange server or administrative account is compromised, a threat actor can exploit these permissions to:
- Reset passwords of privileged accounts (e.g., MSOL_*)
- Add accounts to sensitive groups, including those with elevated privileges
- Modify ACLs to gain full domain control
- DCSync attacks
- ESC9 / ESC10 (Exchange permission abuse)
- ESC14 (X.509 certificate mapping abuse)
Dangerous Access Control Lists (ACLs) can expose Data Protection API (DPAPI) key objects, crucial for encrypting sensitive data in Windows environments. If an attacker gains access to these DPAPI keys, they could potentially decrypt all domain data protected by DPAPI, leading to significant security breaches. Learn more.
Ensuring proper ACL configurations and monitoring for suspicious activities on domain controllers are essential steps to mitigate this risk.
A large number of accounts in privileged groups makes it difficult to keep track of them, which can lead to poor accountability among privileged users. An environment with an excessive number of privileged users presents a bigger attack surface.
NOTE: Cayosoft Guardian considers both direct and indirect (nested) group permissions when evaluating risks. Privileged users are defined in Active Directory as users with AdminCount=1. By design, Active Directory uses this attribute to protect members of administrative groups.
According to the security best practices, it is not recommended to reuse admin accounts; instead, these accounts must be de-provisioned. If an account has administrative permissions, it may also gain access to other resources using these permissions and retain this access even after it is removed from the administrative groups. Learn more about AdminSdHolder and SDProp - Microsoft Community Hub.
Certain versions of Windows Server 2016 Adprep had an issue granting excessive permissions Full Control to the Enterprise Key Admins group. Without the fix applied, this group had permission to replicate all changes from Active Directory, allowing a threat actor with membership to perform the DCSync attack in some environments.
The only other group granted Full Control over the domain root object, besides the SYSTEM principal, is Enterprise Admins. This is also true for child domains. However, the Enterprise Admins group is part of the protected groups safeguarded by AdminSDHolder.
In contrast, the Enterprise Key Admins group is treated like a regular group in the domain. By default, Account Operators are granted explicit Full Control over the Enterprise Key Admins group, allowing many other users to potentially exploit these permissions.
Additionally, the Enterprise Key Admins group has inheritance enabled, which means other possible OU admins might have access to modify its membership. Without the extra protection afforded to other high-privilege groups like Builtin Admins (BA), Domain Admins (DA), and Enterprise Admins (EA), the Enterprise Key Admins group is an easier target for malicious users aiming to compromise the entire forest.
While RC4 (Rivest Cipher 4) is remarkable for its simplicity and speed, multiple vulnerabilities have been discovered since the original release of RC4, rendering it insecure. RC4 is especially vulnerable when the beginning of the output key stream isn't discarded, or when non-random or related keys are used. A threat actor employing MITM tactics (Man-in-the-Middle) could execute successful deciphering operations in an environment with weak encryption.
NOTE: Cayosoft Guardian defines privileged users in Active Directory as users with adminCount=1. By design Active Directory uses this attribute to protect members of administrative groups.
According to security best practices it is not recommended re-using admin accounts, instead these accounts must be de-provisioned. If an account has administrative permissions, it might also obtain access to other resources using these administrative permissions and keep this access even after it is removed from the administrative groups. Learn more about AdminSdHolder and SDProp - Microsoft Community Hub.
Dangerous Access Control Lists (ACLs) in Active Directory (AD) can expose Distributed File System Replication (DFSR) settings objects. These objects are critical because they manage the replication of the SYSVOL share, which contains essential domain controller configurations, such as Group Policy Objects (GPOs). Compromising DFSR settings can lead to unauthorized changes in GPOs, which attackers can exploit for privilege escalation or persistence in the environment.
Ensuring proper ACL configurations and regularly auditing these settings can help mitigate this risk.
Deploying Active Directory domain controllers as virtual machines without drive encryption exposes sensitive data at rest. In case of theft, compromise, or unauthorized access to the virtual hard disk (VHD) files, an attacker could extract credentials or other sensitive information. Drive encryption such as BitLocker with TPM ensures protection against these risks.
A user right assignment in Windows controls powerful local privileges such as "Log on as a service", "Act as part of the operating system", or "Debug programs", etc. If these privileges are granted to non-administrative users or groups on domain controllers, a threat actor can use them to escalate privileges, establish persistence, or bypass authentication mechanisms.
Domain controllers should only grant sensitive rights to trusted security principals (typically Administrators, SYSTEM, or domain-specific service accounts). Assigning dangerous rights to non-standard accounts can allow lateral movement, impersonation, or even complete domain compromise.
In an Active Directory domain, where group policy does not restrict the anonymous enumeration of SAM accounts and shared resources, an unauthorized user could anonymously list account names and shared resources and use the information to attempt to guess passwords or perform social engineering attacks.
To mitigate this risk, a group policy with the Network access: Do not allow anonymous enumeration of SAM accounts and shares enabled setting should be applied to the domain. This ensures that only authenticated users can retrieve accounts and share information.
Applying this policy may introduce some operational limitations. In one-way trust environments, administrators in the trusting domain may be unable to list accounts from the trusted domain, which complicates access management. Additionally, users who attempt to access file and print servers anonymously will no longer be able to view shared resources. They will need to authenticate before they can see available shares and printers.
Some of your domain controllers haven't been authenticating for over 45 days. This could indicate that their secrets haven't been renewed, typically done every 30 days by default. To address this, you should check the connectivity and replication status between your domain controllers. Running diagnostics on the domain controllers, testing DNS, and examining Kerberos authentication can help identify and resolve the issue. If the issue persists, you may need to force a password change or reconfigure the affected domain controllers.
Note: If the ms-DS-Logon-Time-Sync-Interval Active Directory Schema attribute is greater than the Time Interval parameter defined in the threat rule, the accuracy of the threat rule results may be compromised. This discrepancy can lead to inaccurate detection outcomes, such as false positives or false negatives.
An account with Kerberos pre-authentication disabled doesn´t have sufficient protection against password-guessing attacks.
The Key Distribution Center (KDC) is available as part of the domain controller and performs two key functions which are: Authentication Service (AS) and Ticket-Granting Service (TGS). By default the KDC requires all accounts to use pre-authentication. This is a security feature which offers protection against password-guessing attacks.
If pre-authentication is enabled, a time stamp will be encrypted using the user's password hash as an encryption key. If the KDC reads a valid time when using the user's password hash, which is available in the Active Directory, to decrypt the time stamp, the KDC knows that request isn't a replay of a previous request. When you do not enforce pre-authentication, a malicious actor can directly send a dummy request for authentication. The KDC will return an encrypted TGT and the malicious actor can brute force it offline.
Enable pre-authentication on all users. If disabling pre-authentication is required, consider reducing permissions of accounts with disabled pre-authentication. Kerberos pre-authentication can prevent the active attacker. However, it does not prevent a passive attacker from sniffing the client's encrypted timestamp message to the KDC. If the attacker can sniff that full packet, he can brute force it offline. To mitigate this problem, it is recommended that the users use lengthy passwords. Additionally, a good password rotation policy should also be implemented in the domain to make the offline brute-forcing infeasible or increasingly difficult.
A regular user who is a member of the DNS Admins group or has write permissions on a DNS server object poses a threat to your Active Directory environment. A threat actor might use such an account to escalate privileges by injecting a malicious DLL into the DNS process running as a System to escalate when the service restarts.
NOTE: Cayosoft Guardian considers both direct and indirect (nested) group permissions when evaluating risks. Privileged users are defined in Active Directory as users with AdminCount=1. By design, Active Directory uses this attribute to protect members of administrative groups.
According to security best practices, it is not recommended to reuse admin accounts; instead, these accounts must be de-provisioned. If an account has administrative permissions, it may also gain access to other resources using these permissions and retain this access even after it is removed from the administrative groups. Learn more about AdminSdHolder and SDProp - Microsoft Community Hub.
The addition of a certificate to an Entra ID Enterprise Application can allow an attacker to authenticate without MFA and gain persistent access. If a threat actor compromises an account with App Admin or Owner privileges, they can add credentials to an application and use it to generate OAuth tokens for persistent access.
This method is commonly exploited in OAuth abuse attacks, where attackers use newly added credentials to impersonate users, escalate privileges, or maintain unauthorized access even after an account password reset.
By monitoring this activity, organizations can detect unauthorized persistence mechanisms and prevent potential MFA bypass attacks.
The absence of a Conditional Access policy in Entra ID to block access from untrusted locations represents a significant vulnerability. Threat actors can exploit this gap by attempting unauthorized access from external and high-risk locations. Without a policy to deny such attempts, the environment is exposed to credential compromise, brute force, and other attack methods. Proper Conditional Access policies enhance defense mechanisms by ensuring only trusted locations can interact with critical services.
Apps with risky permissions pose a threat to your Microsoft Entra tenant. Threat actors can use such Microsoft Entra apps for long-term lowered visibility access to contacts, mail, notes, mailbox settings, user directory, and files. Write permissions allow a threat actor to modify your environment to inflict damage or establish persistence. Microsoft describes the consent grant attack:
- An attacker registers an app with an OAuth 2.0 provider, such as Microsoft Entra ID.
- The app is configured in a way that makes it seem legitimate. For example, attackers might use the name of a popular product available in the same ecosystem.
- The attacker gets a link directly from users, which may be done through conventional email-based phishing, by compromising a non-malicious website, or through other techniques.
- The user selects the link and is shown an authentic consent prompt asking them to grant the malicious app permissions to data.
- If a user selects 'Accept', they will grant the app permissions to access sensitive data.
- The app gets an authorization code, which it redeems for an access token, and potentially a refresh token. The access token is used to make API calls on behalf of the user.
- If the user accepts, the attacker can gain access to the user's mails, forwarding rules, files, contacts, notes, profile, and other sensitive data and resources.
Passwords that appear in known data breaches are considered compromised and are highly vulnerable to exploitation. Attackers often use these leaked credentials in automated attacks across multiple environments.
To help detect such risks, Cayosoft Guardian compares password hashes against a curated database of breached credentials sourced from Have I Been Pwned. This database is downloaded to the Cayosoft cloud server, where it is filtered to retain only the most frequently used passwords. Your Cayosoft Guardian server then downloads this filtered list and performs local hash comparisons directly on your domain controllers.
Cayosoft Guardian is designed with strict security principles to protect sensitive credential data within customer environments.
Cayosoft Guardian does not store or transmit password hashes. All password-related comparison operations are executed locally on your domain controllers, ensuring that password hashes remain within your secure environment and are never sent to the internet or external systems.
This architecture ensures that password hashes are not collected, exported, or exposed outside your Active Directory domain controllers during backup, recovery, or change monitoring operations.
The absence of a fine-grained password policy or the misconfiguration of one or more settings has been identified. Establishing fine-grained password policies for all privileged administrative and service accounts within the domain is imperative. These accounts require more stringent password protocols than those applied to standard users due to the elevated risk they pose to the organization if compromised.
NOTE: Cayosoft Guardian defines privileged users in Active Directory as users with adminCount=1. By design Active Directory uses this attribute to protect members of administrative groups.
According to security best practices it is not recommended re-using admin accounts, instead these accounts must be de-provisioned. If an account has administrative permissions, it might also obtain access to other resources using these administrative permissions and keep this access even after it is removed from the administrative groups. Learn more about AdminSdHolder and SDProp - Microsoft Community Hub.
Active Directory objects such as users, computers, and groups are securable objects. A Discretionary Access Control List (DACL) is an internal list attached to an object in Active Directory that specifies which users and groups can access the object and what kinds of operations they can perform. It is implemented using access control lists. When a process tries to access a securable object, the system checks the ACEs in the object's DACL to determine whether to grant access to it or not.
Threat actors may modify an object’s DACL to bypass defense mechanisms and establish a persistent presence within your environment. By exploiting weak or misconfigured permissions, a regular user could escalate privileges, allowing them to manipulate objects, disrupt operations, or access sensitive resources.
Cayosoft Guardian monitors changes to DACLs and triggers alerts when suspicious modifications are detected. The rule checks the following objects and permissions:
Objects:
- Domain controllers
- Domain root
- Domain controllers Organizational Unit (OU)
- Privileged accounts and groups
- Specific objects with critical permissions
Permissions:
- ForceChangePassword: Ability to reset another user's password
- GenericAll: Full control over an object
- GenericWrite: Ability to update any attributes of an object
- WriteOwner: Capability to assume ownership of an object
- AllExtendedRights: Rights to add users to groups or reset passwords
- WriteDacl: Ability to modify an object’s DACL
- Self (Self-Membership): Ability to add oneself to a group
NOTE: Cayosoft Guardian considers both direct and indirect (nested) group permissions when evaluating risks. Privileged users are defined in Active Directory as users with adminCount=1. By design, Active Directory uses this attribute to protect members of administrative groups.
According to security best practices, it is not recommended to reuse admin accounts; instead, these accounts must be de-provisioned. If an account has administrative permissions, it may also gain access to other resources using these permissions and retain this access even after it is removed from the administrative groups. Learn more about AdminSdHolder and SDProp - Microsoft Community Hub.
- Print spooler is a software service that manages printing processes. The spooler accepts print jobs from computers and makes sure that printer resources are available. The spooler also schedules the order in which print jobs are sent to the print queue for printing.
- While seemingly harmless, any authenticated user can remotely connect to a domain controllers print spooler service, and request an update on new print jobs. Also, users can tell the domain controller to send the notification to the system with unconstrained delegation. These actions test the connection and expose the domain controller computer account credential (Print spooler is owned by SYSTEM).
Due to the possibility for exposure, domain controllers and Active Directory admin systems need to have the Print spooler service stopped and disabled. The recommended way to do this is using a Group Policy Object (GPO).
- Unconstrained Kerberos delegation is a mechanism in which a user sends its credentials to a service to enable the service to access resources on behalf of the user. To enable unconstrained Kerberos delegation, the service's account in Active Directory must be marked as trusted for delegation.
- A lot of modern web applications use this delegation mechanism. For example, a web server can delegate the credentials of authenticated users of the website hosted on that server to any other service in the active directory such as an SMTP server, a file server, a database server, another web server, etc. This is called unconstrained delegation because the application account has the permission to delegate credentials to any service it contacts.
- If a threat actor compromises the application, he can use it to act on behalf of other users. If you are logged on as domain admin, the site can create a ticket to whatever other services it wishes, acting as you, the domain admin. For example, the site could choose a domain controller, and make changes to the enterprise admin group. Similarly, the site could acquire the hash of the KRBTGT account, or download a file.
This is because a DNS update source is considered as trusted only if:
- The DNS update source was authenticated against Active Directory
- The DNS update source has the permission to update the DNS record
A threat actor might compromise an AD computer to be able to act as a member of that group.
NOTE: Cayosoft Guardian considers both direct and indirect (nested) group permissions when evaluating risks. Privileged users are defined in Active Directory as users with adminCount=1. By design, Active Directory uses this attribute to protect members of administrative groups.
According to security best practices, it is not recommended to reuse admin accounts; instead, these accounts must be de-provisioned. If an account has administrative permissions, it may also gain access to other resources using these permissions and retain this access even after it is removed from the administrative groups. Learn more about AdminSdHolder and SDProp - Microsoft Community Hub.
NOTE: Cayosoft Guardian defines privileged users in Active Directory as users with adminCount=1. By design Active Directory uses this attribute to protect members of administrative groups.
According to security best practices it is not recommended re-using admin accounts, instead these accounts must be de-provisioned. If an account has administrative permissions, it might also obtain access to other resources using these administrative permissions and keep this access even after it is removed from the administrative groups. Learn more about AdminSdHolder and SDProp - Microsoft Community Hub.