Threat Directory

Welcome to the Cayosoft Threat Directory— a continuously updated hub of intelligence on hybrid identity attack techniques and detection patterns. It’s designed to empower security teams to turn alerts into actionable insights with detailed remediation steps, enabling fast, confident response across Active Directory, Entra ID, Intune, and Microsoft 365.

Cayosoft Threat Directory
Severity:
Threat Severity
System:
Threat System
Tactic:
Threat Tactic
CTD-000076
High
AD CS server vulnerable to NTLM relay attacks
An NTLM relay attack exploits the NTLM challenge-response mechanism. A threat actor intercepts legitimate authentication requests and then forwards them to the server. The client who originally sent the request receives the appropriate challenges, but the threat actor intercepts the responses and forwards them to the server, which then authenticates the attacker rather than the person or device that made the request.
Active Directory
Credential Access Privilege Escalation
CTD-000018
Critical
Microsoft Entra tenant with auditing disabled
In Microsoft Entra tenant with auditing disabled, user activities are not recorded in the auditing log. Without data from auditing log investigation of security issues might be difficult or impossible in some cases. A threat actor might disable auditing to perform some changes in your environment.
Entra ID
Defense Evasion
CTD-000012
Critical
Modified federation settings in Microsoft Entra domain

This rule checks if the domain's federation settings were recently modified.
When you federate your on-premises environment with Microsoft Entra ID, you establish a trust relationship between the on-premises identity provider and Microsoft Entra ID.
Due to this established trust, Microsoft Entra ID honours the security token issued by the on-premises identity provider post-authentication, to grant access to resources protected by Microsoft Entra ID. A malicious user might modify federation settings to get access to resources in Microsoft Entra ID.

Entra ID
Lateral Movement Persistence
CTD-000117
High
Microsoft Entra tenant with partner access via Delegated Administrative Privileges

A Microsoft Entra tenant configured to allow partner access through Delegated Administrative Privileges (DAP) poses a high-severity threat if not tightly monitored and restricted. This access model grants external partners elevated rights within the tenant, potentially including Global Administrator or other privileged roles.

The existence of DAP allows a partner organization to act on behalf of your tenant without needing per-activity approval or just-in-time access, which increases the attack surface. If a partner organization is compromised or acts maliciously, the threat actor could gain control over sensitive resources within your environment, bypass Conditional Access policies, or disable security configurations.

Furthermore, partner access may not show up in standard user audit logs, complicating the detection of misuse. If DAP accounts are unnecessary, it is highly recommended to eliminate them and implement Least Privilege Access, opting for more secure alternatives like Granular Delegated Admin Privileges (GDAP) instead.

Entra ID
Defense Evasion Initial Access Persistence Privilege Escalation
CTD-000145
High
Backup location with unencrypted AD backups

Encrypting Active Directory backups adds an extra layer of security to sensitive data like user credentials, group policies, and other sensitive data. Encrypting backups ensures that even if threat actors gain access to the backup files, they won't be able to read or misuse the information.

Encrypted backups are much safer in the event of a data breach. Even if threat actors manage to access the backup files, they won't be able to decipher the information without the encryption key, minimizing the impact of the breach. In addition, they guard against insider threats. Even employees with access to backup files won't be able to misuse the data if it's encrypted without the necessary decryption keys.

When transferring backup files over networks or storing them in cloud services, encryption ensures that the data remains secure throughout the transmission and storage, protecting it from interception or unauthorized access.

Active Directory Cayosoft Guardian
Collection Credential Access
CTD-000095
High
Entra ID tenant vulnerable to MFA fatigue attacks via voice authentication method
With increasing adoption of strong authentication, multi-factor authentication (MFA) fatigue attacks (aka, MFA spamming) have become more prevalent. These attacks rely on the user's ability to approve a simple voice notification that doesn't require the user to have context of the session they are authenticating. Anytime users are doing “press hash key” or “enter your PIN to approve” instead of entering a code they see on-screen, they are doing simple approvals. Microsoft's studies show that about 1% of users will accept a simple approval request on the first try. That's why it's critical to ensure that users must enter information from the login screen and that they have more context and protection. Number matching with "type the code" experience prevents accidental approval by requiring the user to type in a two-digit code from the login screen to their Authenticator app. If the user didn't initiate the sign-in, they won't know the two-digit code, thereby requiring the threat actor to share the two-digit code in a separate channel, which the user shouldn't accept.
Entra ID
Credential Access
CTD-000094
High
AD domain with unsecure configuration of Cloud Kerberos Trust

In a hybrid scenario, identities are synchronized from the on-premises AD to Microsoft Entra ID, with the on-premises AD being the authoritative source. Normally, lateral movement from the compromised on-premises AD to Microsoft Entra ID is more common, as information flows from on-premises to the cloud.

However, the Cloud Kerberos Trust model creates trust from the on-premises AD to Microsoft Entra ID, allowing authentication based on information from Microsoft Entra ID. A threat actor who obtains Global Admin privileges in Microsoft Entra ID can abuse this trust to escalate their privileges to Domain Admin. This means that the attacker, starting with control over Microsoft Entra ID, can gain control over the on-premises AD and potentially compromise the entire environment.

NOTE: Cayosoft Guardian defines privileged users in Active Directory as users with adminCount=1. By design Active Directory uses this attribute to protect members of administrative groups.

According to security best practices it is not recommended re-using admin accounts, instead these accounts must be de-provisioned. If an account has administrative permissions, it might also obtain access to other resources using these administrative permissions and keep this access even after it is removed from the administrative groups. Learn more about AdminSdHolder and SDProp - Microsoft Community Hub.

Active Directory Entra ID Hybrid
Credential Access
CTD-000160
High
Read-Only Domain Controller (RODC) in Inconsistent State

Read-Only Domain Controllers (RODCs) in an inconsistent state pose significant risks to the integrity and security of an Active Directory environment. RODCs are intended to provide a read-only replica of the Active Directory database, often in less secure locations. Inconsistent states due to replication failures, partial updates, or misconfigurations, can lead to outdated or incorrect data being served to clients, undermining authentication, authorization, and policy application. Additionally, threat actors may exploit this inconsistency to escalate privileges, bypass security controls, or compromise sensitive credentials cached on the RODC.

Active Directory
Defense Evasion Persistence Privilege Escalation
CTD-000156
High
Unauthorized changes to compliance policies

Unauthorized changes to compliance policies weaken your organization's security by potentially allowing non-compliant or compromised devices to access corporate resources. Such changes may indicate that a threat actor has gained administrative access and is attempting to bypass security controls. Monitoring compliance policy changes ensures that the integrity of your device management environment remains intact.

A threat actor who gains administrative access could alter compliance policies to reduce security requirements, allowing non-compliant devices (such as those lacking encryption or updated software) to access critical systems. By detecting these unauthorized changes, the organization can quickly respond and restore secure policies, mitigating the risk of compromised devices accessing sensitive resources.

Entra ID Intune
Defense Evasion Impair Defenses (T1562) Persistence Privilege Escalation
CTD-000182
High
Multiple inbox rules created in an Exchange Online mailbox within a short period

A threat actor who gains access to an Exchange Online mailbox may create multiple inbox rules to conceal emails - tactics commonly used in Business Email Compromise (BEC) attacks to evade detection and maintain access.

The threat is detected based on the creation of multiple new inbox rules in a given period of time.

Detection is scheduled to run regularly across all Entra tenants and will trigger an alert when particular number of new inbox rules are created in a particular period of time. Both the minimum rules number and the time period are adjustable in the Rule settings.

A threat actor who gains access to an Exchange Online mailbox may create a new inbox rule to delete, move, or forward incoming emails - tactics commonly used in Business Email Compromise (BEC) attacks to evade detection and maintain access.

The threat is detected based on the creation of new inbox rules that meet any of the following criteria:

  • Move emails to Deleted Items
  • Mark emails as Read
  • Forward emails to external domains

Detection is scheduled to run regularly across all Entra tenants and will trigger an alert when:

  • A new inbox rule with one or more of the above suspicious actions is created
  • The rule is created by someone other than the mailbox owner (e.g., via delegated access or compromised credentials)

NOTE: This threat rule includes a built-in lookback parameter set to 25 hours. Only events that occurred within this timeframe are processed by the rule.

Entra ID Exchange Online
Collection Defense Evasion
CTD-000174
High
Detected a malicious inbox rule to conceal email in Exchange Online

A threat actor who gains access to an Exchange Online mailbox may create a new inbox rule to delete, move, or forward incoming emails - tactics commonly used in Business Email Compromise (BEC) attacks to evade detection and maintain access.

The threat is detected based on the creation of new inbox rules that meet any of the following criteria:

  • Move emails to Deleted Items
  • Mark emails as Read
  • Forward emails to external domains

Detection is scheduled to run regularly across all Entra tenants and will trigger an alert when:

  • A new inbox rule with one or more of the above suspicious actions is created
  • The rule is created by someone other than the mailbox owner (e.g., via delegated access or compromised credentials)

NOTE: This threat rule includes a built-in lookback parameter set to 25 hours. Only events that occurred within this timeframe are processed by the rule.

Entra ID Exchange Online
Collection Defense Evasion
CTD-000155
High
Unusual device wipe activity

Bulk device wipes executed within a short time frame pose a serious threat to an organization's devices and data integrity. If an attacker gains access to administrative credentials, they could carry out large-scale wipes to eliminate evidence or disrupt business operations. This rule identifies instances where more than N device wipe or reset actions occur within a default 10-minute window (with both the value of N defaulting to 3 and the time interval set in the threat settings). Such activity is unusual and may indicate a coordinated attack targeting multiple devices.

If a threat actor gains access to administrative credentials, they could initiate multiple device wipes at the same time, resulting in significant data loss and operational disruption. In this situation, the malicious actor can erase several devices simultaneously, complicating efforts to recover data or track their activities. Early detection of bulk device wipes is crucial, as it minimizes the potential for widespread impact. This allows security teams to intervene and mitigate the damage before it spreads throughout the network.

NOTE: This threat rule includes a built-in lookback parameter set to 25 hours. Only events that occurred within this timeframe are processed by the rule.

Entra ID Intune
Impact
CTD-000177
Medium
Device enrolled in Intune but never synced

When a device is successfully enrolled in Intune but never performs a compliance check-in, it may indicate one of the following: the management agent failed to initialize, the user uninstalled the MDM profile, or the device was enrolled solely to satisfy Conditional Access requirements and was subsequently abandoned or hidden from management.

Entra ID Intune
Defense Evasion Initial Access
CTD-000114
Medium
AD-integrated DNS zone with WINS forward lookup enabled
The vulnerability related to WINS forwarding in AD-integrated DNS occurs when the DNS server performs a WINS forward lookup. This means that if the DNS server receives an address record query for which it does not have an answer, it sends a NBT-NS Query Request to a pre-configured WINS server. This process can be exploited by a threat actor who can forge DNS responses to compromise user accounts. This is because the DNS server trusts the responses it receives from the WINS server, even if they are not authentic. The threat actor can send malicious responses that trick the DNS server into providing incorrect information, potentially leading to security breaches or unauthorized access to sensitive information. As a result, it is important to properly secure the WINS server and the communication between the DNS server and WINS server to prevent this type of vulnerability.
Active Directory DNS
Credential Access
CTD-000133
Medium
External trust without SID filtering enabled

In certain scenarios, threat actors who have gained control of a domain controller in a trusted domain can exploit the SID history attribute (sIDHistory) to associate SIDs with new user accounts, thereby granting themselves unauthorized access. SID filter quarantining is enabled by default on all external trusts to mitigate this risk. This security feature ensures that only SIDs from the directly trusted domain or forest are considered valid by removing any SID references that do not pertain to them from inbound access requests.

However, administrators can turn off this setting, and older Active Directory trusts may not enable SID filtering. Threat actors can insert spoofed SIDs into access requests without SID filtering, potentially gaining unauthorized access. While SID filtering significantly enhances security by blocking such attacks, it can also cause operational issues if legitimate access relies on SID history or Universal Groups, potentially leading to denied access.

Enabling SID filter quarantining on a trust relationship restricts the trust to the specific domains on either side, breaking its transitivity. This means only SIDs from the directly trusted domain are valid, strengthening security by ensuring only authorized SIDs are accepted.

Active Directory
Defense Evasion
CTD-000113
Medium
AD forest with Java schema extension
A threat actor might add malicious code in the java attribute of an Active Directory object. Using Java Naming and Directory Interface threat actor might force an external application to execute pre-uploaded malicious code.
Active Directory
Defense Evasion Execution
CTD-000165
Medium
AD domain allowing multicast name resolution (LLMNR)

Multicast Name Resolution (LLMNR) is a legacy protocol for name resolution in networks without DNS servers. In an Active Directory domain, LLMNR can expose the environment to spoofing and credential-harvesting attacks, such as responder attacks. Attackers can intercept and manipulate LLMNR requests to gain user credentials or redirect traffic.

Disabling LLMNR mitigates these security risks by preventing unauthorized interception of name resolution requests. However, this change may impact legacy applications or older systems that rely on LLMNR or NetBIOS for network communication.

Active Directory
Credential Access Discovery Lateral Movement
CTD-000186
Medium
Private IP addresses in Entra ID Conditional Access policy

This detection identifies Conditional Access policies that include private IP address ranges (for example, 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) in Named Locations. Because these ranges are non-routable and not globally unique, they provide an unreliable basis for enforcing access control boundaries.

Such configurations may enable threat actors to bypass Conditional Access restrictions if they are:

  • Operating from within corporate or partner networks,
  • Spoofing internal IPs through VPNs, or
  • Leveraging misconfigured proxies.

In addition, Microsoft Entra ID does not natively resolve internal IP addresses to hostnames, nor does it differentiate between multiple users behind a NAT device. As a result, private IP ranges are unsuitable for precise or secure access enforcement.

Entra ID
Defense Evasion Initial Access Persistence
CTD-000190
Medium
AD domain with misconfigured PowerShell logging policies

PowerShell is a legitimate administrative and automation framework, but it is frequently exploited by attackers using tools such as Mimikatz, PowerView, Empire, and Cobalt Strike. When PowerShell Script Block Logging and Module Logging are disabled, malicious activity executed through PowerShell remains invisible to security monitoring solutions such as SIEM and EDR platforms.

Enabling comprehensive PowerShell logging through Group Policy ensures that all script executions—including obfuscated, encoded, or dynamically generated commands - are captured in the Windows Event Log (Event IDs 4103 and 4104). These logs provide critical telemetry for identifying suspicious activity, enabling timely investigation, threat hunting, and detection of advanced adversary techniques.

Active Directory
Credential Access Defense Evasion Execution Persistence
CTD-000195
Medium
Suspicious Global Administrator sign-in in Entra ID

The activity where a sign-in from a Global Administrator account in Entra ID has been detected is considered a high-risk security event. Global Administrator accounts have unrestricted privileges across the tenant, making them prime targets for threat actors attempting to obtain full control over cloud resources and identity infrastructure. Any unexpected or unusual sign-in activity involving these accounts may indicate credential compromise or malicious reconnaissance and should be investigated promptly.

This activity warrants immediate scrutiny - especially if it occurs:

  • Outside of normal business hours,
  • From an unusual or untrusted geographic location or IP address,
  • On an unfamiliar device or user agent, or
  • Following a prolonged period of account inactivity.

Such anomalies may indicate account compromise, credential theft, or early-stage reconnaissance by an adversary. Unauthorized access to a Global Admin account can rapidly lead to full tenant takeover, configuration tampering, and lateral movement across integrated services.

Organizations must treat all Global Admin sign-ins as high-risk events until verified. Proactive mitigation includes enforcing strict Conditional Access policies (e.g., requiring MFA, compliant devices, and named locations), implementing just-in-time access via Privileged Identity Management (PIM), and maintaining vigilant monitoring through Microsoft Entra ID Protection and audit logs. Rapid validation and response are essential to prevent catastrophic cloud environment compromise.

NOTE: This threat rule includes a built-in lookback parameter set to 25 hours. Only events that occurred within this timeframe are processed by the rule.

Entra ID
Discovery Initial Access Privilege Escalation
CTD-000200
High
Active Directory SMB signing not enforced on domain controller
SMB signing helps protect SMB traffic from tampering and relay-style abuse. When SMB signing is not required through Group Policy, a threat actor may exploit this vulnerability to use man-in-the-middle, relay, or reflection techniques against SMB-based systems, especially domain controllers and other critical infrastructure. Recent public research and vulnerability disclosures, including CVE-2025-33073, show that a weak SMB signing posture can increase exposure to modern SMB abuse. Requiring SMB signing through Group Policy is an effective mitigation because it applies the control consistently and reduces the risk of configuration drift on critical systems.
Active Directory
Credential Access Lateral Movement Privilege Escalation
CTD-000196
High
Insecure ACLs on Service Connection Points in Active Directory

In Active Directory, Service Connection Points (SCPs) are special objects that help domain-joined devices discover services such as Configuration Manager, Exchange Autodiscover, and custom applications. These SCPs are stored in the System container and can include connection details such as server names, ports, and protocols. To function correctly, clients must be able to trust the information stored in these SCPs.

A common security oversight is applying overly permissive Access Control Lists (ACLs) to these objects, allowing broad groups such as Authenticated Users or Domain Users to modify them. This is risky because attackers who gain access to a standard user account can exploit these permissions to change SCP values—especially attributes such as serviceBindingInformation. By doing so, they can redirect domain-joined clients to attacker-controlled systems that clients may trust implicitly. As a result, clients may unknowingly send credentials, sensitive data, or service traffic to rogue endpoints, enabling man-in-the-middle (MitM) attacks, credential theft, and lateral movement across the environment.

Active Directory
Persistence Privilege Escalation
CTD-000189
High
Conditional Access policy in Entra ID missing Continuous Access Evaluation (CAE)

This detection identifies Conditional Access policies in Entra ID that do not enforce Continuous Access Evaluation (CAE). CAE enables near real-time policy enforcement by revoking tokens when events such as user disablement, location changes, or role elevation occur.

Without CAE, OAuth access and refresh tokens remain valid until their expiration, even if a user's risk state or session conditions change. This extends the window for attackers to maintain access after privilege elevation or credential compromise.

Entra ID
Defense Evasion Persistence Privilege Escalation
CTD-000122
Critical
AD object with schema update permissions
In Active Directory, a schema is a blueprint that defines the rules for the type of objects that can be stored in the Active Directory database and the attributes related to these objects. The schema contains formal definitions of every object class that can be created in an Active Directory forest, as well as every attribute that can exist in an Active Directory object. The schema is managed as an object itself, so it can be administered and manipulated.
A threat actor with permissions to modify schema might compromise your Active Directory forest or make it inoperable.
Active Directory
Impact Persistence
High
Active Directory SMB signing not enforced on domain controller
SMB signing helps protect SMB traffic from tampering and relay-style abuse. When SMB signing is not required through Group Policy, a threat actor may exploit this vulnerability to use man-in-the-middle, relay, or reflection techniques against SMB-based systems, especially domain controllers and other critical infrastructure. Recent public research and vulnerability disclosures, including CVE-2025-33073, show that a weak SMB signing posture can increase exposure to modern SMB abuse. Requiring SMB signing through Group Policy is an effective mitigation because it applies the control consistently and reduces the risk of configuration drift on critical systems.
Active Directory
Credential Access Lateral Movement Privilege Escalation
CTD-000022
High
Microsoft Entra tenant where regular users can register applications
Custom-developed applications might pose a threat to your environment. A threat actor might use an application to access data in the tenant on behalf of a user. It is recommended to prevent regular users from registering their own applications and let administrators review and register applications. This ensures that the application undergoes a security review before exposing the tenant's data to the application.
Entra ID
Persistence Privilege Escalation
CTD-000136
Critical
AD domain controller not changing its password
Some domain controllers have not updated their passwords in over 45 days, suggesting that their security credentials may be outdated. Domain controllers are typically configured to change their passwords automatically every 30 days. Therefore, it is crucial to ensure that domain controller passwords are updated regularly to maintain security. Investigating why the automatic password change is not occurring is important, as it could indicate a potential security issue. Regular password updates help protect against breaches and ensure the ongoing security of your network.
Active Directory
Credential Access
CTD-000158
High
The certificate template has a key length of less than 2048 bits

A threat actor can exploit weak or vulnerable certificates by exploiting several inherent weaknesses, particularly random number generation, key size, and susceptibility to side-channel attacks. Replacing vulnerable keys with more modern and secure cryptographic algorithms mitigates these risks. To secure your environment, it’s essential to phase out secure certificates, revoke any currently issued weak certificates, and replace them with certificates using stronger algorithms and key sizes.

Active Directory Certificate Services (ADCS)
Privilege Escalation
CTD-000142
Critical
Dangerous ACLs expose certificate containers
Non-default principals with elevated permissions on the NTAuthCertificates container pose a security risk, as this may allow them to escalate privileges and compromise the domain by introducing a malicious Certificate Authority (CA) into the trust hierarchy.
Active Directory
Credential Access
CTD-000150
Critical
Dangerous enrollment permission on authentication certificate templates

Misconfigured permissions on certificate templates for Windows authentication can pose significant security risks. If unprivileged users are granted permission to request certificates where they can supply arbitrary subject information, they could potentially obtain certificates for any user, including high-privilege accounts like domain admins.

To mitigate this risk, reviewing and adjusting the delegations on these certificate templates is crucial. Specifically, ensure that permissions are not granted to broad groups such as Authenticated Users, Domain Users, or Domain Computers. Instead, permissions should be limited to specific, trusted accounts, and additional security measures should be implemented, such as manager approval or required authorized signatures.

Active Directory Certificate Services (ADCS)
Credential Access Privilege Escalation
CTD-000102
Medium
Microsoft Entra tenant with unsecure configuration of sign-in risk policy
Sign-in risk policy in Conditional Access allows mitigation of sign-in risks preventing threat actors from getting access to user accounts. Organizations must decide the level of risk they want to require access control on balancing user experience and security posture. Microsoft recommends requiring Microsoft Entra multifactor authentication when sign-in risk level is Medium or High, allowing users to prove it's them by using one of their registered authentication methods, remediating the sign-in risk.
Entra ID
Credential Access
CTD-000083
High
Microsoft Entra tenant with recent changes in Cross Tenant Access configuration
When a cross-tenant synchronization is configured, a trust relationship between a source tenant and a target tenant is established. By modifying existing or creating a cross tenant access configuration, a threat actor who has access to the source tenant might obtain a long-term persistence in the target tenant or elevate their permissions in the target tenant by including synced accounts into privileged groups.
Entra ID
Defense Evasion Persistence Privilege Escalation
CTD-000149
High
Entra user added to a privileged role

A user added to a privileged role can indicate unauthorized or suspicious activity. This includes direct membership changes, membership granted through nested groups, and membership granted through role-assignable groups. Such changes may be used to escalate privileges, establish persistence, or gain access to sensitive systems and data.

NOTE: This threat rule includes a built-in lookback parameter set to 48 hours. Only events that occurred within this timeframe are processed by the rule.

Entra ID
Privilege Escalation
CTD-000173
Critical
Service principal promoted to privileged role via OAuth consent attack

An attacker could exploit an OAuth consent attack to provide a malicious service principal with privileged access, enabling long-term persistence.

NOTE: This threat rule includes a built-in lookback parameter set to 25 hours. Only events that occurred within this timeframe are processed by the rule.

Entra ID
Persistence Privilege Escalation
CTD-000159
High
Insufficient forest and domain functional levels

Active Directory environments operating at Windows Server 2012 R2 or lower functional levels lack foundational security features, such as robust encryption, advanced authentication methods, and recovery mechanisms. These limitations expose the environment to critical vulnerabilities, including outdated cryptographic standards, unprotected credentials, and the difficulty to recover from accidental deletions. Forests and domains at these levels are highly susceptible to exploitation by attackers leveraging deprecated protocols and privilege escalation techniques.

Active Directory
Defense Evasion Persistence Privilege Escalation
CTD-000121
Low
AD Domain with executable files in SYSVOL
Executable files in SYSVOL might pose a risk as these files might be infected. These infected files will be included in your backups for forest recovery and will transfer infection into a recovered forest.
Active Directory
Persistence
CTD-000138
High
Resource-based constrained delegation on domain controllers

Modifying the msDS-AllowedToActOnBehalfOfOtherIdentity attribute can have security implications. So, it's important to refrain from assigning tasks to privileged resources like DCS. Resource-based constrained delegation is configured on the target resource, unlike other delegation types configured on the accounts accessing the resource.

When a threat actor gains control over a service account, the potential for exploitation of improperly configured Resource-Based Constrained Delegation (RBCD) settings is significant. These misconfigurations can be leveraged to delegate credentials from a lower-privileged account to a higher-privileged resource, thereby escalating their privileges.

Configuring RBCD on domain controllers allows specific accounts to impersonate other users when accessing particular resources. This approach gives administrators granular control over delegation permissions, focusing on the resources rather than the service accounts. However, if misconfigured, RBCD can be a significant security risk.

Active Directory
Defense Evasion Lateral Movement Privilege Escalation
CTD-000146
High
AD user added to privileged group

Modification of privileged group membership might be an indication of a privilege escalation attempt by a threat actor. This activity could signal unauthorized access or an attempt to gain elevated permissions within the system.

Users can configure alerts based on AdminCount or sAMAccountName to monitor and detect suspicious changes to privileged group memberships. However, the built-in privileged groups will always trigger an alert, regardless of user configuration, ensuring that critical security events are not overlooked.

NOTE: Cayosoft Guardian considers both direct and indirect (nested) group permissions when evaluating risks. Privileged users are defined in Active Directory as groups with adminCount=1 and a well-known SID.

NOTE: This threat rule includes a built-in lookback parameter set to 48 hours. Only events that occurred within this timeframe are processed by the rule.

Active Directory
Credential Access Privilege Escalation
CTD-000125
Medium
Folder on SYSVOL with non-default access permissions
Improper access permissions for directory data files could allow unauthorized users including threat actors to read, modify, or delete directory data. The SYSVOL directory contains public files (to the domain) such as policies and logon scripts. Data in shared subdirectories are replicated to all domain controllers in a domain.

NOTE: Cayosoft Guardian defines privileged users in Active Directory as users with adminCount=1. By design Active Directory uses this attribute to protect members of administrative groups.

According to security best practices it is not recommended re-using admin accounts, instead these accounts must be de-provisioned. If an account has administrative permissions, it might also obtain access to other resources using these administrative permissions and keep this access even after it is removed from the administrative groups. Learn more about AdminSdHolder and SDProp - Microsoft Community Hub.

Active Directory
Defense Evasion Persistence Privilege Escalation
CTD-000141
High
AD domain with unsecure ESX authentication bypass

VMware ESXi contains an authentication bypass vulnerability.

A threat actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management by re-creating the configured AD group ('ESX Admins' by default) after it was deleted from AD.

Active Directory VMware Hypervisor ESXi
Persistence Privilege Escalation
CTD-000134
Medium
Microsoft Entra tenant has Exchange Organization without mail-flow rules restricting attachments with executables

This threat detects all tenants that do not have mail-flow rules restricting attachments with executables.

The threat actor may execute code or a script using the attachments in the email.
Entra ID Exchange Online
Execution Initial Access
CTD-000003
Medium
AD forest with anonymous access enabled over Name Service Provider Interface
Anonymous NSPI access to AD is enabled in the Active Directory forest. Anonymous name service provider interface (NSPI) access to AD is a feature that allows anonymous RPC-based binds to AD. A threat actor might use this protocol to get initial access to the environment.
Active Directory
Initial Access
CTD-000006
High
Anonymous access enabled in AD forest
Enabled anonymous LDAP access exposes directory information to unauthenticated users, allowing attackers to enumerate users, groups, and other Active Directory objects without authentication. This significantly lowers the effort required for reconnaissance and target identification but does not directly provide privilege escalation or persistence capabilities. However, the information obtained can be used to support follow-on attacks such as password spraying, phishing, and privilege escalation through other weaknesses.
Active Directory
Defense Evasion Discovery Initial Access
CTD-000042
High
Microsoft Entra tenant with Certificate-Based Authentication enabled for all users
  1. If a treat actor gains control of a root CA trusted by Microsoft Entra ID, the threat actor can impersonate any user without knowing their password.
  2. Configuring Certificate-Based Authentication and impersonating a Global Admin doesn’t require Global Admin rights. The threat actor might use this technique to elevate his privileges without being noticed.
Entra ID
Defense Evasion Persistence
CTD-000039
Medium
Microsoft Entra application registration with dangling URI
  1. A redirect URI, or reply URL, is the location where the authorization server sends the user once the app has been successfully authorized and granted an authorization code or access token. The authorization server sends the code or token to the redirect URI, so it's important you register the correct location as part of the app registration process.
  2. If the corresponding App Service is deleted, but redirect URI is not deleted from the Microsoft Entra app registration, a threat actor could discover the dangling URI and register the App service instance. After registering the new App Server instance, threat actor will be able to get user sessions authorization tokens.
Entra ID
Credential Access
CTD-000009
Low
Microsoft Entra app with risky read permissions

Apps with risky permissions pose a threat to your Microsoft Entra tenant. Threat actors can use such Microsoft Entra apps for long-term lowered visibility access to contacts, mail, notes, mailbox settings, user directory, and files. Microsoft describes the consent grant attack:

  • An attacker registers an app with an OAuth 2.0 provider, such as Microsoft Entra ID.
  • The app is configured in a way that makes it seem legitimate. For example, attackers might use the name of a popular product available in the same ecosystem.
  • The attacker gets a link directly from users, which may be done through conventional email-based phishing, by compromising a non-malicious website, or through other techniques.
  • The user selects the link and is shown an authentic consent prompt asking them to grant the malicious app permissions to data.
  • If a user selects 'Accept', they will grant the app permissions to access sensitive data. The app gets an authorization code, which it redeems for an access token, and potentially a refresh token. The access token is used to make API calls on behalf of the user.
  • If the user accepts, the attacker can gain access to the user's mails, forwarding rules, files, contacts, notes, profile, and other sensitive data and resources.
Entra ID
Collection Defense Evasion
CTD-000103
Low
Microsoft Entra tenant where regular users can create Microsoft 365 groups
Microsoft 365 groups are used to manage access to resources and services in Azure. If a regular user can create groups in the tenant, a threat actor might create a group and use that group to get access to other user accounts. Microsoft 365 groups creation should be restricted to Microsoft Entra administrators only.
Entra ID
Collection
CTD-000100
Medium
Entra ID tenant without policy to show geographic location context in Microsoft Authenticator notifications
By default, Microsoft Authenticator notifications do not include geographic location context, so users do not know what exactly they confirm. A threat actor might use this to compromise an account by sending authentication requests that users might confirm by mistake. A policy can be configured to improve the security of user sign-in by adding the application name and geographic location of the sign-in to Microsoft Authenticator passwordless and push notifications.
Entra ID
Credential Access
CTD-000092
Low
Stale Microsoft Entra service principal
A compromised Enterprise Application can be used by threat actor to access data in your tenant. If there is an application without sign-ins, it might be an indication that this Service Principal is no longer used. It is recommended to disable the Service Principal to reduce attack surface.
Entra ID
Defense Evasion Persistence
CTD-000077
Medium
AD domain allowing NTLM authentication

NTLM and NTLMv2 authentication is vulnerable to various malicious attacks, including SMB replay, man-in-the-middle attacks, and brute force attacks. Reducing and eliminating NTLM authentication from your environment forces the Windows operating system to use more secure protocols, such as the Kerberos version 5 protocol, or different authentication mechanisms, such as smart cards.

Malicious attacks on NTLM authentication traffic resulting in a compromised server or domain controller can occur only if the server or domain controller handles NTLM requests. If those requests are denied, this attack vector is eliminated.

Active Directory
Credential Access Defense Evasion Lateral Movement Privilege Escalation
CTD-000194
High
AD domain with misconfigured LDAP signing policy on the domain controllers

The Lightweight Directory Access Protocol (LDAP) is used by clients and services to query and interact with Active Directory. When LDAP signing is not enforced, authentication traffic between clients and domain controllers is transmitted in clear text and can be intercepted or modified by attackers. This exposes the environment to man-in-the-middle (MitM) and LDAP relay attacks, which can result in credential theft, privilege escalation, or user impersonation.

To mitigate these risks, Microsoft strongly recommends configuring domain controllers to require LDAP signing. Enforcing signed LDAP communication ensures data integrity and authenticity, preventing unauthorized entities on the network from tampering with or relaying LDAP requests.

Active Directory
Credential Access Defense Evasion Lateral Movement Privilege Escalation
CTD-000193
High
Active Directory missing KDS root key required for gMSA support

Group Managed Service Accounts (gMSAs) depend on the Key Distribution Service (KDS) and its Root Key to securely generate and distribute account passwords. The KDS Root Key enables domain controllers to create cryptographically strong, automatically managed passwords for gMSAs.

If the domain lacks a KDS Root Key, gMSA functionality is disabled, and any attempt to create or use gMSAs will fail. This misconfiguration forces services to rely on traditional accounts with manually rotated passwords, increasing administrative overhead and expanding the potential attack surface through weak or stale credentials.

Active Directory
Credential Access Privilege Escalation
CTD-000192
High
AD domain with misconfigured UNC paths policies

Domain Controllers (DCs) host the SYSVOL and NETLOGON shared folders via SMB, which are critical for distributing Group Policy and logon scripts. If Hardened UNC Paths are not enforced on DCs, these shares become vulnerable to NTLM relay, man-in-the-middle, and SMB downgrade attacks. Such attacks can enable adversaries to intercept or manipulate authentication traffic, steal user credentials, impersonate domain controllers, or distribute malicious Group Policy objects across the environment.

Active Directory
Credential Access Defense Evasion Initial Access Lateral Movement Privilege Escalation
CTD-000191
High
Persistent membership detected in Active Directory Schema Admins group

The Schema Admins group holds forest-wide privileges that allow modification of the Active Directory schema which is one of the most sensitive operations in an AD environment. Members can create or alter object classes and attributes, potentially introducing unauthorized or malicious schema changes.

Persistent membership in the Schema Admins group significantly increases the risk of privilege escalation and long-term persistence by threat actors. Best practice is to keep this group empty under normal conditions and grant only temporary membership during controlled operations (e.g., schema extensions or directory upgrades), then remove access immediately after completion.

Active Directory
Defense Evasion Persistence Privilege Escalation
CTD-000007
Informational
Microsoft Entra ID Administrative Units are not being used
Usage of Administrative Units enhances tenant's protection against threats. When planning your access control strategy, there are three aspects to consider when you assign a role to your administrators: a specific set of permissions, over a specific scope, for a specific period of time. The least privilege means you grant your administrators exactly the permission they need to do their job. By limiting scopes with Administrative units, you limit what resources are at risk if the security principal is ever compromised.
Entra ID
Persistence
CTD-000020
Medium
Microsoft Entra tenant with Privileged Identity Management not being used
In a tenant with Privileged Identity Management (PIM), Microsoft Entra roles can be secured with an additional approval process and require MFA on activation. Without PIM, if a threat actor gets access to an account with membership in a powerful role such as Global Admin, he will be able to use it right away. PIM provides a time-based and approval-based role activation to mitigate the risks of excessive, unnecessary, or misused access permissions to important resources. These resources include resources in Microsoft Entra ID, Azure, and other Microsoft Online Services such as Microsoft 365 or Microsoft Intune.
Entra ID
Privilege Escalation
CTD-000014
Medium
Microsoft Entra tenant configured to allow guests to invite other guests
A guest invitation configuration where guest users can invite other guest users poses a threat to the tenant's identities. Even with limited access, guest users can collect some data about the environment, for example, they can verify other user's existence in the environment. A threat actor might use a guest account to collect information for future attacks.
Entra ID
Initial Access
CTD-000019
Low
Microsoft Entra tenant with Microsoft 365 groups exposed to the whole organization
A public group might pose a threat as all users in the organization might have access to the group's content. A threat actor can add herself to any public group using the Microsoft Entra admin center and access resources such as SharePoint documents or Teams chats.
Entra ID
Discovery
CTD-000148
Medium
Insufficient Active Directory domain controller auditing policy configuration
This threat checks whether your organization has sufficient auditing settings for your AD domain controllers, which helps organizations alert of suspicious activity that could lead to lateral movement and privilege escalation, including a complete domain compromise.
Active Directory
Defense Evasion
CTD-000056
High
AD domain allows unprivileged users to add computer accounts
  1. By default, the ms-DS-MachineAccountQuota attribute is set to 10, which means that any user in Active Directory can create up to 10 computer accounts associated with them. The legitimate usage of this attribute is to allow users to have multiple devices on a network that belong to them that they can then manage. However, if a compromised user doesn’t have 10 actual devices associated with their account, an attacker can create an account for a non-existing device that will be an object in Active Directory. This fake computer account isn’t associated with a real device but can perform Active Directory authentication requests as if it were.
  2. Organizations should also consider setting the ms-DS-MachineAccountQuota attribute to 0 to make it more difficult for an attacker to leverage the attribute for attacks. Setting the attribute to 0 stops non-admin users from adding new devices to the domain, blocking the most effective method to carry out the attack’s first step and forcing threat actors to choose more complex methods to acquire a suitable resource.
Active Directory
Initial Access
CTD-000031
Informational
Exchange Online mailbox with SMTP forwarding address
Exchange Online mailbox with SMTP forwarding address might be an indication of threat activities. A threat actor might use an SMTP forwarding address to receive emails from the compromised mailbox.
Entra ID Exchange Online
Defense Evasion Persistence
CTD-000151
Critical
Dangerous ACLs expose GPOs applied to privileged group members
Misconfigured Access Control Lists (ACLs) can expose Group Policy Objects (GPOs) applied to privileged group members. If an attacker gains access to these GPOs, they can execute code on workstations of privileged accounts, potentially escalating their privileges. This vulnerability highlights the importance of properly securing ACLs to prevent unauthorized access and privilege escalation within an Active Directory environment.
Active Directory
Execution Privilege Escalation
CTD-000089
Critical
AD domain with unsecure RBCD delegation on domain controllers
A threat actor could exploit this vulnerability by identifying non-privileged users outside of the Domain Admins, Enterprise Admins, or Built-in Admins groups who possess write access to Resource-Based Constrained Delegation (RBCD) settings on domain controllers. With write access, attackers can enable a resource to impersonate any user, except those explicitly restricted by delegation settings.
Active Directory
Credential Access
CTD-000075
Medium
AD forest with Recycle Bin not enabled
A user or a threat actor might delete objects in the Active Directory, causing downtime. The Recycle Bin feature allows restoring deleted objects immediately without losing any data.
Active Directory
Impact
CTD-000176
Critical
Exchange-related AD group with excessive permissions
Cayosoft Guardian detects a threat when the Exchange Windows Permissions and Exchange Trusted Subsystem Exchange-related security groups in Active Directory have any of the following excessive permissions assigned on critical AD objects (such as the domain root):
  • FullControl
  • WriteDACL
  • ForceChangePassword
  • AddMember
These permissions, when inherited via ACLs, grant broad and dangerous control over user and group objects.

If an Exchange server or administrative account is compromised, a threat actor can exploit these permissions to:

  • Reset passwords of privileged accounts (e.g., MSOL_*)
  • Add accounts to sensitive groups, including those with elevated privileges
  • Modify ACLs to gain full domain control
While AdminSDHolder protects some Tier 0 accounts, many others - including Microsoft Entra Connect service accounts - are unprotected. This allows for privilege escalation paths such as:
  • DCSync attacks
  • ESC9 / ESC10 (Exchange permission abuse)
  • ESC14 (X.509 certificate mapping abuse)
Active Directory Exchange
Credential Access Defense Evasion Initial Access Persistence Privilege Escalation
CTD-000144
Critical
Dangerous ACLs expose DPAPI key objects

Dangerous Access Control Lists (ACLs) can expose Data Protection API (DPAPI) key objects, crucial for encrypting sensitive data in Windows environments. If an attacker gains access to these DPAPI keys, they could potentially decrypt all domain data protected by DPAPI, leading to significant security breaches. Learn more

Ensuring proper ACL configurations and monitoring for suspicious activities on domain controllers are essential steps to mitigate this risk.

Active Directory
Credential Access
CTD-000143
Critical
Dangerous ACLs expose Certificate Templates container
Non-default principals with elevated permissions on the Certificate Templates container pose a security risk, as this may allow them to escalate privileges and compromise the domain by introducing a malicious Certificate Authority (CA) into the trust hierarchy.
Active Directory
Credential Access
CTD-000088
High
AD domain controller using unsecure encryption type

While RC4 (Rivest Cipher 4) is remarkable for its simplicity and speed, multiple vulnerabilities have been discovered since the original release of RC4, rendering it insecure. RC4 is especially vulnerable when the beginning of the output key stream isn't discarded, or when non-random or related keys are used. A threat actor employing MITM tactics (Man-in-the-Middle) could execute successful deciphering operations in an environment with weak encryption.

Active Directory
Credential Access Privilege Escalation
CTD-000099
Medium
Entra ID tenant without policy to show application name context in Microsoft Authenticator notifications
By default, Microsoft Authenticator notifications do not include additional application context, so users do not know what exactly they confirm. A threat actor might use this to compromise an account by sending authentication requests that users might confirm by mistake. A policy can be configured to improve the security of user sign-in by adding the application name and geographic location of the sign-in to Microsoft Authenticator passwordless and push notifications.
Entra ID
Credential Access
CTD-000168
High
AD domain controller deployed as a VM without drive encryption

Deploying Active Directory domain controllers as virtual machines without drive encryption exposes sensitive data at rest. In case of theft, compromise, or unauthorized access to the virtual hard disk (VHD) files, an attacker could extract credentials or other sensitive information. Drive encryption such as BitLocker with TPM ensures protection against these risks.

Active Directory
Defense Evasion Privilege Escalation
CTD-000172
High
Active directory dangerous user rights assignments on domain controllers

A user right assignment in Windows controls powerful local privileges such as "Log on as a service", "Act as part of the operating system", or "Debug programs", etc. If these privileges are granted to non-administrative users or groups on domain controllers, a threat actor can use them to escalate privileges, establish persistence, or bypass authentication mechanisms.

Domain controllers should only grant sensitive rights to trusted security principals (typically Administrators, SYSTEM, or domain-specific service accounts). Assigning dangerous rights to non-standard accounts can allow lateral movement, impersonation, or even complete domain compromise.

Active Directory
Defense Evasion Persistence Privilege Escalation
CTD-000008
Medium
Microsoft Entra app with client secrets
App registration with client secrets poses a threat. A client secret is a string value that might be used in config files or scripts, and it can be easily compromised. Once the secret is compromised, any permissions granted to the service principal can be used by a threat actor to perform actions on behalf of an application.
Entra ID
Credential Access Defense Evasion
CTD-000096
Medium
Microsoft Entra tenant with device settings allowing brute force attacks
If a Windows device does not restrict password attempts, a threat actor may be able to repeatedly guess the password and gain access to the device. This can lead to compromised credentials or data or to the installation of malicious software.
Entra ID Intune
Initial Access
CTD-000015
Medium
Microsoft Entra tenant with unsecure Guest user access permissions
A Microsoft Entra ID is configured with unsecure Guest user access permissions. With the current setting value, the threat actor might enumerate groups and users using a tool such as AADInternals. The API calls to Microsoft Entra ID are not logged and therefore the actions of a threat actor can not be easily detected.
Entra ID
Discovery
CTD-000021
High
Microsoft Entra tenant with security defaults not enabled
Microsoft Entra ID supports the most widely used authentication and authorization protocols including legacy authentication. Legacy authentication can't prompt users for second factor authentication or other authentication requirements needed to satisfy conditional access policies. With legacy authentication allowed in the tenant, a threat actor might use previously obtained credentials to log in and access resources.
Entra ID
Credential Access
CTD-000169
High
Unauthorized certificate addition to Entra ID Enterprise Application

The addition of a certificate to an Entra ID Enterprise Application can allow an attacker to authenticate without MFA and gain persistent access. If a threat actor compromises an account with App Admin or Owner privileges, they can add credentials to an application and use it to generate OAuth tokens for persistent access.

This method is commonly exploited in OAuth abuse attacks, where attackers use newly added credentials to impersonate users, escalate privileges, or maintain unauthorized access even after an account password reset.

By monitoring this activity, organizations can detect unauthorized persistence mechanisms and prevent potential MFA bypass attacks.

Entra ID
Credential Access Defense Evasion
CTD-000167
High
Entra ID tenant allowing multicast name resolution (LLMNR)
Multicast Name Resolution (LLMNR) is a legacy protocol for name resolution in networks without DNS servers. In an Active Directory domain, LLMNR can expose the environment to spoofing and credential-harvesting attacks, such as responder attacks. Attackers can intercept and manipulate LLMNR requests to gain user credentials or redirect traffic.
Entra ID Intune
Collection Credential Access
CTD-000038
High
Microsoft Entra tenant with unsecure access to Azure management
Organizations use many Azure services and manage them from Azure Resource Manager based tools like Microsoft Entra admin center, Azure PowerShell, and Azure CLI. These tools can provide highly privileged access to resources. To protect these privileged resources, Microsoft recommends requiring multifactor authentication (MFA) for any user accessing these resources. Without MFA enforced, a threat actor might compromise an account and immediately get access to the privileged resources.
Entra ID
Command and Control Execution Lateral Movement Privilege Escalation
CTD-000010
Critical
Microsoft Entra app with risky write permissions

Apps with risky permissions pose a threat to your Microsoft Entra tenant. Threat actors can use such Microsoft Entra apps for long-term lowered visibility access to contacts, mail, notes, mailbox settings, user directory, and files. Write permissions allow a threat actor to modify your environment to inflict damage or establish persistence. Microsoft describes the consent grant attack:

  • An attacker registers an app with an OAuth 2.0 provider, such as Microsoft Entra ID.
  • The app is configured in a way that makes it seem legitimate. For example, attackers might use the name of a popular product available in the same ecosystem.
  • The attacker gets a link directly from users, which may be done through conventional email-based phishing, by compromising a non-malicious website, or through other techniques.
  • The user selects the link and is shown an authentic consent prompt asking them to grant the malicious app permissions to data.
  • If a user selects 'Accept', they will grant the app permissions to access sensitive data.
  • The app gets an authorization code, which it redeems for an access token, and potentially a refresh token. The access token is used to make API calls on behalf of the user.
  • If the user accepts, the attacker can gain access to the user's mails, forwarding rules, files, contacts, notes, profile, and other sensitive data and resources.
Entra ID
Collection Defense Evasion
CTD-000062
Critical
AD domain controller with enabled print spooler
  1. Print spooler is a software service that manages printing processes. The spooler accepts print jobs from computers and makes sure that printer resources are available. The spooler also schedules the order in which print jobs are sent to the print queue for printing.
  2. While seemingly harmless, any authenticated user can remotely connect to a domain controllers print spooler service, and request an update on new print jobs. Also, users can tell the domain controller to send the notification to the system with unconstrained delegation. These actions test the connection and expose the domain controller computer account credential (Print spooler is owned by SYSTEM).
    Due to the possibility for exposure, domain controllers and Active Directory admin systems need to have the Print spooler service stopped and disabled. The recommended way to do this is using a Group Policy Object (GPO).
Active Directory
Privilege Escalation
CTD-000091
Critical
DNS zone allowing unsecure update
Unsecure dynamic updates allow a threat actor to update a DNS record without authentication. Threat actor can replace an existing DNS record and redirect people to another server. If enabling Dynamic updates is required for a company, it is highly recommended to use Secure only dynamic updates option.

This is because a DNS update source is considered as trusted only if:

  1. The DNS update source was authenticated against Active Directory
  2. The DNS update source has the permission to update the DNS record
Active Directory DNS
Credential Access Defense Evasion