CTD-000002

AD domain with built-in domain Guest account enabled

Medium
Active Directory
Discovery Initial Access Reconnaissance
v76

Signature Identity

CTD-000002
Threat ID
76
Version
IOE
Indicator Type

Threat Description

An enabled built-in Guest account introduces a low-trust authentication path into the domain that can be abused for initial access. Attackers can sign in with minimal restrictions, establish a foothold, and operate within the environment using a known, low-visibility identity. From this position, they can perform reconnaissance, enumerate users and resources, and stage follow-on attacks such as password spraying and phishing. Because activity is attributed to the Guest account, attribution and detection are degraded, allowing attackers to remain anonymous during early attack stages.

MITRE ATT&CK: Attack Tactics

Discovery Initial Access Reconnaissance

D3FEND: Defend Tactics

Application Configuration Hardening

Remediation

Disable the built-in guest account:

  1. Open Active Directory Users and Computers.
  2. Find Guest user account.
  3. Right-click on the account and select Disable Account.

Frequently Asked Questions

What does AD domain with built-in domain Guest account enabled mean?

In an Active Directory environment, the built-in domain Guest account is a pre-created user account that can be used for anonymous access. When this account is enabled, it allows anyone to sign in without providing valid credentials.

An enabled domain guest account provides an entry point for unauthorized access, allowing attackers to enumerate users, groups, and other domain details. This information can aid in planning future attacks by identifying potential vulnerabilities and targets.

An attacker can sign in using the built-in guest account and perform reconnaissance against the domain, gathering information about accounts, group memberships, and other details that support planning malicious operations. This access also enables them to potentially escalate privileges or gain unauthorized access to sensitive resources.

Cayosoft Guardian continuously monitors the state of the built-in Guest account across the Active Directory environment. When it detects an enabled guest account, Guardian flags it as a security issue to alert administrators and provide visibility into potential attack paths.

Cayosoft Guardian alerts administrators when it detects an enabled guest account, supporting investigation and response efforts. By providing visibility into security issues, Guardian helps administrators review and address potential vulnerabilities, reducing the risk of unauthorized access and limiting reconnaissance opportunities for attackers.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Account protection
Attack Tactics
Discovery Initial Access Reconnaissance
Defend Tactics
Application Configuration Hardening
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical