AD object with modified msDS-KeyCredentialLink

Active Directory objects with modified msDS-KeyCredentialLink expose users to persistent access attacks through unauthorized key pair creation and encryption, enabling attackers to bypass normal authentication controls.