Honey account targeted with Kerberos pre-authentication attempts

Kerberos pre-authentication attempts against honey accounts expose credentials to attackers, enabling reconnaissance and potential compromise.
AD user with suspicious password refresh

Active Directory user with suspicious password refresh exposes organization to potential password policy compromise, allowing attackers to manipulate settings.
AD-integrated DNS zone with WINS forward lookup enabled

AD-integrated DNS zones with WINS forward lookup enabled expose users to forged DNS responses that can compromise account authentication, enabling attackers to bypass authentication or steal credentials.
Entra user attempted to access LAPS password

An Entra user accessed LAPS password, exposing local admin credentials and enabling lateral movement through administrative account access.
Active Directory password in Group Policy Preferences (GPP) compromise

Active Directory password exposure in Group Policy Preferences (GPP) XML files allows attackers to decrypt passwords and access privileged accounts or systems.
Regular AD object with Migrate SID history permission

Attackers can migrate high-privilege SIDs into their own accounts via a regular AD object with Migrate SID history permission, gaining elevated access and privileges.
Privileged AD user with failed logon attempts

A Privileged AD user with failed logon attempts may indicate an unauthorized access attempt against a high-value domain account, exposing attack paths and administrative scope.
Microsoft Entra user retrieving Bitlocker keys

Unauthorized Microsoft Entra users accessing BitLocker recovery keys enable attackers to decrypt drives and gain unauthorized data access, exposing sensitive information through administrative scope.
Stale Microsoft Entra device

Stale Microsoft Entra devices expose credentials and increase attack surface, allowing attackers to access company resources through primary refresh tokens.
Rejected PIM role membership request from Microsoft Entra user

Unauthorized privilege escalation attempts via rejected PIM role membership requests from Microsoft Entra users may indicate a compromised account, exposing attack paths for persistence and reconnaissance.