AD user with blank password

Active Directory user accounts without passwords are exposed to unauthorized access due to authentication bypass.

AD domain controller not changing its password

Active Directory

Domain controllers with outdated passwords expose sensitive information to attackers, enabling unauthorized access and potential breaches through pass-the-ticket (PtT) or pass-the-hash (PtH) attacks.

Failed logon attempts targeting honey account

Active Directory

Failed logon attempts targeting honey accounts in Active Directory may indicate brute-force attacks or reconnaissance activity, exposing administrative scope and attacker capability.

Dangerous ACLs expose certificate containers

Active Directory

Critical: Non-default principals with elevated permissions on the NTAuthCertificates container expose certificate containers, enabling privilege escalation and CA compromise through attack paths.