Detected a malicious inbox rule to conceal email in Exchange Online

A malicious inbox rule in Exchange Online conceals emails, aiding Business Email Compromise attacks, exposing your organization to unauthorized data access and financial losses.
Device enrolled in Intune but never synced

Devices enrolled in Intune but never synced expose organizations to attack paths through persistence and reconnaissance, highlighting the need for continuous compliance checks.
AD object with modified msDS-KeyCredentialLink
Active Directory objects with modified msDS-KeyCredentialLink expose users to persistent access attacks through unauthorized key pair creation and encryption, enabling attackers to bypass normal authentication controls.
AD user with suspicious password refresh

Active Directory user with suspicious password refresh exposes organization to potential password policy compromise, allowing attackers to manipulate settings.
Microsoft Entra user with authentication phone details modified by another user

Microsoft Entra users with modified authentication phone details may indicate unauthorized access or compromise, allowing attackers to receive multifactor authentication messages for a compromised account. This vulnerability exposes sensitive information and enables attack paths through administrative scope and credentials.
Regular AD object with unexpected admincount value

Unexpected admincount values in AD objects may indicate unauthorized changes, allowing attackers to evade detection and plan future malicious operations.
External trust without SID filtering enabled

External trusts without SID filtering enabled expose Active Directory to spoofed Security Identifiers (SIDs) in access requests, allowing attackers to gain unauthorized access.
Regular AD object with Migrate SID history permission

Attackers can migrate high-privilege SIDs into their own accounts via a regular AD object with Migrate SID history permission, gaining elevated access and privileges.
AD domain with restored domain controllers

Attackers can modify user account access and evade detection through restored domain controllers in Active Directory, allowing unauthorized password resets or group membership modifications.
AD forest with Java schema extension

Active Directory forests with Java schema extensions are exposed to malicious code injection through extended attributes, enabling attackers to escalate privileges and execute arbitrary commands.