Private IP addresses in Entra ID Conditional Access policy
Attackers can misuse private IP addresses in Entra ID Conditional Access policies to evade access control boundaries and gain initial access.
Entra object created by unusual Initiator
AD domain controller allowing authentication with keys vulnerable to ROCA
AD object with privileged SIDs in the sIDHistory

Active Directory objects with privileged SIDs in their SIDHistory attribute can be exploited by attackers for privilege escalation and unauthorized access. Cayosoft Guardian detects and alerts on this critical security risk, providing visibility into attack paths and persistence.
AD object with non-default permissions on AdminSDHolder

Attackers can exploit non-default permissions on AdminSDHolder to modify protected objects’ permissions, gaining elevated access and compromising domain security.
AD computer with traces of DCShadow attack

Active Directory computer objects with DCShadow attack traces expose potential unauthorized access and manipulation of security settings through attacker-controlled domain controllers.
Microsoft Entra tenant with recent changes in Cross Tenant Access configuration

Unauthorized access or privilege escalation risk due to misconfigured Entra cross-tenant access synchronization.
Insufficient forest and domain functional levels

A low forest and domain functional level exposes your Active Directory environment to critical vulnerabilities, making it easier for attackers to exploit deprecated protocols and escalate privileges.
Resource-based constrained delegation on domain controllers

Domain controllers with resource-based constrained delegation enabled expose sensitive resources to unauthorized access via user impersonation.
Folder on SYSVOL with non-default access permissions

SYSVOL folder with non-standard access permissions exposes sensitive information to unauthorized users.