AD user with blank password
Active Directory user accounts without passwords are exposed to unauthorized access due to authentication bypass.
Suspicious Global Administrator sign-in in Entra ID
A sign-in from a Global Administrator account in Entra ID indicates potential credential compromise or malicious reconnaissance, warranting immediate investigation.
Entra user account with compromised password
Entra user account with compromised password exposes internal domains to public breaches, enabling attackers to exploit exposed credentials and gain unauthorized access.
AD user account with compromised password
Exposure of Active Directory user account passwords allows attackers to authenticate, but not necessarily escalate privileges.
Private IP addresses in Entra ID Conditional Access policy
Attackers can misuse private IP addresses in Entra ID Conditional Access policies to evade access control boundaries and gain initial access.
AD domain with built-in domain Guest account enabled

An enabled domain guest account exposes the Active Directory environment to unauthorized access, enabling attackers to gather information for potential future attacks.
Microsoft Entra tenant has Exchange Organization without mail-flow rules restricting attachments with executables

Exchange Organization without mail-flow rules restricting attachments with executables exposes organizations to attack via email-borne malware and scripts.
AD domain with multiple failed authentication attempts via process

Multiple failed authentication attempts via process in an Active Directory domain expose attack paths and allow attackers to obtain initial access or elevate privileges.
AD forest with anonymous access enabled over Name Service Provider Interface

Anonymous RPC-based binds via Name Service Provider Interface expose AD forest to reconnaissance and initial access.
Anonymous access enabled in AD forest

Enabled anonymous access in Active Directory (AD) forest exposes sensitive information via LDAP queries, allowing unauthenticated users to gather user and group details.