Entra object created by unusual Initiator
Constrained delegation with protocol transition to the krbtgt account
Constrained delegation with protocol transition to the krbtgt account enables attackers to compromise the trusted krbtgt account, impersonate users, and access network resources through Kerberos authentication mechanisms.
Active Directory SMB signing not enforced on domain controller
Privileged AD user account with associated SPNs

Attackers can exploit Privileged AD user accounts with associated SPNs for lateral movement and credential access due to elevated privileges and Kerberos Service Ticket capabilities.
Entra ID application owner attribute populated with a hybrid user account

A hybrid user account set as Entra ID application owner attribute may lead to unauthorized access and privilege escalation through compromised credentials or exploited permissions.
Resource-based constrained delegation on domain controllers

Domain controllers with resource-based constrained delegation enabled expose sensitive resources to unauthorized access via user impersonation.
AD domain allowing NTLM authentication

AD domains using NTLM authentication expose sensitive information, enabling attackers to gather domain details through unauthorized access.
AD object created by unusual Initiator

Cayosoft Guardian detects anomalous Active Directory account creation by unusual Initiators, exposing potential attack paths and helping administrators investigate and remediate security issues.
AD domain with misconfigured LDAP signing policy on the domain controllers

A misconfigured LDAP signing policy on Active Directory domain controllers exposes the environment to man-in-the-middle attacks, allowing attackers to intercept authentication traffic.
AD domain with misconfigured UNC paths policies

Active Directory misconfigurations expose authentication traffic, allowing attackers to intercept credentials or impersonate domain controllers via NTLM relay and SMB downgrade vulnerabilities.