AD object with non-default primary group

Active Directory

Attackers can silently inherit elevated permissions and hide persistence in Active Directory through group membership manipulation by targeting a domain account with non-default primary group membership.

Exchange-related AD group with excessive permissions

Active Directory

Attackers exploiting Exchange-related AD group with excessive permissions can reset passwords, add accounts to sensitive groups, or modify ACLs due to assigned FullControl, WriteDACL, ForceChangePassword, or AddMember permissions.