Regular AD object with unexpected admincount value

Unexpected admincount values in AD objects may indicate unauthorized changes, allowing attackers to evade detection and plan future malicious operations.
Computer with unsupported OS version in AD domain

Outdated OS versions in AD domains expose systems to security vulnerabilities, enabling attackers to exploit unpatched weaknesses.
Rejected PIM role membership request from Microsoft Entra user

Unauthorized privilege escalation attempts via rejected PIM role membership requests from Microsoft Entra users may indicate a compromised account, exposing attack paths for persistence and reconnaissance.
Password hash synchronization not enabled in hybrid environment

Password hash synchronization not enabled in hybrid environment exposes user credentials to attackers attempting unauthorized access through compromised credentials.
Entra user account with compromised password
Entra user account with compromised password exposes internal domains to public breaches, enabling attackers to exploit exposed credentials and gain unauthorized access.
AD domain controller allowing authentication with keys vulnerable to ROCA
AD user account with compromised password
Exposure of Active Directory user account passwords allows attackers to authenticate, but not necessarily escalate privileges.
Failed logon attempts targeting honey account

Failed logon attempts targeting honey accounts in Active Directory may indicate brute-force attacks or reconnaissance activity, exposing administrative scope and attacker capability.
AD object with privileged SIDs in the sIDHistory

Active Directory objects with privileged SIDs in their SIDHistory attribute can be exploited by attackers for privilege escalation and unauthorized access. Cayosoft Guardian detects and alerts on this critical security risk, providing visibility into attack paths and persistence.
AD object with non-default permissions on AdminSDHolder

Attackers can exploit non-default permissions on AdminSDHolder to modify protected objects’ permissions, gaining elevated access and compromising domain security.