AD computer with traces of DCShadow attack

Active Directory computer objects with DCShadow attack traces expose potential unauthorized access and manipulation of security settings through attacker-controlled domain controllers.
Privileged AD user account with associated SPNs

Attackers can exploit Privileged AD user accounts with associated SPNs for lateral movement and credential access due to elevated privileges and Kerberos Service Ticket capabilities.
AD Krbtgt account password was not reset recently

Active Directory (AD) is exposed to potential golden ticket and pass-the-hash attacks due to an unchanged Kerberos ticket-granting service account password.
Stale Microsoft Entra guest account

Stale Microsoft Entra guest accounts expose your Entra ID tenant to information collection by attackers through inactive user accounts.
Stale privileged Microsoft Entra user account

A stale privileged Microsoft Entra user account exposes sensitive access and increases attacker capability due to compromised credentials.
Privileged Microsoft Entra account synced from on-premise

Attackers can access Microsoft Entra resources with elevated permissions due to direct membership in administrative roles from a compromised on-premises account synced from Active Directory.
Privileged AD user synced to Microsoft Entra ID

Privileged AD users are synced to Microsoft Entra ID, exposing sensitive resources to unauthorized access.
Regular AD object with access to gMSA passwords

Regular AD objects with access to gMSA passwords pose a risk of unauthorized access due to improper permissions, which Cayosoft Guardian detects and alerts administrators to mitigate.
AD forest with recent changes to default security descriptor in schema

Active Directory schema modifications expose attack paths and persistence risks.
Stale administrative account in AD domain

A stale administrative account in Active Directory exposes elevated privileges and cached credentials, enabling potential privilege escalation and reconnaissance.