Privileged AD user not protected against delegation

A high-severity threat where a privileged AD user’s credentials are vulnerable to unauthorized delegation, enabling privilege escalation through Kerberos protocol exploitation.
AD user account with DES encryption type enabled

Active Directory user accounts using outdated DES encryption type are exposed to brute-force attacks, allowing unauthorized access.
Built-in domain Administrator account used recently

Built-in domain Administrator account usage indicates potential unauthorized access to high-privilege credentials, exposing the organization to attack paths through administrative scope and credential misuse.
AD computer account that is a member of privileged groups

A compromised AD computer account in a privileged group enables persistent lateral movement within the domain.