AD user has a password that matches its sAMAccountName

Predictable password pattern in Active Directory exposes users to brute-force attacks, compromising account security and allowing unauthorized access.
Microsoft Entra tenant with auditing disabled

A disabled auditing feature in Microsoft Entra tenant exposes attackers to undetected activity, allowing them to persist and evade detection.
AD Delegated Managed Service Account (dMSA) object takeover by computer object
Attackers exploit dMSA delegation in Active Directory, gaining write access and escalating privileges through computer object impersonation, allowing them to modify sensitive objects and maintain persistence.
Service Principal promoted a service principal to privileged role members

Attackers can persist and elevate privileges when a service principal is promoted to a privileged role member.
Microsoft Entra cloud-only user with immutable ID set

Attackers can exploit a Microsoft Entra cloud-only user with an immutable ID set to gain direct access to sensitive data and systems, bypassing normal authentication and authorization controls.
AD domain with multiple failed authentication attempts from invalid users via NTLM

Multiple failed NTLM authentication attempts from invalid users in an Active Directory domain may indicate a Password Spraying attack, exposing the environment to potential reconnaissance and privilege escalation.
AD domain with multiple failed authentication attempts via Kerberos

Multiple failed Kerberos authentications against an AD domain expose users to password guessing attacks, enabling attackers to plan and execute a targeted attack.
AD domain with multiple failed remote authentication attempts

Multiple failed remote authentication attempts against an Active Directory domain may indicate a potential Password Spraying attack, which can be mitigated by Cayosoft Guardian’s detection and alerting capabilities.
AD domain with multiple failed authentication attempts by non-existing users using Kerberos

Multiple failed Kerberos authentication attempts by non-existent users indicate a potential password spraying attack, exposing credentials and permissions.
Honey account targeted with Kerberos pre-authentication attempts

Kerberos pre-authentication attempts against honey accounts expose credentials to attackers, enabling reconnaissance and potential compromise.