Failed logon attempts targeting honey account

Active Directory

Failed logon attempts targeting honey accounts in Active Directory may indicate brute-force attacks or reconnaissance activity, exposing administrative scope and attacker capability.

AD user added to privileged group

Active Directory

Attackers can escalate privileges and access sensitive data through unauthorized access when a user is added to a privileged Active Directory group.

Exchange-related AD group with excessive permissions

Active Directory

Attackers exploiting Exchange-related AD group with excessive permissions can reset passwords, add accounts to sensitive groups, or modify ACLs due to assigned FullControl, WriteDACL, ForceChangePassword, or AddMember permissions.

AD user with compromised password

Active Directory

Attackers can exploit exposed password hashes in Active Directory user accounts, enabling unauthorized access and potential privilege escalation.