AD domain with multiple failed authentication attempts via Kerberos

Multiple failed Kerberos authentications against an AD domain expose users to password guessing attacks, enabling attackers to plan and execute a targeted attack.
Regular AD user with permission to link GPOs

A regular AD user with permission to link GPOs can exploit group membership to elevate their permissions, exposing Active Directory domain security to potential attack paths.
AD domain with multiple failed remote authentication attempts

Multiple failed remote authentication attempts against an Active Directory domain may indicate a potential Password Spraying attack, which can be mitigated by Cayosoft Guardian’s detection and alerting capabilities.
AD domain with multiple failed authentication attempts by non-existing users using Kerberos

Multiple failed Kerberos authentication attempts by non-existent users indicate a potential password spraying attack, exposing credentials and permissions.
Unauthorized changes to compliance policies

Unauthorized changes to compliance policies expose devices to security risks by allowing non-compliant or compromised devices to access corporate resources through modified configuration settings.
Multiple inbox rules created in an Exchange Online mailbox within a short period

Attackers use multiple inbox rules in Exchange Online mailboxes within a short period to evade detection and maintain unauthorized access, indicating high severity.
Detected a malicious inbox rule to conceal email in Exchange Online

A malicious inbox rule in Exchange Online conceals emails, aiding Business Email Compromise attacks, exposing your organization to unauthorized data access and financial losses.
Unusual device wipe activity

Bulk device wipes within a short time frame indicate potential unauthorized access or malicious activity, exposing an organization’s devices and data integrity.
AD object with modified msDS-KeyCredentialLink
Active Directory objects with modified msDS-KeyCredentialLink expose users to persistent access attacks through unauthorized key pair creation and encryption, enabling attackers to bypass normal authentication controls.
Microsoft Entra tenant with bulk changes of devices

Bulk device changes in a Microsoft Entra tenant can indicate unauthorized activity or mistakes, exposing attackers to sensitive areas and potential service disruptions.