AD user with suspicious password refresh

Active Directory user with suspicious password refresh exposes organization to potential password policy compromise, allowing attackers to manipulate settings.
Microsoft Entra user with authentication phone details modified by another user

Microsoft Entra users with modified authentication phone details may indicate unauthorized access or compromise, allowing attackers to receive multifactor authentication messages for a compromised account. This vulnerability exposes sensitive information and enables attack paths through administrative scope and credentials.
Regular AD object with unexpected admincount value

Unexpected admincount values in AD objects may indicate unauthorized changes, allowing attackers to evade detection and plan future malicious operations.
Privileged AD user with failed logon attempts

A Privileged AD user with failed logon attempts may indicate an unauthorized access attempt against a high-value domain account, exposing attack paths and administrative scope.
AD domain with bulk changes of groups

Active Directory bulk group changes can indicate malicious activity or errors, leading to service disruptions and unauthorized access.
AD domain with bulk changes of computers

Active Directory bulk changes can indicate unauthorized modifications or mistakes, impacting service availability and exposing attack paths.
Microsoft Entra user retrieving Bitlocker keys

Unauthorized Microsoft Entra users accessing BitLocker recovery keys enable attackers to decrypt drives and gain unauthorized data access, exposing sensitive information through administrative scope.
Microsoft Entra tenant with bulk changes of users

Bulk user changes in Microsoft Entra tenant may indicate unauthorized access, administrative mistakes, or malicious activity.
Rejected PIM role membership request from Microsoft Entra user

Unauthorized privilege escalation attempts via rejected PIM role membership requests from Microsoft Entra users may indicate a compromised account, exposing attack paths for persistence and reconnaissance.
AD user with identical password
Attackers can access multiple AD user accounts with identical passwords without additional authentication efforts, increasing exposure and attack paths.