Entra object created by unusual Initiator
AD user account with compromised password
Exposure of Active Directory user account passwords allows attackers to authenticate, but not necessarily escalate privileges.
Entra user account with compromised password
Entra user account with compromised password exposes internal domains to public breaches, enabling attackers to exploit exposed credentials and gain unauthorized access.
AD domain with misconfigured PowerShell logging policies
A misconfigured PowerShell logging policy exposes an Active Directory domain to attackers who can evade detection through PowerShell-based reconnaissance and persistence.
AD object with schema update permissions
Attackers can exploit AD object with schema update permissions to compromise forest integrity through unauthorized attribute and object creation.
AD user with blank password
Active Directory user accounts without passwords are exposed to unauthorized access due to authentication bypass.
AD object with privileged SIDs in the sIDHistory

Active Directory objects with privileged SIDs in their SIDHistory attribute can be exploited by attackers for privilege escalation and unauthorized access. Cayosoft Guardian detects and alerts on this critical security risk, providing visibility into attack paths and persistence.
AD object with non-default permissions on AdminSDHolder

Attackers can exploit non-default permissions on AdminSDHolder to modify protected objects’ permissions, gaining elevated access and compromising domain security.
AD computer with traces of DCShadow attack

Active Directory computer objects with DCShadow attack traces expose potential unauthorized access and manipulation of security settings through attacker-controlled domain controllers.
Microsoft Entra tenant with bulk changes of groups

Bulk group changes in your Microsoft Entra tenant may indicate unauthorized access or service disruptions.