Short-lived privileged AD object

Active Directory

Elevated permissions can be temporarily gained through short-lived privileged AD objects, exposing sensitive resources to unauthorized access.

Computer not resetting its password periodically

Active Directory

A non-expiring password on a computer account may indicate unauthorized access or control, allowing attackers to use pass-through authentication and potentially leading to more serious compromise.

AD object created by unusual Initiator

Active Directory

Cayosoft Guardian detects anomalous Active Directory account creation by unusual Initiators, exposing potential attack paths and helping administrators investigate and remediate security issues.

AD object with non-default primary group

Active Directory

Attackers can silently inherit elevated permissions and hide persistence in Active Directory through group membership manipulation by targeting a domain account with non-default primary group membership.