AD domain with unsecure RBCD delegation on domain controllers

Attackers can impersonate any user via unsecure Resource-Based Constrained Delegation (RBCD) on domain controllers, enabling unauthorized access to sensitive resources and data.
Exchange-related AD group with excessive permissions

Attackers exploiting Exchange-related AD group with excessive permissions can reset passwords, add accounts to sensitive groups, or modify ACLs due to assigned FullControl, WriteDACL, ForceChangePassword, or AddMember permissions.
Active directory dangerous user rights assignments on domain controllers

High-severity Active Directory user rights assignments on domain controllers expose sensitive privileges to non-admin users, enabling privilege escalation and persistence.
AD domain with non-default permissions on krbtgt account

A domain with non-default permissions on the krbtgt account exposes attackers to creating a Golden Ticket, granting unauthorized Kerberos authentication.
Unauthorized certificate addition to Entra ID Enterprise Application

Unauthorized Entra ID Enterprise Application certificates can be added by attackers, allowing them to authenticate without MFA due to compromised credentials.
Microsoft Entra Global Administrator with elevated access to Azure Resources

Elevated Azure resource access by a Global Admin exposes sensitive data to potential attacks through unfiltered access.
AD user with compromised password

Attackers can exploit exposed password hashes in Active Directory user accounts, enabling unauthorized access and potential privilege escalation.
AD user account with DES encryption type enabled

Active Directory user accounts using outdated DES encryption type are exposed to brute-force attacks, allowing unauthorized access.
Privileged AD object with permissions allowing takeover by regular user

A privileged Active Directory object with misconfigured permissions allows regular users to take control, exposing sensitive resources and escalating privileges.
Built-in domain Administrator account used recently

Built-in domain Administrator account usage indicates potential unauthorized access to high-privilege credentials, exposing the organization to attack paths through administrative scope and credential misuse.