Exchange-related AD group with excessive permissions

Active Directory

Attackers exploiting Exchange-related AD group with excessive permissions can reset passwords, add accounts to sensitive groups, or modify ACLs due to assigned FullControl, WriteDACL, ForceChangePassword, or AddMember permissions.

AD user with compromised password

Active Directory

Attackers can exploit exposed password hashes in Active Directory user accounts, enabling unauthorized access and potential privilege escalation.

Built-in domain Administrator account used recently

Active Directory

Built-in domain Administrator account usage indicates potential unauthorized access to high-privilege credentials, exposing the organization to attack paths through administrative scope and credential misuse.