Insecure ACLs on Service Connection Points in Active Directory
Insecure ACLs on Service Connection Points in Active Directory expose sensitive data and enable man-in-the-middle attacks through unauthorized attribute modifications.
Conditional Access policy in Entra ID missing Continuous Access Evaluation (CAE)
Conditional Access policy in Entra ID missing Continuous Access Evaluation (CAE) exposes users to extended session duration after privilege elevation or credential compromise, enabling attackers to maintain access to sensitive resources for an extended period.
Constrained delegation with protocol transition to the krbtgt account
Constrained delegation with protocol transition to the krbtgt account enables attackers to compromise the trusted krbtgt account, impersonate users, and access network resources through Kerberos authentication mechanisms.
AD user with blank password
Active Directory user accounts without passwords are exposed to unauthorized access due to authentication bypass.
Active Directory SMB signing not enforced on domain controller
Microsoft Entra tenant where regular users can register applications

High-risk exposure in Microsoft Entra tenant where regular users can register applications, enabling attackers to expand their reach and gain persistence.
AD domain controller not changing its password

Domain controllers with outdated passwords expose sensitive information to attackers, enabling unauthorized access and potential breaches through pass-the-ticket (PtT) or pass-the-hash (PtH) attacks.
The certificate template has a key length of less than 2048 bits

A certificate template with a key length of less than 2048 bits exposes the organization to high-risk cryptographic vulnerabilities, enabling attackers to exploit weaknesses in random number generation and side-channel attacks.
Dangerous ACLs expose certificate containers

Critical: Non-default principals with elevated permissions on the NTAuthCertificates container expose certificate containers, enabling privilege escalation and CA compromise through attack paths.
AD domain with built-in domain Guest account enabled

An enabled domain guest account exposes the Active Directory environment to unauthorized access, enabling attackers to gather information for potential future attacks.