AD object with schema update permissions
Attackers can exploit AD object with schema update permissions to compromise forest integrity through unauthorized attribute and object creation.
AD domain controller not changing its password

Domain controllers with outdated passwords expose sensitive information to attackers, enabling unauthorized access and potential breaches through pass-the-ticket (PtT) or pass-the-hash (PtH) attacks.
Dangerous ACLs expose certificate containers

Critical: Non-default principals with elevated permissions on the NTAuthCertificates container expose certificate containers, enabling privilege escalation and CA compromise through attack paths.
Dangerous enrollment permission on authentication certificate templates

Misconfigured certificate templates expose Active Directory Certificate Services to unauthorized users obtaining high-privilege certificates due to excessive enrollment permission.
AD object with privileged SIDs in the sIDHistory

Active Directory objects with privileged SIDs in their SIDHistory attribute can be exploited by attackers for privilege escalation and unauthorized access. Cayosoft Guardian detects and alerts on this critical security risk, providing visibility into attack paths and persistence.
AD object with non-default permissions on AdminSDHolder

Attackers can exploit non-default permissions on AdminSDHolder to modify protected objects’ permissions, gaining elevated access and compromising domain security.
Privileged Microsoft Entra account not registered for MFA

Privileged Microsoft Entra accounts without multi-factor authentication (MFA) expose organizations to identity-based attacks via password-only authentication.
AD computer with traces of DCShadow attack

Active Directory computer objects with DCShadow attack traces expose potential unauthorized access and manipulation of security settings through attacker-controlled domain controllers.
Service principal promoted to privileged role via OAuth consent attack

Attackers exploit OAuth consent to promote malicious service principals, enabling long-term persistence in Entra ID. Cayosoft Guardian detects and mitigates this threat by monitoring OAuth consent logs and service principal permissions.
Security principals with dangerous replication permissions

Active Directory security principals with Replicate Changes All permission enable attackers to execute DCSync attacks, exposing all user passwords.