AD user with compromised password

Active Directory

Attackers can exploit exposed password hashes in Active Directory user accounts, enabling unauthorized access and potential privilege escalation.

AD domain controller with enabled print spooler

Active Directory

A domain controller with enabled print spooler exposes domain credentials to remote connections, enabling attackers to compromise the domain controller or other systems through Kerberos authentication attacks.

Built-in domain Administrator account used recently

Active Directory

Built-in domain Administrator account usage indicates potential unauthorized access to high-privilege credentials, exposing the organization to attack paths through administrative scope and credential misuse.

DNS zone allowing unsecure update

Active Directory

A DNS zone allowing unsecure update enables attackers to modify records without authentication, exposing users to malicious servers via DNS spoofing and cache poisoning.