AD domain controller with enabled print spooler

Active Directory

A domain controller with enabled print spooler exposes domain credentials to remote connections, enabling attackers to compromise the domain controller or other systems through Kerberos authentication attacks.

Built-in domain Administrator account used recently

Active Directory

Built-in domain Administrator account usage indicates potential unauthorized access to high-privilege credentials, exposing the organization to attack paths through administrative scope and credential misuse.

DNS zone allowing unsecure update

Active Directory

A DNS zone allowing unsecure update enables attackers to modify records without authentication, exposing users to malicious servers via DNS spoofing and cache poisoning.

AD Domain Controller with non-admin owner

Active Directory

A non-administrator owning an AD Domain Controller poses a significant risk due to potential privilege escalation through unauthorized group membership, exposing attack paths and administrative scope.