AD user with identical password
Attackers can access multiple AD user accounts with identical passwords without additional authentication efforts, increasing exposure and attack paths.
AD domain controller allowing authentication with keys vulnerable to ROCA
AD domain allowing multicast name resolution (LLMNR)
Active Directory domains enabling Multicast Name Resolution (LLMNR) expose networks to spoofing and credential-harvesting attacks via intercepted DNS requests, allowing attackers to gather user credentials or redirect traffic.
AD user account with compromised password
Exposure of Active Directory user account passwords allows attackers to authenticate, but not necessarily escalate privileges.
AD domain with misconfigured PowerShell logging policies
A misconfigured PowerShell logging policy exposes an Active Directory domain to attackers who can evade detection through PowerShell-based reconnaissance and persistence.
AD privileged account password reset or unlock
Unauthorized password reset or account unlock for a privileged Active Directory account can expose sensitive data and enable attackers to escalate privileges.
NTLM auditing not enabled in Active Directory
NTLM auditing not enabled in Active Directory exposes organizations to credential relay and lateral movement attacks through legacy protocol weaknesses.
AD account configured or modified to use RC4 encryption
Active Directory accounts using RC4 encryption are vulnerable to password cracking and forged Kerberos tickets, enabling lateral movement and data breach.
Active Directory SMB signing not enforced on domain controller
Active Directory SMB signing not enforced on domain controllers exposes SMB traffic to tampering and relay-style attacks, enabling attackers to bypass authentication and access sensitive data.
Insecure ACLs on Service Connection Points in Active Directory
Insecure ACLs on Service Connection Points in Active Directory expose sensitive data and enable man-in-the-middle attacks through unauthorized attribute modifications.