AD object with schema update permissions
Attackers can exploit AD object with schema update permissions to compromise forest integrity through unauthorized attribute and object creation.
Constrained delegation with protocol transition to the krbtgt account
Constrained delegation with protocol transition to the krbtgt account enables attackers to compromise the trusted krbtgt account, impersonate users, and access network resources through Kerberos authentication mechanisms.
AD user with blank password
Active Directory user accounts without passwords are exposed to unauthorized access due to authentication bypass.
Active Directory SMB signing not enforced on domain controller
AD domain controller not changing its password

Domain controllers with outdated passwords expose sensitive information to attackers, enabling unauthorized access and potential breaches through pass-the-ticket (PtT) or pass-the-hash (PtH) attacks.
Failed logon attempts targeting honey account

Failed logon attempts targeting honey accounts in Active Directory may indicate brute-force attacks or reconnaissance activity, exposing administrative scope and attacker capability.
Dangerous ACLs expose certificate containers

Critical: Non-default principals with elevated permissions on the NTAuthCertificates container expose certificate containers, enabling privilege escalation and CA compromise through attack paths.
AD domain with built-in domain Guest account enabled

An enabled domain guest account exposes the Active Directory environment to unauthorized access, enabling attackers to gather information for potential future attacks.
AD object with privileged SIDs in the sIDHistory

Active Directory objects with privileged SIDs in their SIDHistory attribute can be exploited by attackers for privilege escalation and unauthorized access. Cayosoft Guardian detects and alerts on this critical security risk, providing visibility into attack paths and persistence.
AD object with non-default permissions on AdminSDHolder

Attackers can exploit non-default permissions on AdminSDHolder to modify protected objects’ permissions, gaining elevated access and compromising domain security.