AD computer with traces of DCShadow attack

Active Directory computer objects with DCShadow attack traces expose potential unauthorized access and manipulation of security settings through attacker-controlled domain controllers.
Privileged AD user account with associated SPNs

Attackers can exploit Privileged AD user accounts with associated SPNs for lateral movement and credential access due to elevated privileges and Kerberos Service Ticket capabilities.
AD Krbtgt account password was not reset recently

Active Directory (AD) is exposed to potential golden ticket and pass-the-hash attacks due to an unchanged Kerberos ticket-granting service account password.
Privileged Microsoft Entra account synced from on-premise

Attackers can access Microsoft Entra resources with elevated permissions due to direct membership in administrative roles from a compromised on-premises account synced from Active Directory.
Privileged AD user synced to Microsoft Entra ID

Privileged AD users are synced to Microsoft Entra ID, exposing sensitive resources to unauthorized access.
Insufficient forest and domain functional levels

A low forest and domain functional level exposes your Active Directory environment to critical vulnerabilities, making it easier for attackers to exploit deprecated protocols and escalate privileges.
AD domain with Operator Groups that are not empty

Attackers can exploit non-empty Operator Groups in an AD domain, gaining unauthorized access and escalating privileges.
AD Domain with executable files in SYSVOL

Executable files in SYSVOL may be infected, enabling attackers to maintain persistence through Active Directory forest recovery.
Regular AD object with access to gMSA passwords

Regular AD objects with access to gMSA passwords pose a risk of unauthorized access due to improper permissions, which Cayosoft Guardian detects and alerts administrators to mitigate.
Resource-based constrained delegation on domain controllers

Domain controllers with resource-based constrained delegation enabled expose sensitive resources to unauthorized access via user impersonation.