AD user added to privileged group

Active Directory

Attackers can escalate privileges and access sensitive data through unauthorized access when a user is added to a privileged Active Directory group.

AD domain with bulk changes of users

Active Directory

Active Directory bulk user changes can indicate unauthorized access or administrative errors, potentially leading to service disruptions through lateral movement or privilege escalation.

Short-lived privileged AD object

Active Directory

Elevated permissions can be temporarily gained through short-lived privileged AD objects, exposing sensitive resources to unauthorized access.

Stale administrative account in AD domain

Active Directory

A stale administrative account in Active Directory exposes elevated privileges and cached credentials, enabling potential privilege escalation and reconnaissance.

AD domain controller with SMB1 enabled

Active Directory

A domain controller with SMB1 enabled exposes a high-risk vulnerability that attackers can exploit for remote code execution via the SMBv1 protocol, allowing lateral movement and privilege escalation within the domain.