AD domain with multiple failed authentication attempts by non-existing users using Kerberos

Multiple failed Kerberos authentication attempts by non-existent users indicate a potential password spraying attack, exposing credentials and permissions.
AD object with modified msDS-KeyCredentialLink
Active Directory objects with modified msDS-KeyCredentialLink expose users to persistent access attacks through unauthorized key pair creation and encryption, enabling attackers to bypass normal authentication controls.
Honey account targeted with Kerberos pre-authentication attempts

Kerberos pre-authentication attempts against honey accounts expose credentials to attackers, enabling reconnaissance and potential compromise.
Microsoft Entra tenant with bulk changes of devices

Bulk device changes in a Microsoft Entra tenant can indicate unauthorized activity or mistakes, exposing attackers to sensitive areas and potential service disruptions.
AD user with suspicious password refresh

Active Directory user with suspicious password refresh exposes organization to potential password policy compromise, allowing attackers to manipulate settings.
Microsoft Entra user with authentication phone details modified by another user

Microsoft Entra users with modified authentication phone details may indicate unauthorized access or compromise, allowing attackers to receive multifactor authentication messages for a compromised account. This vulnerability exposes sensitive information and enables attack paths through administrative scope and credentials.
Entra user attempted to access LAPS password

An Entra user accessed LAPS password, exposing local admin credentials and enabling lateral movement through administrative account access.
Regular AD object with unexpected admincount value

Unexpected admincount values in AD objects may indicate unauthorized changes, allowing attackers to evade detection and plan future malicious operations.
Active Directory password in Group Policy Preferences (GPP) compromise

Active Directory password exposure in Group Policy Preferences (GPP) XML files allows attackers to decrypt passwords and access privileged accounts or systems.
Regular AD object with Migrate SID history permission

Attackers can migrate high-privilege SIDs into their own accounts via a regular AD object with Migrate SID history permission, gaining elevated access and privileges.