AD domain with restored domain controllers

Active Directory

Attackers can modify user account access and evade detection through restored domain controllers in Active Directory, allowing unauthorized password resets or group membership modifications.

Microsoft Entra user retrieving Bitlocker keys

Active Directory

Unauthorized Microsoft Entra users accessing BitLocker recovery keys enable attackers to decrypt drives and gain unauthorized data access, exposing sensitive information through administrative scope.

Stale Microsoft Entra device

Entra ID

Stale Microsoft Entra devices expose credentials and increase attack surface, allowing attackers to access company resources through primary refresh tokens.