AD domain with restored domain controllers

Attackers can modify user account access and evade detection through restored domain controllers in Active Directory, allowing unauthorized password resets or group membership modifications.
Privileged AD user with failed logon attempts

A Privileged AD user with failed logon attempts may indicate an unauthorized access attempt against a high-value domain account, exposing attack paths and administrative scope.
Microsoft Entra tenant with unsecure app consent policy configuration

A tenant policy allowing any user to grant app access without admin consent exposes users to consent phishing via unsecured app permissions.
AD domain with bulk changes of groups

Active Directory bulk group changes can indicate malicious activity or errors, leading to service disruptions and unauthorized access.
AD domain with bulk changes of computers

Active Directory bulk changes can indicate unauthorized modifications or mistakes, impacting service availability and exposing attack paths.
Microsoft Entra user retrieving Bitlocker keys

Unauthorized Microsoft Entra users accessing BitLocker recovery keys enable attackers to decrypt drives and gain unauthorized data access, exposing sensitive information through administrative scope.
Stale Microsoft Entra device

Stale Microsoft Entra devices expose credentials and increase attack surface, allowing attackers to access company resources through primary refresh tokens.
Microsoft Entra guest account with unredeemed invite

Unredeemed Microsoft Entra guest account invitations can be exploited by attackers to create persistence, increasing risk of credential exposure through authentication and authorization mechanisms.
Microsoft Entra tenant with bulk changes of users

Bulk user changes in Microsoft Entra tenant may indicate unauthorized access, administrative mistakes, or malicious activity.
Rejected PIM role membership request from Microsoft Entra user

Unauthorized privilege escalation attempts via rejected PIM role membership requests from Microsoft Entra users may indicate a compromised account, exposing attack paths for persistence and reconnaissance.