AD domain with multiple failed authentication attempts via process

Multiple failed authentication attempts via process in an Active Directory domain expose attack paths and allow attackers to obtain initial access or elevate privileges.
Short-lived privileged AD object

Elevated permissions can be temporarily gained through short-lived privileged AD objects, exposing sensitive resources to unauthorized access.
Stale administrative account in AD domain

A stale administrative account in Active Directory exposes elevated privileges and cached credentials, enabling potential privilege escalation and reconnaissance.
AD domain controller with SMB1 enabled

A domain controller with SMB1 enabled exposes a high-risk vulnerability that attackers can exploit for remote code execution via the SMBv1 protocol, allowing lateral movement and privilege escalation within the domain.
AD domain controller allowing vulnerable Netlogon secure channel connections

An unauthenticated attacker can exploit a domain controller’s vulnerable Netlogon secure channel connection, changing AD passwords and escalating privileges.
Security principals with dangerous replication permissions

Active Directory security principals with Replicate Changes All permission enable attackers to execute DCSync attacks, exposing all user passwords.
User account with old passwords

Old Active Directory passwords expose users to unauthorized access if not regularly updated.
Microsoft Entra tenant with unsecure configuration of user risk policy

An unsecure user risk policy in Microsoft Entra tenant exposes users to unnecessary access risks due to inadequate password change requirements, enabling attackers to gather information and plan future malicious operations.
AD object created by unusual Initiator

Cayosoft Guardian detects anomalous Active Directory account creation by unusual Initiators, exposing potential attack paths and helping administrators investigate and remediate security issues.
AD computer using dNSHostName that belongs to another computer account

Attackers can exploit dNSHostName attribute modifications in Active Directory to impersonate computer accounts, compromising certificate-based authentication.