AD forest with anonymous access enabled over Name Service Provider Interface

Anonymous RPC-based binds via Name Service Provider Interface expose AD forest to reconnaissance and initial access.
Anonymous access enabled in AD forest

Enabled anonymous access in Active Directory (AD) forest exposes sensitive information via LDAP queries, allowing unauthenticated users to gather user and group details.
AD forest is not protected against forest-wide failure by Cayosoft Guardian

A high-severity threat where an AD forest lacks a safeguard to quickly recover from catastrophic events like ransomware attacks or directory data corruption, exposing it to prolonged downtime, significant data loss, and substantial business disruption.
AD domain with misconfigured LDAP signing policy on the domain controllers

A misconfigured LDAP signing policy on Active Directory domain controllers exposes the environment to man-in-the-middle attacks, allowing attackers to intercept authentication traffic.
AD domain with misconfigured UNC paths policies

Active Directory misconfigurations expose authentication traffic, allowing attackers to intercept credentials or impersonate domain controllers via NTLM relay and SMB downgrade vulnerabilities.
Persistent membership detected in Active Directory Schema Admins group

Active Directory Schema Admins group membership persistence exposes forest-wide schema modification capabilities to attackers.
AD forest with Recycle Bin not enabled

A disabled Active Directory Recycle Bin exposes deleted objects to permanent loss through lack of restoration capabilities, enabling attackers to delete critical objects without fear of recovery.
AD forest with high numbers of privileged group accounts

A high number of privileged group accounts in an Active Directory forest exposes administrators to unauthorized access and privilege escalation through lateral movement.
AD Domain where Enterprise Key Admins group has full access to the domain

Attackers can exploit a domain group with excessive permissions in Active Directory to perform DCSync attacks and compromise the forest.
Active Directory Dangerous ACLs expose DFSR settings objects of the SYSVOL share

Active Directory Dangerous ACLs expose SYSVOL share replication settings, allowing attackers to exploit privilege escalation or persistence through unauthorized DFSR modifications.