AD Krbtgt account password was not reset recently

Active Directory (AD) is exposed to potential golden ticket and pass-the-hash attacks due to an unchanged Kerberos ticket-granting service account password.
Insufficient forest and domain functional levels

A low forest and domain functional level exposes your Active Directory environment to critical vulnerabilities, making it easier for attackers to exploit deprecated protocols and escalate privileges.
AD Domain with executable files in SYSVOL

Executable files in SYSVOL may be infected, enabling attackers to maintain persistence through Active Directory forest recovery.
Regular AD object with access to gMSA passwords

Regular AD objects with access to gMSA passwords pose a risk of unauthorized access due to improper permissions, which Cayosoft Guardian detects and alerts administrators to mitigate.
Folder on SYSVOL with non-default access permissions

SYSVOL folder with non-standard access permissions exposes sensitive information to unauthorized users.
AD domain with unsecure ESX authentication bypass

VMware ESXi host with unsecure AD authentication exposes attackers to exploit a vulnerability, bypassing access controls and gaining control over the system.
AD domain controller with SMB1 enabled

A domain controller with SMB1 enabled exposes a high-risk vulnerability that attackers can exploit for remote code execution via the SMBv1 protocol, allowing lateral movement and privilege escalation within the domain.
AD forest with anonymous access enabled over Name Service Provider Interface

Anonymous RPC-based binds via Name Service Provider Interface expose AD forest to reconnaissance and initial access.
AD domain controller allowing vulnerable Netlogon secure channel connections

An unauthenticated attacker can exploit a domain controller’s vulnerable Netlogon secure channel connection, changing AD passwords and escalating privileges.
Computer not resetting its password periodically

A non-expiring password on a computer account may indicate unauthorized access or control, allowing attackers to use pass-through authentication and potentially leading to more serious compromise.