Threat Directory

Welcome to the Cayosoft Threat Directory— a continuously updated hub of intelligence on hybrid identity attack techniques and detection patterns. It’s designed to empower security teams to turn alerts into actionable insights with detailed remediation steps, enabling fast, confident response across Active Directory, Entra ID, Intune, and Microsoft 365.

Cayosoft Threat Directory
Severity:
Threat Severity
CTD-000076
High
AD CS server vulnerable to NTLM relay attacks
An NTLM relay attack exploits the NTLM challenge-response mechanism. A threat actor intercepts legitimate authentication requests and then forwards them to the server. The client who originally sent the request receives the appropriate challenges, but the threat actor intercepts the responses and forwards them to the server, which then authenticates the attacker rather than the person or device that made the request.
Active Directory
Credential Access Privilege Escalation
CTD-000018
Critical
Microsoft Entra tenant with auditing disabled
In Microsoft Entra tenant with auditing disabled, user activities are not recorded in the auditing log. Without data from auditing log investigation of security issues might be difficult or impossible in some cases. A threat actor might disable auditing to perform some changes in your environment.
Entra ID
Defense Evasion
CTD-000012
Critical
Modified federation settings in Microsoft Entra domain

This rule checks if the domain's federation settings were recently modified.
When you federate your on-premises environment with Microsoft Entra ID, you establish a trust relationship between the on-premises identity provider and Microsoft Entra ID.
Due to this established trust, Microsoft Entra ID honours the security token issued by the on-premises identity provider post-authentication, to grant access to resources protected by Microsoft Entra ID. A malicious user might modify federation settings to get access to resources in Microsoft Entra ID.

Entra ID
Lateral Movement Persistence
CTD-000117
High
Microsoft Entra tenant with partner access via Delegated Administrative Privileges

A Microsoft Entra tenant configured to allow partner access through Delegated Administrative Privileges (DAP) poses a high-severity threat if not tightly monitored and restricted. This access model grants external partners elevated rights within the tenant, potentially including Global Administrator or other privileged roles.

The existence of DAP allows a partner organization to act on behalf of your tenant without needing per-activity approval or just-in-time access, which increases the attack surface. If a partner organization is compromised or acts maliciously, the threat actor could gain control over sensitive resources within your environment, bypass Conditional Access policies, or disable security configurations.

Furthermore, partner access may not show up in standard user audit logs, complicating the detection of misuse. If DAP accounts are unnecessary, it is highly recommended to eliminate them and implement Least Privilege Access, opting for more secure alternatives like Granular Delegated Admin Privileges (GDAP) instead.

Entra ID
Defense Evasion Initial Access Persistence Privilege Escalation
CTD-000145
High
Backup location with unencrypted AD backups

Encrypting Active Directory backups adds an extra layer of security to sensitive data like user credentials, group policies, and other sensitive data. Encrypting backups ensures that even if threat actors gain access to the backup files, they won't be able to read or misuse the information.

Encrypted backups are much safer in the event of a data breach. Even if threat actors manage to access the backup files, they won't be able to decipher the information without the encryption key, minimizing the impact of the breach. In addition, they guard against insider threats. Even employees with access to backup files won't be able to misuse the data if it's encrypted without the necessary decryption keys.

When transferring backup files over networks or storing them in cloud services, encryption ensures that the data remains secure throughout the transmission and storage, protecting it from interception or unauthorized access.

Active Directory Cayosoft Guardian
Collection Credential Access
CTD-000095
High
Entra ID tenant vulnerable to MFA fatigue attacks via voice authentication method
With increasing adoption of strong authentication, multi-factor authentication (MFA) fatigue attacks (aka, MFA spamming) have become more prevalent. These attacks rely on the user's ability to approve a simple voice notification that doesn't require the user to have context of the session they are authenticating. Anytime users are doing “press hash key” or “enter your PIN to approve” instead of entering a code they see on-screen, they are doing simple approvals. Microsoft's studies show that about 1% of users will accept a simple approval request on the first try. That's why it's critical to ensure that users must enter information from the login screen and that they have more context and protection. Number matching with "type the code" experience prevents accidental approval by requiring the user to type in a two-digit code from the login screen to their Authenticator app. If the user didn't initiate the sign-in, they won't know the two-digit code, thereby requiring the threat actor to share the two-digit code in a separate channel, which the user shouldn't accept.
Entra ID
Credential Access
CTD-000094
High
AD domain with unsecure configuration of Cloud Kerberos Trust

In a hybrid scenario, identities are synchronized from the on-premises AD to Microsoft Entra ID, with the on-premises AD being the authoritative source. Normally, lateral movement from the compromised on-premises AD to Microsoft Entra ID is more common, as information flows from on-premises to the cloud.

However, the Cloud Kerberos Trust model creates trust from the on-premises AD to Microsoft Entra ID, allowing authentication based on information from Microsoft Entra ID. A threat actor who obtains Global Admin privileges in Microsoft Entra ID can abuse this trust to escalate their privileges to Domain Admin. This means that the attacker, starting with control over Microsoft Entra ID, can gain control over the on-premises AD and potentially compromise the entire environment.

NOTE: Cayosoft Guardian defines privileged users in Active Directory as users with adminCount=1. By design Active Directory uses this attribute to protect members of administrative groups.

According to security best practices it is not recommended re-using admin accounts, instead these accounts must be de-provisioned. If an account has administrative permissions, it might also obtain access to other resources using these administrative permissions and keep this access even after it is removed from the administrative groups. Learn more about AdminSdHolder and SDProp - Microsoft Community Hub.

Active Directory Entra ID Hybrid
Credential Access
CTD-000160
High
Read-Only Domain Controller (RODC) in Inconsistent State

Read-Only Domain Controllers (RODCs) in an inconsistent state pose significant risks to the integrity and security of an Active Directory environment. RODCs are intended to provide a read-only replica of the Active Directory database, often in less secure locations. Inconsistent states due to replication failures, partial updates, or misconfigurations, can lead to outdated or incorrect data being served to clients, undermining authentication, authorization, and policy application. Additionally, threat actors may exploit this inconsistency to escalate privileges, bypass security controls, or compromise sensitive credentials cached on the RODC.

Active Directory
Defense Evasion Persistence Privilege Escalation
CTD-000156
High
Unauthorized changes to compliance policies

Unauthorized changes to compliance policies weaken your organization's security by potentially allowing non-compliant or compromised devices to access corporate resources. Such changes may indicate that a threat actor has gained administrative access and is attempting to bypass security controls. Monitoring compliance policy changes ensures that the integrity of your device management environment remains intact.

A threat actor who gains administrative access could alter compliance policies to reduce security requirements, allowing non-compliant devices (such as those lacking encryption or updated software) to access critical systems. By detecting these unauthorized changes, the organization can quickly respond and restore secure policies, mitigating the risk of compromised devices accessing sensitive resources.

Entra ID Intune
Defense Evasion Impair Defenses (T1562) Persistence Privilege Escalation
CTD-000182
High
Multiple inbox rules created in an Exchange Online mailbox within a short period

A threat actor who gains access to an Exchange Online mailbox may create multiple inbox rules to conceal emails - tactics commonly used in Business Email Compromise (BEC) attacks to evade detection and maintain access.

The threat is detected based on the creation of multiple new inbox rules in a given period of time.

Detection is scheduled to run regularly across all Entra tenants and will trigger an alert when particular number of new inbox rules are created in a particular period of time. Both the minimum rules number and the time period are adjustable in the Rule settings.

A threat actor who gains access to an Exchange Online mailbox may create a new inbox rule to delete, move, or forward incoming emails - tactics commonly used in Business Email Compromise (BEC) attacks to evade detection and maintain access.

The threat is detected based on the creation of new inbox rules that meet any of the following criteria:

  • Move emails to Deleted Items
  • Mark emails as Read
  • Forward emails to external domains

Detection is scheduled to run regularly across all Entra tenants and will trigger an alert when:

  • A new inbox rule with one or more of the above suspicious actions is created
  • The rule is created by someone other than the mailbox owner (e.g., via delegated access or compromised credentials)

NOTE: This threat rule includes a built-in lookback parameter set to 25 hours. Only events that occurred within this timeframe are processed by the rule.

Entra ID Exchange Online
Collection Defense Evasion
CTD-000174
High
Detected a malicious inbox rule to conceal email in Exchange Online

A threat actor who gains access to an Exchange Online mailbox may create a new inbox rule to delete, move, or forward incoming emails - tactics commonly used in Business Email Compromise (BEC) attacks to evade detection and maintain access.

The threat is detected based on the creation of new inbox rules that meet any of the following criteria:

  • Move emails to Deleted Items
  • Mark emails as Read
  • Forward emails to external domains

Detection is scheduled to run regularly across all Entra tenants and will trigger an alert when:

  • A new inbox rule with one or more of the above suspicious actions is created
  • The rule is created by someone other than the mailbox owner (e.g., via delegated access or compromised credentials)

NOTE: This threat rule includes a built-in lookback parameter set to 25 hours. Only events that occurred within this timeframe are processed by the rule.

Entra ID Exchange Online
Collection Defense Evasion
CTD-000155
High
Unusual device wipe activity

Bulk device wipes executed within a short time frame pose a serious threat to an organization's devices and data integrity. If an attacker gains access to administrative credentials, they could carry out large-scale wipes to eliminate evidence or disrupt business operations. This rule identifies instances where more than N device wipe or reset actions occur within a default 10-minute window (with both the value of N defaulting to 3 and the time interval set in the threat settings). Such activity is unusual and may indicate a coordinated attack targeting multiple devices.

If a threat actor gains access to administrative credentials, they could initiate multiple device wipes at the same time, resulting in significant data loss and operational disruption. In this situation, the malicious actor can erase several devices simultaneously, complicating efforts to recover data or track their activities. Early detection of bulk device wipes is crucial, as it minimizes the potential for widespread impact. This allows security teams to intervene and mitigate the damage before it spreads throughout the network.

NOTE: This threat rule includes a built-in lookback parameter set to 25 hours. Only events that occurred within this timeframe are processed by the rule.

Entra ID Intune
Impact
CTD-000177
Medium
Device enrolled in Intune but never synced

When a device is successfully enrolled in Intune but never performs a compliance check-in, it may indicate one of the following: the management agent failed to initialize, the user uninstalled the MDM profile, or the device was enrolled solely to satisfy Conditional Access requirements and was subsequently abandoned or hidden from management.

Entra ID Intune
Defense Evasion Initial Access
CTD-000114
Medium
AD-integrated DNS zone with WINS forward lookup enabled
The vulnerability related to WINS forwarding in AD-integrated DNS occurs when the DNS server performs a WINS forward lookup. This means that if the DNS server receives an address record query for which it does not have an answer, it sends a NBT-NS Query Request to a pre-configured WINS server. This process can be exploited by a threat actor who can forge DNS responses to compromise user accounts. This is because the DNS server trusts the responses it receives from the WINS server, even if they are not authentic. The threat actor can send malicious responses that trick the DNS server into providing incorrect information, potentially leading to security breaches or unauthorized access to sensitive information. As a result, it is important to properly secure the WINS server and the communication between the DNS server and WINS server to prevent this type of vulnerability.
Active Directory DNS
Credential Access
CTD-000133
Medium
External trust without SID filtering enabled

In certain scenarios, threat actors who have gained control of a domain controller in a trusted domain can exploit the SID history attribute (sIDHistory) to associate SIDs with new user accounts, thereby granting themselves unauthorized access. SID filter quarantining is enabled by default on all external trusts to mitigate this risk. This security feature ensures that only SIDs from the directly trusted domain or forest are considered valid by removing any SID references that do not pertain to them from inbound access requests.

However, administrators can turn off this setting, and older Active Directory trusts may not enable SID filtering. Threat actors can insert spoofed SIDs into access requests without SID filtering, potentially gaining unauthorized access. While SID filtering significantly enhances security by blocking such attacks, it can also cause operational issues if legitimate access relies on SID history or Universal Groups, potentially leading to denied access.

Enabling SID filter quarantining on a trust relationship restricts the trust to the specific domains on either side, breaking its transitivity. This means only SIDs from the directly trusted domain are valid, strengthening security by ensuring only authorized SIDs are accepted.

Active Directory
Defense Evasion
CTD-000113
Medium
AD forest with Java schema extension
A threat actor might add malicious code in the java attribute of an Active Directory object. Using Java Naming and Directory Interface threat actor might force an external application to execute pre-uploaded malicious code.
Active Directory
Defense Evasion Execution