The following Active Directory vulnerabilities have been added to Discoveries:

  • Credential Access:

    • Domain trust without Kerberos AES encryption enabled

    • Kerberos KRBTGT account password has not changed recently
  • Privilege Escalation:

    • Non-Tier Zero account can use a misconfigured certificate template to impersonate any user

    • Suspicious ESX Admins group detected in domain