Product
Active Directory
- First Reported
- Aug 15, 2026
- Latest Reported
- Oct 7, 2026
Reported Context (7)
- Content management systems, file hosting systems, Active Directory, Apache Log4j, Microsoft Windows, and remote desktop protocol each appear once. CYFIRMA Report Highlights Elevated Cyber Risks Facing the Education Sector
- [11] was deployed on a Linux server in Darktrace’s testing environment, which simulates a corporate Active Directory (AD) environment. The same environment included a benchmark server hosting the coding exercise’s Darktrace Tests Show AI Agents Hacking Simulated Corporate Networks to Cheat
- That combination makes it valuable for post-exploitation reconnaissance, lateral movement, and session hijacking across Active Directory estates. Using Impacket’s tstool to Control Windows Sessions and Hijack RDP Sessions
- The threat actor obtained domain admin-equivalent control of the organization’s Active Directory environment and authored a malicious Group Policy Object (GPO) named PAYLOAD, linking it at the domain root. PAYLOAD Ransomware Used Malicious Active Directory Policies to Disrupt a Manufacturing Firm
- The operator successfully extracted SAM and LSA secrets from nine Active Directory environments. In five environments, recovered domain-controller machine-account credentials enabled DRSUAPI-based DCSync attacks, Hunt.io Links UK Council Attack to SonicWall SMA1000 Exploitation Campaign
CVE (1)
Malware (1)
People (2)
Threat Actors (18)
MITRE ATT&CK (38)
Vendors (11)
Products (25)
Tools (25)
Industries (11)
Countries (32)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.