+Sensitive data was identified within the Active Directory environment and is accessible without authentication, or with permissions that are overly broad for authenticated domain users. The sensitive information is accessible due to open file share, the domain controller accepting LDAP queries without authentication, or due to other misconfigurations An attacker can take advantage of these misconfigurations to browse and download sensitive content, such as credentials, internal infrastructure diagrams, database backups, source code, financial records, or personally identifiable information.
0 commit comments