Skip to content

User Defined Rules

Muhammad Ali edited this page Mar 23, 2025 · 9 revisions

Current Built-in Rules

ID Name Description Severity Key Conditions
VULN-001 Kerberoastable Kerberoastable account Medium - Has SPN
- Not disabled
- Not a computer account
- AdminCount != 1
VULN-001 Kerberoastable High Privilege Kerberoastable high privilege account Medium - Has SPN
- AdminCount = 1
- Not disabled
- Not a computer account
VULN-002 Password Never Expires User account with password that never expires Low - DONT_EXPIRE_PASSWORD flag
- Is user account
- Not MSOL_ account
VULN-003 Password Not Required User account with password not required High - PASSWD_NOTREQD flag
- Is user account
- Not disabled
VULN-004 Admin with Reversible Encryption Admin account with reversible encryption enabled High - ENCRYPTED_TEXT_PWD_ALLOWED flag
- Is user account
- Not disabled
VULN-005 Unconstrained Delegation Account has unconstrained delegation enabled High - TRUSTED_FOR_DELEGATION flag
- Not disabled
VULN-006 Old Password Account with old password (>90 days) Medium - Password last set > 90 days
- Is user account
- Not disabled
VULN-007 Inactive Account Inactive account (no login >30 days) Low - Last logon > 30 days
- Is user account
- Not disabled
VULN-009 ASREPRoastable User account does not require Kerberos preauthentication High - DONT_REQ_PREAUTH flag
- Is user account
- Not disabled
VULN-010 SMB Signing Disabled Computer with SMB signing disabled High - Has DNS hostname
- Has operating system
- Not disabled
VULN-011 Constrained Delegation Account configured for constrained delegation Medium - Has msDS-AllowedToDelegateTo
- Not disabled
VULN-012 Resource Based Constrained Delegation Account vulnerable to resource-based constrained delegation High - Has msDS-AllowedToActOnBehalfOfOtherIdentity
- Not disabled
VULN-013 Empty Password Account with empty password Critical - PASSWD_NOTREQD flag
- pwdLastSet = 0
- Not disabled
VULN-014 Never Logged On Account that has never logged on Medium - lastLogon = 0
- Not disabled
VULN-015 Admin with Plain Text Password Admin account with password stored in reversible encryption Critical - Member of Administrators
- ENCRYPTED_TEXT_PWD_ALLOWED flag
- Not disabled
VULN-016 DC Auth Policy Domain Controller with weak authentication policy High - Is DC (primaryGroupID=516)
- SERVER_TRUST_ACCOUNT
- No AES256 support
VULN-019 Inactive Admin Inactive administrator account High - Member of Domain Admins
- Last logon > 30 days
- Not default Administrator
- Not disabled
VULN-020 Admin Account Delegation Admin account with delegation enabled High - Member of Domain Admins
- NOT_DELEGATED flag not set
- Not disabled
VULN-021 Default KRBTGT Password KRBTGT account password may never have been changed Critical - Is krbtgt account
- Password older than 180 days
VULN-022 RODC Password Replication Sensitive account allowed for password replication to RODCs High - In Allowed RODC Password Replication Group
- Member of Domain Admins
- Not disabled

Getting Started

Use Cases

Available Modules

LDAP Operations
GPO
Computer Enumeration
ADCS
Exchange
Domain Trust
Service Accounts
Shadow Credentials
Misc

Web UI

Usage
API Documentation

Integrations

Sponsor

Clone this wiki locally