Security Findings
Detailed view of all vulnerabilities and misconfigurations across assessments.
1 Critical
2 High
2 Medium
| Severity | Finding | Asset | Category | Status |
|---|---|---|---|---|
| critical | RDP Exposed to Network Direct access to remote desktop allows for brute-force or exploitation. | SRV-DC-01 | Network | open |
| high | LDAP Signing Not Enforced Exposure to LDAP relay / MITM attacks. | CONTOSO.LOCAL | Active Directory | in progress |
| high | Weak Password Policy Simple passwords can be easily cracked via brute-force or spraying. | CONTOSO.LOCAL | Active Directory | open |
| medium | Inactive Administrator Accounts Old admin accounts are prime targets for takeover. | SRV-FS-02 | Active Directory | remediated |
| medium | Unencrypted HTTP Service Cleartext communication allows credential sniffing. | WEB-PRD-01 | Network | open |