Security experts have reported on the risks faced by Active Directory. The service, which is built into most Windows Server operating systems, is the main way to manage Windows domain networks. However, this also hides the risk of being exploited by hackers
According to many information security professionals, Active Directory is the primary identity platform for many businesses around the world. It is used to connect different systems together and has therefore become a prime target for hackers. This is because if someone who intends to attack manages to get into Active Directory, then they could potentially have access to all the systems connected to that network.

A digital forensic investigation conducted by security firm Bitdefender has identified a cybercrime known as Carbanak, which has a malware called Cobalt Strike Beacon. Bitdefender said the malware has the ability to execute commands on systems, record keystrokes, take screenshots and even deploy memory manipulation tools such as Mimikatz or multiple Active Directory hosts. All of the above can help would-be hackers gain access to other systems.
Rapid7 released a report titled Under the Hoodie 2019. It summarized 180 penetration tests over a nine-month period. 40% of the tests focused on identifying vulnerabilities and exposing the organization to internet risks. 36%, on the other hand, focused on internal network assessments. According to the research, every business has at least one vulnerability that a hacker can exploit.
Of the vulnerabilities found during internal testing, Rapid7 said 11% contained credentials found in memory, which could potentially allow a hacker to access other systems. Meanwhile, 9% of all internal vulnerabilities involve Kerberosting.

Kerberosting is a term coined by Tim Medin. It is essentially a privilege escalation technique that has proven to be very effective in extracting service account credentials across a domain.
Many organizations use accounts with weak passwords, which have never expired and usually enjoy excessive privileges.
Last June, the department's inspector general said that inadequate management of Active Directory put the United States Patent and Trademark Office at risk.
Rapid7 tester Nick Powers, in the company's report, was looking for wireless and internal network vulnerabilities in a system of eight hospitals. The wireless network there seemed very well locked down. But the network had many non-standard devices, most of which were medical. Some were running outdated versions of Windows. One of them had accessed a user in the Active Directory service, which allowed the recovery of that user's credentials from memory.
Experts argue that there are specific defenses that should be created and operated in organizations to avoid such problems.
