TestimoX

API Reference

Enum

PurpleKnightDoc

Namespace TestimoX.Baselines.Crosswalk
Assembly TestimoX
Base Enum
Implements
IComparable ISpanFormattable IFormattable IConvertible
Modifiers sealed

Purple Knight indicator identifiers used to cross-reference rules with vendor content.

Inheritance

  • Enum
  • PurpleKnightDoc

Values

public const PurpleKnightDoc Unprivilegeduserscanaddcomputeraccountstothedomain #
Value: 0
public const PurpleKnightDoc Builtinguestaccountisenabled #
Value: 1
public const PurpleKnightDoc EvidenceofMimikatzDCShadowattack #
Value: 2
public const PurpleKnightDoc UsersandcomputerswithnondefaultPrimaryGroupIDs #
Value: 3
public const PurpleKnightDoc ReversiblepasswordsfoundinGPOs #
Value: 4
public const PurpleKnightDoc ComputeroruseraccountswithSPNthathaveunconstraineddelegation #
Value: 5
public const PurpleKnightDoc KerberosKRBTGTaccountwitholdpassword #
Value: 6
public const PurpleKnightDoc NondefaultvalueonmsMcsAdmPwdSearchFlags #
Value: 7
public const PurpleKnightDoc PrivilegeduserswithSPNdefined #
Value: 8
public const PurpleKnightDoc ProtectedUsersgroupnotinuse #
Value: 9
public const PurpleKnightDoc NondefaultprincipalswithDCSyncrightsonthedomain #
Value: 10
public const PurpleKnightDoc RiskyRODCcredentialcaching #
Value: 11
public const PurpleKnightDoc WellknownprivilegedSIDsinSIDHistory #
Value: 12
public const PurpleKnightDoc UnprivilegedprincipalsasDNSAdmins #
Value: 13
public const PurpleKnightDoc Privilegedobjectswithunprivilegedowners #
Value: 14
public const PurpleKnightDoc Custombannedpasswordprotectionnotinuse #
Value: 15
public const PurpleKnightDoc UserswithKerberospreauthenticationdisabled #
Value: 16
public const PurpleKnightDoc BuiltindomainAdministratoraccountusedwithinthelasttwoweeks #
Value: 17
public const PurpleKnightDoc UserswithPasswordNeverExpiresflagset #
Value: 18
public const PurpleKnightDoc AnonymousaccesstoActiveDirectoryenabled #
Value: 19
public const PurpleKnightDoc ComputeraccounttakeoverthroughKerberosResourceBasedConstrainedDelegationRBCD #
Value: 20
public const PurpleKnightDoc GPOlinkingdelegationatthedomainlevel #
Value: 21
public const PurpleKnightDoc Recentprivilegedaccountcreationactivity #
Value: 22
public const PurpleKnightDoc UnprivilegedaccountswithadminCount1 #
Value: 23
public const PurpleKnightDoc ChangestoMSLAPSreadpermissions #
Value: 24
public const PurpleKnightDoc Zerologonvulnerability #
Value: 25
public const PurpleKnightDoc Userswitholdpasswords #
Value: 26
public const PurpleKnightDoc Enabledadminaccountsthatareinactive #
Value: 27
public const PurpleKnightDoc Privilegedusersthataredisabled #
Value: 28
public const PurpleKnightDoc GPOlinkingdelegationatthedomaincontrollerOUlevel #
Value: 29
public const PurpleKnightDoc GPOlinkingdelegationattheADSitelevel #
Value: 30
public const PurpleKnightDoc UserswithSPNdefined #
Value: 31
public const PurpleKnightDoc Changestoprivilegedgroupmembershipinthelast7days #
Value: 32
public const PurpleKnightDoc ADobjectscreatedwithinthelast10days #
Value: 33
public const PurpleKnightDoc Securityquestionsareinuse #
Value: 34
public const PurpleKnightDoc ObjectsinprivilegedgroupswithoutadminCount1SDProp #
Value: 35
public const PurpleKnightDoc Changestodefaultsecuritydescriptorschemainthelast90days #
Value: 36
public const PurpleKnightDoc ChangestoDefaultDomainPolicyorDefaultDomainControllersPolicyinthelast7days #
Value: 37
public const PurpleKnightDoc BuiltindomainAdministratoraccountwitholdpassword180days #
Value: 38
public const PurpleKnightDoc DomainControllerownerisnotanadministrator #
Value: 39
public const PurpleKnightDoc Domainswithobsoletefunctionallevels #
Value: 40
public const PurpleKnightDoc AnonymousNSPIaccesstoADenabled #
Value: 41
public const PurpleKnightDoc OperatorgroupsnolongerprotectedbyAdminSDHolderandSDProp #
Value: 42
public const PurpleKnightDoc ComputerswitholderOSversions #
Value: 43
public const PurpleKnightDoc PermissionchangesonAdminSDHolderobject #
Value: 44
public const PurpleKnightDoc EnterpriseKeyAdminswithfullaccesstodomain #
Value: 45
public const PurpleKnightDoc Objectswithconstraineddelegationconfigured #
Value: 46
public const PurpleKnightDoc Kerberosprotocoltransitiondelegationconfigured #
Value: 47
public const PurpleKnightDoc Computerswithpasswordlastsetover90daysago #
Value: 48
public const PurpleKnightDoc RecentSIDHistorychangesonobjects #
Value: 49
public const PurpleKnightDoc ComputerAccountsinPrivilegedGroups #
Value: 50
public const PurpleKnightDoc Adminswitholdpasswords #
Value: 51
public const PurpleKnightDoc DomainControllerswitholdpasswords #
Value: 52
public const PurpleKnightDoc Forestcontainsmorethan50privilegedaccounts #
Value: 53
public const PurpleKnightDoc PrincipalswithconstraineddelegationusingprotocoltransitionenabledforaDCservice #
Value: 54
public const PurpleKnightDoc DomainControllerswithResourceBasedConstrainedDelegationRBCDenabled #
Value: 55
public const PurpleKnightDoc Privilegedaccountswithapasswordthatneverexpires #
Value: 56
public const PurpleKnightDoc Trustaccountswitholdpasswords #
Value: 57
public const PurpleKnightDoc DomainControllersininconsistentstate #
Value: 58
public const PurpleKnightDoc PrincipalswithconstrainedauthenticationdelegationenabledforaDCservice #
Value: 59
public const PurpleKnightDoc KrbtgtaccountwithResourceBasedConstrainedDelegationRBCDenabled #
Value: 60
public const PurpleKnightDoc GMSAobjectswitholdpasswords #
Value: 61
public const PurpleKnightDoc DomainControllersthathavenotauthenticatedtothedomainformorethan45days #
Value: 62
public const PurpleKnightDoc Useraccountswithpasswordnotrequired #
Value: 63
public const PurpleKnightDoc UseraccountsthatuseDESencryption #
Value: 64
public const PurpleKnightDoc Useraccountsthatstorepasswordswithreversibleencryption #
Value: 65
public const PurpleKnightDoc PrintspoolerserviceisenabledonaDC #
Value: 66
public const PurpleKnightDoc UsersandcomputerswithoutreadablePGID #
Value: 67
public const PurpleKnightDoc WriteaccesstoRBCDonDC #
Value: 68
public const PurpleKnightDoc WriteaccesstoRBCDonkrbtgtaccount #
Value: 69
public const PurpleKnightDoc Nonstandardschemapermissions #
Value: 70
public const PurpleKnightDoc ChangestoADDisplaySpecifiersinthepast90days #
Value: 71
public const PurpleKnightDoc NonprivilegeduserswithaccesstogMSApasswords #
Value: 72
public const PurpleKnightDoc GMSAnotinuse #
Value: 73
public const PurpleKnightDoc UnsecuredDNSconfiguration #
Value: 74
public const PurpleKnightDoc Weakcertificatecipher #
Value: 75
public const PurpleKnightDoc Domaintrusttoathirdpartydomainwithoutquarantine #
Value: 76
public const PurpleKnightDoc OutboundforesttrustwithSIDHistoryenabled #
Value: 77
public const PurpleKnightDoc UserswithpermissionstosetServerTrustAccount #
Value: 78
public const PurpleKnightDoc Dangerouscontrolpathsexposecertificatetemplates #
Value: 79
public const PurpleKnightDoc Dangerouscontrolpathsexposecertificatecontainers #
Value: 80
public const PurpleKnightDoc NondefaultaccesstoDPAPIkey #
Value: 81
public const PurpleKnightDoc ReportsuspiciousMFAactivitydisabled #
Value: 82
public const PurpleKnightDoc ADCertificateAuthoritywithWebEnrollmentESC8 #
Value: 83
public const PurpleKnightDoc PrivilegedUserswithWeakPasswordPolicy #
Value: 84
public const PurpleKnightDoc NTFRSSYSVOLReplication #
Value: 85
public const PurpleKnightDoc AbnormalPasswordRefresh #
Value: 86
public const PurpleKnightDoc AccountswithConstrainedDelegationconfiguredtokrbtgt #
Value: 87
public const PurpleKnightDoc AccountswithConstrainedDelegationconfiguredtoghostSPN #
Value: 88
public const PurpleKnightDoc SYSVOLExecutableChanges #
Value: 89
public const PurpleKnightDoc AccountswithaltSecurityIdentitiesconfigured #
Value: 90
public const PurpleKnightDoc FGPPnotappliedtoGlobalgroup #
Value: 91
public const PurpleKnightDoc ChangestoPreWindows2000CompatibleAccessGroupmembership #
Value: 92
public const PurpleKnightDoc NonsyncedEntrauserthatiseligibleforaprivilegedrole #
Value: 93
public const PurpleKnightDoc InheritanceenabledonAdminSDHolderobject #
Value: 94
public const PurpleKnightDoc DangerousTrustAttributeSet #
Value: 95
public const PurpleKnightDoc EphemeralAdmins #
Value: 96
public const PurpleKnightDoc Guestaccountsthatwereinactiveformorethan30days #
Value: 97
public const PurpleKnightDoc SuspiciousDirectorySynchronizationAccountsrolemember #
Value: 98
public const PurpleKnightDoc ResourceBasedConstrainedDelegationappliedtoAZUREADSSOACCaccount #
Value: 99
public const PurpleKnightDoc Checkiflegacyauthenticationisallowed #
Value: 100
public const PurpleKnightDoc Administrativeunitsarenotbeingused #
Value: 101
public const PurpleKnightDoc Securitydefaultsnotenabled #
Value: 102
public const PurpleKnightDoc MFAnotconfiguredforprivilegedaccounts #
Value: 103
public const PurpleKnightDoc Unrestricteduserconsentallowed #
Value: 104
public const PurpleKnightDoc ConditionalAccessPolicythatdoesnotrequireapasswordchangefromhighriskusers #
Value: 105
public const PurpleKnightDoc ForeignSecurityPrincipalsinPrivilegedGroup #
Value: 106
public const PurpleKnightDoc Privilegedgroupcontainsguestaccount #
Value: 107
public const PurpleKnightDoc Checkforguestshavingpermissiontoinviteotherguests #
Value: 108
public const PurpleKnightDoc CheckforriskyAPIpermissionsgrantedtoapplicationserviceprincipals #
Value: 109
public const PurpleKnightDoc CheckforuserswithweakornoMFA #
Value: 110
public const PurpleKnightDoc SSOcomputeraccountwithpasswordlastsetover90daysago #
Value: 111
public const PurpleKnightDoc ConditionalAccessPolicydoesnotrequireMFAonprivilegedaccounts #
Value: 112
public const PurpleKnightDoc EntraConnectsyncaccountpasswordreset #
Value: 113
public const PurpleKnightDoc ConditionalAccesspoliciesthatcontainMFATrustedIPs #
Value: 114
public const PurpleKnightDoc GlobalAdministratorsthatsignedinduringthelast14days #
Value: 115
public const PurpleKnightDoc PrivilegedusercredentialscachedonRODC #
Value: 116
public const PurpleKnightDoc ConditionalAccessPolicythatdisableadmintokenpersistence #
Value: 117
public const PurpleKnightDoc Smartcardpasswordrotationdisabled #
Value: 118
public const PurpleKnightDoc OperatorsGroupsthatarenotempty #
Value: 119
public const PurpleKnightDoc RC4orDESencryptiontypearesupportedbyDomainControllers #
Value: 120
public const PurpleKnightDoc PrimaryuserswithSPNnotsupportingAESencryptiononKerberos #
Value: 121
public const PurpleKnightDoc LDAPsigningisnotrequiredonDomainControllers #
Value: 122
public const PurpleKnightDoc SMBSigningisnotrequiredonDomainControllers #
Value: 123
public const PurpleKnightDoc SMBv1isenabledonDomainControllers #
Value: 124
public const PurpleKnightDoc Certificatetemplateswith3ormoreinsecureconfigurations #
Value: 125
public const PurpleKnightDoc CertificatetemplatesthatallowrequesterstospecifyasubjectAltName #
Value: 126
public const PurpleKnightDoc EntraIDprivilegedusersthatarealsoprivilegedinAD #
Value: 127
public const PurpleKnightDoc Nonadminuserscanregistercustomapplications #
Value: 128
public const PurpleKnightDoc Guestusersarenotrestricted #
Value: 129
public const PurpleKnightDoc ADprivilegedusersthataresyncedtoEntraID #
Value: 130
public const PurpleKnightDoc Morethan5GlobalAdministratorsexist #
Value: 131
public const PurpleKnightDoc Guestinvitesnotacceptedinlast30day #
Value: 132
public const PurpleKnightDoc ConditionalAccesspolicywithContinuousAccessEvaluationdisabled #
Value: 133
public const PurpleKnightDoc Userscancreatesecuritygroups #
Value: 134
public const PurpleKnightDoc ConditionalAccesspoliciescontainprivateIPaddresses #
Value: 135
public const PurpleKnightDoc ConditionalAccessPolicythatdoesnotrequireMFAwhensigninriskhasbeenidentified #
Value: 136
public const PurpleKnightDoc ObjectswithReanimateTombstonesextendedright #
Value: 137
public const PurpleKnightDoc GPOWeakLMHashstorageenabled #
Value: 138
public const PurpleKnightDoc WritableshortcutsfoundinGPO #
Value: 139
public const PurpleKnightDoc OUpermissionsenablingBadSuccessordMSAescalation #
Value: 140
public const PurpleKnightDoc Changestounprivilegedgroupmembershipinthelast7days #
Value: 141
public const PurpleKnightDoc ApplicationnameandgeographiclocationadditionalcontextsaredisabledonMFA #
Value: 142
public const PurpleKnightDoc Nonadminuserscancreatetenants #
Value: 143
public const PurpleKnightDoc Usersordevicesinactiveforatleast90days #
Value: 144
public const PurpleKnightDoc Userconsentisallowedforriskyapplications #
Value: 145
public const PurpleKnightDoc EnterpriseapplicationsusingSAMLforSSO #
Value: 146
public const PurpleKnightDoc MFAbombingattackoccurredinthepastday #
Value: 147
public const PurpleKnightDoc QuerypoliciesthathavetheattributeofLDAPdenylistset #
Value: 148
public const PurpleKnightDoc ListofRiskyusersmediumorhighlevel #
Value: 149
public const PurpleKnightDoc Morethan10PrivilegedAdministratorsexist #
Value: 150
public const PurpleKnightDoc Privilegedaccountswithmailbox #
Value: 151
public const PurpleKnightDoc Lessthan2GlobalAdministratorsexist #
Value: 152
public const PurpleKnightDoc Applicationinstancepropertylockdisabled #
Value: 153
public const PurpleKnightDoc Unprivilegedownerofaprivilegedgroup #
Value: 154
public const PurpleKnightDoc ProhibitedEntraIDRolesAssigned #
Value: 155
public const PurpleKnightDoc Selfservicepasswordresetenabledforprivilegedroles #
Value: 156
public const PurpleKnightDoc EnsureallnonprivilegeduserscancompleteMFA #
Value: 157
public const PurpleKnightDoc PermanentActivePrivilegedRoleAssignment #
Value: 158
public const PurpleKnightDoc EntratenantissusceptibletoHiddenConsentGrantattack #
Value: 159
public const PurpleKnightDoc EntracustomRoleswithriskypermissions #
Value: 160
public const PurpleKnightDoc DetectMFApolicychangesforgroupsandusers #
Value: 161
public const PurpleKnightDoc Passwordhashsynchronizationisnotenabled #
Value: 162
public const PurpleKnightDoc CertificateBasedAuthenticationPersistence #
Value: 163
public const PurpleKnightDoc UseraccountsusingSmartCardauthenticationwitholdpassword #
Value: 164
public const PurpleKnightDoc UnresolvedEntraIDprivilegedrolemembers #
Value: 165
public const PurpleKnightDoc Usersarenotusingtheirprivilegedroles #
Value: 166
public const PurpleKnightDoc Newpermissionhasbeengrantedtoagroup #
Value: 167
public const PurpleKnightDoc Newpermissionhasbeengrantedtoauser #
Value: 168
public const PurpleKnightDoc DangeroususerrightsgrantedbyGPO #
Value: 169
public const PurpleKnightDoc NewAPItokenwascreated #
Value: 170
public const PurpleKnightDoc DangerousGPOlogonscriptpath #
Value: 171
public const PurpleKnightDoc NewSuperAdminpermissionhasbeengrantedtoauser #
Value: 172
public const PurpleKnightDoc NewSuperAdminpermissionhasbeengrantedtoagroup #
Value: 173
public const PurpleKnightDoc Useractivationinthelast7days #
Value: 174
public const PurpleKnightDoc Userdeactivationinthelast7days #
Value: 175
public const PurpleKnightDoc UserswithoutMultiFactorAuthenticationMFA #
Value: 176
public const PurpleKnightDoc Passwordpolicycheck #
Value: 177
public const PurpleKnightDoc Highprivilegedcustomroles #
Value: 178
public const PurpleKnightDoc UnexpectedaccountsinCertPublishersGroup #
Value: 179
public const PurpleKnightDoc Applicationexpiredsecretsandcertificates #
Value: 180
public const PurpleKnightDoc GPOwithScheduledTasksconfigured #
Value: 181
public const PurpleKnightDoc FIDO2Attestationisnotenforced #
Value: 182
public const PurpleKnightDoc UserswiththeattributeuserPasswordset #
Value: 183
public const PurpleKnightDoc ShadowCredentialsonprivilegedobjects #
Value: 184
public const PurpleKnightDoc DistributedCOMUsersgrouporPerformanceLogUsersgrouparenotempty #
Value: 185
public const PurpleKnightDoc SuspiciouscredentialsonMicrosoftserviceprincipals #
Value: 186

Extension Methods

public static String Id(PurpleKnightDoc d) #
Returns: String

Parameters

d PurpleKnightDoc requiredposition: 0