Engagement evidence · obxlab.local · Server 2022

Real lab results, reproducible from a single binary.

Every Obexum release runs against our own AD lab before shipping. The numbers below come from the latest end-to-end engagement: a freshly-promoted Server 2022 forest with synthetic adversary fixtures (vulnerable cert templates, Kerberoastable accounts, ACL backdoors) and a full inject → detect → remediate → re-detect clean round-trip.

161
Findings emitted
569
Probes evaluated
0 FPs
After teardown
~3 min
Total scan time

22 critical and 104 high findings on a default install.

Out of the box, a Server 2022 promoted with the default options exposes a large attack surface. The numbers below are typical — we see them on practically every fresh forest that has not been hardened against the CIS Server 2022 baseline.

22
Critical
104
High
30
Medium
5
Low

What the lab DC fails on out of the box.

Each finding ships with a remediation playbook. Click any rule_id to see its detail in the docs.

Rule ID Title Severity Playbook Reboot?
AUD-WIN-ADCS-001ESC1: SAN-supply template enrollable by low-privCRITICALpb-adcs-001
AUD-WIN-ADCS-002ESC2: Any-Purpose EKU templateCRITICALpb-adcs-002
AUD-WIN-ADCS-006ESC6: EDITF_ATTRIBUTESUBJECTALTNAME2 set on CACRITICALpb-adcs-006
AUD-WIN-ADCS-008ESC8: web enrollment without HTTPS+EPACRITICALpb-adcs-008
AUD-WIN-ADCS-015ESC15 / EKUwu (CVE-2024-49019) v1+SAN templateCRITICALpb-adcs-015
AUD-WIN-DCH-001Print Spooler running on DC (PrintNightmare)CRITICALpb-dch-001
AUD-WIN-DCH-010WDigest UseLogonCredential = 1 (cleartext in LSASS)CRITICALpb-dch-010
AUD-WIN-ACL-001DCSync extended right granted to non-Tier0CRITICALpb-acl-001
AUD-WIN-ACL-009Shadow Credentials write granted to non-Tier0CRITICALpb-acl-009
AUD-WIN-DC-001LDAPServerIntegrity ≠ Required (CVE-2017-8563)HIGHpb-dc-001
AUD-WIN-DC-002LdapEnforceChannelBinding ≠ AlwaysHIGHpb-dc-002
AUD-WIN-PRIV-009RunAsPPL not enabled (LSASS dump exposure)HIGHpb-priv-009yes
AUD-WIN-FH-007dSHeuristics anonymous LDAP bind bit setHIGHpb-fh-007
AUD-WIN-PG-006Pre-Win2k Compat Access has Authenticated UsersCRITICALpb-pg-006

Want the complete list? Open the live HTML report — all 161 findings are filterable with searchable evidence.

How we get to zero false positives.

Every check follows the same pericial round-trip before it ships.

1. Inject

Our internal lab harness creates the exact misconfiguration the check is built to detect. ESC1-15 templates, Kerberoastable accounts, ACL backdoors, RBCD configs — every primitive materialised on a controlled DC.

2. Detect

We run the new check. It must fire 1:1 with the injection (no extra findings, no missed ones). We capture full probe output as evidence.

3. Remediate

We remove the injection and re-run the check. It must return PASS. If it still fires, the probe has a false-positive and goes back to the bench.

4. Re-inject

We re-apply the injection and re-run. The check must fire again, identically. This catches checks that pass on accidental state-cleanup, not on actual remediation.

569 / 569 checks have completed this round-trip on the lab DC. Every shipping commit references the lab evidence trail. No false positives means we can put a pericial-grade signature on the report.

How this engagement was conducted

Every finding shown above was produced by Obexum's deterministic check engine on a controlled lab DC running Windows Server 2022. The methodology is documented and reproducible — under license agreement we share the lab harness so customers can validate Obexum against their own staging environment before signing off.

1. Controlled lab

Windows Server 2022 promoted to a fresh domain (obxlab.local) with default policies, no manual hardening. Same baseline a typical SMB-deployed DC starts from.

2. Pericial protocol

Every check was validated under our R1 round-trip protocol: inject the misconfig → detect it → remediate → confirm the detection clears. No baseline-only assumptions.

3. Pinned binary

The same Obexum build that produced these findings is shipped to customers with a SHA-256 manifest. Identical inputs → identical findings.json. Auditors can cross-check.

Customers under enterprise contract receive the lab harness scripts and a step-by-step replication guide as part of the onboarding package — we believe in transparency, but not at the cost of handing detection logic to the threat actors we audit against. Talk to us for the full methodology whitepaper.

Run it on your own DC.

14-day trial, single binary, no agent. Walk away with a defensible report whether you keep the product or not.