What it catches
- Kerberoasting and AS-REP roasting
- Golden / silver / diamond ticket forgery
- DCSync and DCShadow
- OAuth consent phishing (M365 and Workspace)
- Service-account abuse (long-dormant accounts suddenly logging in)
- Risky SaaS app grants (3rd-party apps with mailbox-read scope)