Detects possible addition of shadow credentials to an active directory object.
Read the full analysis on IntelFusions