AUTOMATED VULNERABILITY ASSESSMENT IN WINDOWS ACTIVE DIRECTORY AND ORACLE DATABASE ENVIRONMENTS USING POWERSHELL AND SQL*PLUS

Authors

  • Vasil Slavyanov Vasil Levski National Military University, Veliko Tarnovo, Bulgaria

DOI:

https://doi.org/10.68302/std2026.vol3.146

Keywords:

Active Directory, configuration auditing, internal control testing, Oracle Database, PowerShell, security automation, SQL*Plus, vulnerability assessment

Abstract

Enterprise IT environments are rarely built around a single technology. In most mid-to-large organisations, identity management runs through Microsoft Active Directory while business-critical data sits in relational databases such as Oracle. This combination is operationally essential and a recurring focus of security incidents. Reviewing such environments manually is slow, inconsistent across reviewers, and leaves real gaps in coverage. This paper describes a practical approach to automating vulnerability assessment across both layers using tools already present in the environment: PowerShell for the Windows and Active Directory side, and SQL*Plus for Oracle Database. The focus is on configuration weaknesses, access control gaps, and governance failures that accumulate quietly in production systems. The paper presents a methodology, discussion of typical findings, and an honest account of where the approach runs into its limits.

Downloads

Download data is not yet available.

References

[1] Microsoft Corporation. Windows Server and Active Directory documentation. Microsoft Docs. https://docs.microsoft.com

[2] Oracle Corporation. Oracle Database Security Guide. Oracle Documentation. https://docs.oracle.com/en/database/oracle/oracle-database/

[3] Center for Internet Security (CIS). CIS Benchmarks for Microsoft Windows Server and Oracle Database. https://www.cisecurity.org

[4] ISACA. IT Audit Framework (ITAF): A Professional Practices Framework for IT Audit, 4th Edition. ISACA, 2020.

[5] NIST. Special Publication 800-53: Security and Privacy Controls for Information Systems and Organizations. National Institute of Standards and Technology, 2020. https://doi.org/10.6028/NIST.SP.800-53r5

[6] The Institute of Internal Auditors. International Standards for the Professional Practice of Internal Auditing. IIA, 2017.

[7] Mokhtar, B. I., Jurcut, A. D., ElSayed, M. S., & Azer, M. A. (2022). Active Directory Attacks: Steps, Types, and Signatures. Electronics, 11(16), 2629. https://doi.org/10.3390/electronics11162629

[8] Omotunde, H., & Ahmed, M. (2023). A Comprehensive Review of Security Measures in Database Systems. Mesopotamian Journal of CyberSecurity, 2023, 115-133. https://doi.org/10.58496/MJCSC/2023/016

[9] Bu Haimed, I., Albahar, M., & Alzubaidi, A. (2023). Exploiting Misconfiguration Vulnerabilities in Microsoft's Azure Active Directory for Privilege Escalation Attacks. Future Internet, 15(7), 226. https://doi.org/10.3390/fi15070226

Downloads

Published

17.09.2026

How to Cite

[1]
V. Slavyanov, “AUTOMATED VULNERABILITY ASSESSMENT IN WINDOWS ACTIVE DIRECTORY AND ORACLE DATABASE ENVIRONMENTS USING POWERSHELL AND SQL*PLUS”, SysTechDev, vol. 3, pp. 285–289, Sep. 2026, doi: 10.68302/std2026.vol3.146.