logo

Mapping Deception Solutions With BloodHound OpenGraph

ID: 7f45b13c-5a4f-5316-95bc-cf99bc0e2bda

STIX ID: report--7f45b13c-5a4f-5316-95bc-cf99bc0e2bda

Feed Name: SpecterOps Blog

Date Published: 2026-02-19

Date Updated: 2026-04-30

...
...

This SpecterOps blog outlines a methodology for deploying high-fidelity, low-risk deception controls along real attack paths in Microsoft Configuration Manager (SCCM) and mapping them in BloodHound OpenGraph. It demonstrates creating canary Network Access Accounts (NAA) with auditing, staging deceptive PXE media on Distribution Points with detailed file share auditing (EID 5145), and planting expired credentials in the SC_UserAccount table with SQL audits (EID 33205), while restricting misuse and tracking deceptions via ConfigManBearPig and deceptionClone. The post ties these deceptions to known SCCM attack techniques (e.g., PXE abuse, credential recovery via SCCMHunter) to enable reliable detection without introducing new attack paths.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.