logo

Detecting Active Directory Password-Spraying with a Honeypot Account

ID: 81d5e008-7dee-5e7f-ab97-fe86b0cb419a

STIX ID: report--81d5e008-7dee-5e7f-ab97-fe86b0cb419a

Feed Name: TrustedSec blog

Threat Score
45/100

Date Published: 2025-10-17

Date Updated: 2026-05-01

...
...

This article describes the password-spraying threat and provides pragmatic detection guidance: create honeypot user accounts, enable/route relevant Windows Security and Kerberos audit events (e.g., 4624, 4625, 4768, 4769, 4771), and monitor those accounts to detect successful or failed logons indicative of password-spraying with minimal false positives.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.