Detecting Active Directory Password-Spraying with a Honeypot Account
ID: 81d5e008-7dee-5e7f-ab97-fe86b0cb419a
STIX ID: report--81d5e008-7dee-5e7f-ab97-fe86b0cb419a
Feed Name: TrustedSec blog
Threat Score
This article describes the password-spraying threat and provides pragmatic detection guidance: create honeypot user accounts, enable/route relevant Windows Security and Kerberos audit events (e.g., 4624, 4625, 4768, 4769, 4771), and monitor those accounts to detect successful or failed logons indicative of password-spraying with minimal false positives.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
