logo

Creating Honey Credentials with LSA Secrets

ID: 9f30592a-5f62-5f25-adeb-5ef9a342d416

STIX ID: report--9f30592a-5f62-5f25-adeb-5ef9a342d416

Feed Name: TrustedSec blog

Threat Score
60/100

Date Published: 2023-09-20

Date Updated: 2026-05-01

...
...

The report explains how attackers locate systems with SPNs to dump LSASecrets and extract plaintext service account credentials for privilege escalation, and recommends a defensive deception: create realistic-looking service accounts with false passwords stored in LSASecrets and monitor for authentication failures (e.g., Windows 4625) to detect adversary use of the planted credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.