logo

One Active Directory Account Can Be Your Best Early Warning

ID: 73651746-2713-5138-ab77-c149f3de58f7

STIX ID: report--73651746-2713-5138-ab77-c149f3de58f7

Feed Name: Black Hills Infosec Blog

Date Published: 2025-01-16

Date Updated: 2026-04-27

Author: BHIS

...
...

**Executive Summary:** This blog demonstrates a practical detection-engineering approach using a decoy Active Directory account: create a honey account, enable auditing on the account's UAC attribute to log LDAP reads (EventID 4662), register a service principal name to make the account Kerberoastable and detect ticket requests (EventID 4769), and monitor failed logins against the decoy to catch password spraying/credential stuffing (EventID 4625); the post includes PowerShell commands and KQL queries to implement and validate these high-fidelity detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.