One Active Directory Account Can Be Your Best Early Warning
ID: 73651746-2713-5138-ab77-c149f3de58f7
STIX ID: report--73651746-2713-5138-ab77-c149f3de58f7
Feed Name: Black Hills Infosec Blog
**Executive Summary:** This blog demonstrates a practical detection-engineering approach using a decoy Active Directory account: create a honey account, enable auditing on the account's UAC attribute to log LDAP reads (EventID 4662), register a service principal name to make the account Kerberoastable and detect ticket requests (EventID 4769), and monitor failed logins against the decoy to catch password spraying/credential stuffing (EventID 4625); the post includes PowerShell commands and KQL queries to implement and validate these high-fidelity detections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
