Deceptive-Auditing: An Active Directory Honeypots Tool
ID: a64f3e2c-359e-5413-b05e-c117c0fcfc53
STIX ID: report--a64f3e2c-359e-5413-b05e-c117c0fcfc53
Feed Name: Black Hills Infosec Blog
This blog presents Deceptive-Auditing, a PowerShell toolkit that automates creation of Active Directory decoys (users, computers, groups, OUs, GPOs) and configures SACL auditing to surface events (4662, 4663) when adversaries interact with them, enabling detection and deception in enterprise AD environments; it demonstrates usage of cmdlets like Set-AuditRule and Deploy-*Deception to make decoys attractive (e.g., SPNs, delegation flags) and instrumented for monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
