logo

Deceptive-Auditing: An Active Directory Honeypots Tool

ID: a64f3e2c-359e-5413-b05e-c117c0fcfc53

STIX ID: report--a64f3e2c-359e-5413-b05e-c117c0fcfc53

Feed Name: Black Hills Infosec Blog

Date Published: 2026-01-07

Date Updated: 2026-04-27

Author: BHIS

...
...

This blog presents Deceptive-Auditing, a PowerShell toolkit that automates creation of Active Directory decoys (users, computers, groups, OUs, GPOs) and configures SACL auditing to surface events (4662, 4663) when adversaries interact with them, enabling detection and deception in enterprise AD environments; it demonstrates usage of cmdlets like Set-AuditRule and Deploy-*Deception to make decoys attractive (e.g., SPNs, delegation flags) and instrumented for monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.