Skip to main content
Version: 2.2.1-preview

AD-USER-26 - Honey pot user count should be retrievable

Overview​

Accounts with names that look especially attractive to attackers can be useful as deliberate decoys, but they can also reflect risky naming practices or forgotten identities that warrant review.

  • Threat detection support: Decoy-style names can be monitored for malicious interaction.
  • Naming hygiene: Identifies user names likely to draw attacker attention.
  • Access review: Confirms whether these accounts are intentional and documented.

Security Recommendation​

  • Document whether identified accounts are real users, service accounts, or deception assets.
  • Apply strong monitoring to any deliberate honey pot or lure account.
  • Disable or clean up misleading accounts that no longer serve a purpose.

How the Test Works​

This test counts non-system user accounts whose names match attractive terms such as admin, root, test, backup, or sql.

  • Test-MtAdUserHoneyPotDetails
  • Test-MtAdUserBuiltInAdminEnabledDetails

Test Metadata​

FieldValue
Test IDAD-USER-26
SeverityInfo
SuiteActive Directory
CategoryAD.User
PowerShell testTest-MtAdUserHoneyPotCount
TagsAD, AD-USER-26, AD.User

Source​

  • Pester test: tests/ad/user/Test-MtAdUserHoneyPotCount.Tests.ps1
  • PowerShell source: powershell/public/ad/user/Test-MtAdUserHoneyPotCount.ps1