AD-USER-26 - Honey pot user count should be retrievable
Overviewβ
Accounts with names that look especially attractive to attackers can be useful as deliberate decoys, but they can also reflect risky naming practices or forgotten identities that warrant review.
- Threat detection support: Decoy-style names can be monitored for malicious interaction.
- Naming hygiene: Identifies user names likely to draw attacker attention.
- Access review: Confirms whether these accounts are intentional and documented.
Security Recommendationβ
- Document whether identified accounts are real users, service accounts, or deception assets.
- Apply strong monitoring to any deliberate honey pot or lure account.
- Disable or clean up misleading accounts that no longer serve a purpose.
How the Test Worksβ
This test counts non-system user accounts whose names match attractive terms such as admin, root, test, backup, or sql.
Related Testsβ
Test-MtAdUserHoneyPotDetailsTest-MtAdUserBuiltInAdminEnabledDetails
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-USER-26 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.User |
| PowerShell test | Test-MtAdUserHoneyPotCount |
| Tags | AD, AD-USER-26, AD.User |
Sourceβ
- Pester test:
tests/ad/user/Test-MtAdUserHoneyPotCount.Tests.ps1 - PowerShell source:
powershell/public/ad/user/Test-MtAdUserHoneyPotCount.ps1

