AD-USER-27 - Honey pot user details should be retrievable
Overviewβ
Detailed visibility into potential honey pot style users helps separate intentional deception assets from legacy, misleading, or risky accounts.
- Deception validation: Confirm lure accounts are intentional and monitored.
- Operational clarity: Distinguish test or stale accounts from active users.
- Risk reduction: Remove attractive-but-unnecessary account names.
Security Recommendationβ
- Track owner and purpose for each identified account.
- Alert on any authentication attempts to intentional lure accounts.
- Disable or rename unnecessary accounts that imitate privileged or attractive targets.
How the Test Worksβ
This test returns non-system users whose names match attacker-attractive terms and includes usage-oriented details such as enabled state, last logon, and password expiry status.
Related Testsβ
Test-MtAdUserHoneyPotCountTest-MtAdUserKnownServiceAccountDetails
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-USER-27 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.User |
| PowerShell test | Test-MtAdUserHoneyPotDetails |
| Tags | AD, AD-USER-27, AD.User |
Sourceβ
- Pester test:
tests/ad/user/Test-MtAdUserHoneyPotDetails.Tests.ps1 - PowerShell source:
powershell/public/ad/user/Test-MtAdUserHoneyPotDetails.ps1

