mirror of
https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git
synced 2026-08-06 19:00:17 +03:00
Add 30 new production-grade cybersecurity skills: AI security, supply chain, firmware, cloud-native, compliance, deception, crypto, threat hunting, purple team, OT, privacy
This commit is contained in:
@@ -0,0 +1,201 @@
|
||||
|
||||
Apache License
|
||||
Version 2.0, January 2004
|
||||
http://www.apache.org/licenses/
|
||||
|
||||
TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
|
||||
|
||||
1. Definitions.
|
||||
|
||||
"License" shall mean the terms and conditions for use, reproduction,
|
||||
and distribution as defined by Sections 1 through 9 of this document.
|
||||
|
||||
"Licensor" shall mean the copyright owner or entity authorized by
|
||||
the copyright owner that is granting the License.
|
||||
|
||||
"Legal Entity" shall mean the union of the acting entity and all
|
||||
other entities that control, are controlled by, or are under common
|
||||
control with that entity. For the purposes of this definition,
|
||||
"control" means (i) the power, direct or indirect, to cause the
|
||||
direction or management of such entity, whether by contract or
|
||||
otherwise, or (ii) ownership of fifty percent (50%) or more of the
|
||||
outstanding shares, or (iii) beneficial ownership of such entity.
|
||||
|
||||
"You" (or "Your") shall mean an individual or Legal Entity
|
||||
exercising permissions granted by this License.
|
||||
|
||||
"Source" form shall mean the preferred form for making modifications,
|
||||
including but not limited to software source code, documentation
|
||||
source, and configuration files.
|
||||
|
||||
"Object" form shall mean any form resulting from mechanical
|
||||
transformation or translation of a Source form, including but
|
||||
not limited to compiled object code, generated documentation,
|
||||
and conversions to other media types.
|
||||
|
||||
"Work" shall mean the work of authorship, whether in Source or
|
||||
Object form, made available under the License, as indicated by a
|
||||
copyright notice that is included in or attached to the work
|
||||
(an example is provided in the Appendix below).
|
||||
|
||||
"Derivative Works" shall mean any work, whether in Source or Object
|
||||
form, that is based on (or derived from) the Work and for which the
|
||||
editorial revisions, annotations, elaborations, or other modifications
|
||||
represent, as a whole, an original work of authorship. For the purposes
|
||||
of this License, Derivative Works shall not include works that remain
|
||||
separable from, or merely link (or bind by name) to the interfaces of,
|
||||
the Work and Derivative Works thereof.
|
||||
|
||||
"Contribution" shall mean any work of authorship, including
|
||||
the original version of the Work and any modifications or additions
|
||||
to that Work or Derivative Works thereof, that is intentionally
|
||||
submitted to the Licensor for inclusion in the Work by the copyright owner
|
||||
or by an individual or Legal Entity authorized to submit on behalf of
|
||||
the copyright owner. For the purposes of this definition, "submitted"
|
||||
means any form of electronic, verbal, or written communication sent
|
||||
to the Licensor or its representatives, including but not limited to
|
||||
communication on electronic mailing lists, source code control systems,
|
||||
and issue tracking systems that are managed by, or on behalf of, the
|
||||
Licensor for the purpose of discussing and improving the Work, but
|
||||
excluding communication that is conspicuously marked or otherwise
|
||||
designated in writing by the copyright owner as "Not a Contribution."
|
||||
|
||||
"Contributor" shall mean Licensor and any individual or Legal Entity
|
||||
on behalf of whom a Contribution has been received by the Licensor and
|
||||
subsequently incorporated within the Work.
|
||||
|
||||
2. Grant of Copyright License. Subject to the terms and conditions of
|
||||
this License, each Contributor hereby grants to You a perpetual,
|
||||
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
|
||||
copyright license to reproduce, prepare Derivative Works of,
|
||||
publicly display, publicly perform, sublicense, and distribute the
|
||||
Work and such Derivative Works in Source or Object form.
|
||||
|
||||
3. Grant of Patent License. Subject to the terms and conditions of
|
||||
this License, each Contributor hereby grants to You a perpetual,
|
||||
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
|
||||
(except as stated in this section) patent license to make, have made,
|
||||
use, offer to sell, sell, import, and otherwise transfer the Work,
|
||||
where such license applies only to those patent claims licensable
|
||||
by such Contributor that are necessarily infringed by their
|
||||
Contribution(s) alone or by combination of their Contribution(s)
|
||||
with the Work to which such Contribution(s) was submitted. If You
|
||||
institute patent litigation against any entity (including a
|
||||
cross-claim or counterclaim in a lawsuit) alleging that the Work
|
||||
or a Contribution incorporated within the Work constitutes direct
|
||||
or contributory patent infringement, then any patent licenses
|
||||
granted to You under this License for that Work shall terminate
|
||||
as of the date such litigation is filed.
|
||||
|
||||
4. Redistribution. You may reproduce and distribute copies of the
|
||||
Work or Derivative Works thereof in any medium, with or without
|
||||
modifications, and in Source or Object form, provided that You
|
||||
meet the following conditions:
|
||||
|
||||
(a) You must give any other recipients of the Work or
|
||||
Derivative Works a copy of this License; and
|
||||
|
||||
(b) You must cause any modified files to carry prominent notices
|
||||
stating that You changed the files; and
|
||||
|
||||
(c) You must retain, in the Source form of any Derivative Works
|
||||
that You distribute, all copyright, patent, trademark, and
|
||||
attribution notices from the Source form of the Work,
|
||||
excluding those notices that do not pertain to any part of
|
||||
the Derivative Works; and
|
||||
|
||||
(d) If the Work includes a "NOTICE" text file as part of its
|
||||
distribution, then any Derivative Works that You distribute must
|
||||
include a readable copy of the attribution notices contained
|
||||
within such NOTICE file, excluding any notices that do not
|
||||
pertain to any part of the Derivative Works, in at least one
|
||||
of the following places: within a NOTICE text file distributed
|
||||
as part of the Derivative Works; within the Source form or
|
||||
documentation, if provided along with the Derivative Works; or,
|
||||
within a display generated by the Derivative Works, if and
|
||||
wherever such third-party notices normally appear. The contents
|
||||
of the NOTICE file are for informational purposes only and
|
||||
do not modify the License. You may add Your own attribution
|
||||
notices within Derivative Works that You distribute, alongside
|
||||
or as an addendum to the NOTICE text from the Work, provided
|
||||
that such additional attribution notices cannot be construed
|
||||
as modifying the License.
|
||||
|
||||
You may add Your own copyright statement to Your modifications and
|
||||
may provide additional or different license terms and conditions
|
||||
for use, reproduction, or distribution of Your modifications, or
|
||||
for any such Derivative Works as a whole, provided Your use,
|
||||
reproduction, and distribution of the Work otherwise complies with
|
||||
the conditions stated in this License.
|
||||
|
||||
5. Submission of Contributions. Unless You explicitly state otherwise,
|
||||
any Contribution intentionally submitted for inclusion in the Work
|
||||
by You to the Licensor shall be under the terms and conditions of
|
||||
this License, without any additional terms or conditions.
|
||||
Notwithstanding the above, nothing herein shall supersede or modify
|
||||
the terms of any separate license agreement you may have executed
|
||||
with Licensor regarding such Contributions.
|
||||
|
||||
6. Trademarks. This License does not grant permission to use the trade
|
||||
names, trademarks, service marks, or product names of the Licensor,
|
||||
except as required for reasonable and customary use in describing the
|
||||
origin of the Work and reproducing the content of the NOTICE file.
|
||||
|
||||
7. Disclaimer of Warranty. Unless required by applicable law or
|
||||
agreed to in writing, Licensor provides the Work (and each
|
||||
Contributor provides its Contributions) on an "AS IS" BASIS,
|
||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
|
||||
implied, including, without limitation, any warranties or conditions
|
||||
of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
|
||||
PARTICULAR PURPOSE. You are solely responsible for determining the
|
||||
appropriateness of using or redistributing the Work and assume any
|
||||
risks associated with Your exercise of permissions under this License.
|
||||
|
||||
8. Limitation of Liability. In no event and under no legal theory,
|
||||
whether in tort (including negligence), contract, or otherwise,
|
||||
unless required by applicable law (such as deliberate and grossly
|
||||
negligent acts) or agreed to in writing, shall any Contributor be
|
||||
liable to You for damages, including any direct, indirect, special,
|
||||
incidental, or consequential damages of any character arising as a
|
||||
result of this License or out of the use or inability to use the
|
||||
Work (including but not limited to damages for loss of goodwill,
|
||||
work stoppage, computer failure or malfunction, or any and all
|
||||
other commercial damages or losses), even if such Contributor
|
||||
has been advised of the possibility of such damages.
|
||||
|
||||
9. Accepting Warranty or Additional Liability. While redistributing
|
||||
the Work or Derivative Works thereof, You may choose to offer,
|
||||
and charge a fee for, acceptance of support, warranty, indemnity,
|
||||
or other liability obligations and/or rights consistent with this
|
||||
License. However, in accepting such obligations, You may act only
|
||||
on Your own behalf and on Your sole responsibility, not on behalf
|
||||
of any other Contributor, and only if You agree to indemnify,
|
||||
defend, and hold each Contributor harmless for any liability
|
||||
incurred by, or claims asserted against, such Contributor by reason
|
||||
of your accepting any such warranty or additional liability.
|
||||
|
||||
END OF TERMS AND CONDITIONS
|
||||
|
||||
APPENDIX: How to apply the Apache License to your work.
|
||||
|
||||
To apply the Apache License to your work, attach the following
|
||||
boilerplate notice, with the fields enclosed by brackets "[]"
|
||||
replaced with your own identifying information. (Don't include
|
||||
the brackets!) The text should be enclosed in the appropriate
|
||||
comment syntax for the file format. Please do not remove or change
|
||||
the license header comment from a contributed file except when
|
||||
necessary.
|
||||
|
||||
Copyright 2026 mukul975
|
||||
|
||||
Licensed under the Apache License, Version 2.0 (the "License");
|
||||
you may not use this file except in compliance with the License.
|
||||
You may obtain a copy of the License at
|
||||
|
||||
http://www.apache.org/licenses/LICENSE-2.0
|
||||
|
||||
Unless required by applicable law or agreed to in writing, software
|
||||
distributed under the License is distributed on an "AS IS" BASIS,
|
||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
See the License for the specific language governing permissions and
|
||||
limitations under the License.
|
||||
@@ -0,0 +1,242 @@
|
||||
---
|
||||
name: deploying-active-directory-honeytokens
|
||||
description: >
|
||||
Deploys deception-based honeytokens in Active Directory including fake privileged accounts
|
||||
with AdminCount=1, fake SPNs for Kerberoasting detection (honeyroasting), decoy GPOs with
|
||||
cpassword traps, and fake BloodHound paths. Monitors Windows Security Event IDs 4769, 4625,
|
||||
4662, 5136 for honeytoken interaction. Use when implementing AD deception defenses for
|
||||
detecting lateral movement, credential theft, and reconnaissance.
|
||||
domain: cybersecurity
|
||||
subdomain: deception-technology
|
||||
tags: [active-directory, honeytokens, kerberoasting, deception, detection, bloodhound, gpo]
|
||||
version: "1.0"
|
||||
author: mukul975
|
||||
license: Apache-2.0
|
||||
---
|
||||
|
||||
# Deploying Active Directory Honeytokens
|
||||
|
||||
## When to Use
|
||||
|
||||
- When deploying deception-based detection in Active Directory environments
|
||||
- When detecting Kerberoasting attacks via fake SPN honeytokens (honeyroasting)
|
||||
- When creating tripwire accounts to detect credential theft and lateral movement
|
||||
- When building decoy GPOs to detect Group Policy Preference password harvesting
|
||||
- When creating deceptive BloodHound paths to misdirect and detect attackers
|
||||
- When supplementing existing AD monitoring with high-fidelity detection signals
|
||||
|
||||
## Prerequisites
|
||||
|
||||
- Domain Admin or delegated AD administration privileges
|
||||
- Active Directory domain (Windows Server 2016+ recommended)
|
||||
- Windows Event Log forwarding to SIEM (Splunk, Sentinel, Elastic)
|
||||
- PowerShell 5.1+ with ActiveDirectory module
|
||||
- Group Policy Management Console (GPMC)
|
||||
- Understanding of AD security, Kerberos, and BloodHound attack paths
|
||||
|
||||
## Background
|
||||
|
||||
### Why AD Honeytokens
|
||||
|
||||
Traditional signature-based detection misses novel attack techniques. Honeytokens
|
||||
provide high-fidelity detection with near-zero false positives because any interaction
|
||||
with a decoy object is inherently suspicious. In Active Directory:
|
||||
|
||||
- **Fake privileged accounts** detect credential dumping (DCSync, NTDS.dit extraction)
|
||||
- **Fake SPNs** detect Kerberoasting reconnaissance (TGS requests for nonexistent services)
|
||||
- **Decoy GPOs** detect Group Policy Preference password harvesting
|
||||
- **Fake BloodHound paths** mislead attackers using graph-based AD analysis
|
||||
|
||||
### Key Detection Event IDs
|
||||
|
||||
| Event ID | Description | Honeytoken Use |
|
||||
|----------|-------------|----------------|
|
||||
| 4769 | Kerberos TGS ticket requested | Detect Kerberoast against honey SPN |
|
||||
| 4625 | Failed logon attempt | Detect use of fake credentials from decoy GPO |
|
||||
| 4662 | Directory service object accessed | Detect DACL read on honeytoken user |
|
||||
| 5136 | Directory service object modified | Detect modification of decoy GPO |
|
||||
| 5137 | Directory service object created | Detect GPO creation mimicking decoy |
|
||||
| 4768 | Kerberos TGT requested | Detect AS-REP roasting of honey account |
|
||||
|
||||
### Making Honeytokens Realistic
|
||||
|
||||
Per Trimarc Security research, effective honeytokens must appear legitimate:
|
||||
|
||||
- **Age the account**: Repurpose old inactive accounts (10-15 year old accounts in
|
||||
similarly aged domains appear authentic)
|
||||
- **Set AdminCount=1**: Flags the account as having elevated AD rights, making it
|
||||
an attractive Kerberoasting target
|
||||
- **Use realistic naming**: Match organizational naming conventions (svc_sqlbackup,
|
||||
admin.maintenance, svc_exchange_legacy)
|
||||
- **Set old password date**: Password age of 10+ years with an SPN looks like a
|
||||
high-value, neglected service account to attackers
|
||||
- **Add group memberships**: Place in visible groups like "Remote Desktop Users" or
|
||||
a custom "Backup Operators" to increase attacker interest
|
||||
- **Avoid detection tells**: Attackers check creation date vs. last logon vs.
|
||||
password change date for consistency
|
||||
|
||||
## Instructions
|
||||
|
||||
### Step 1: Deploy Fake Privileged Admin Account
|
||||
|
||||
Create a honeytoken account that mimics a legacy privileged service account.
|
||||
|
||||
```powershell
|
||||
# Import the deployment module
|
||||
Import-Module .\scripts\Deploy-ADHoneytokens.ps1
|
||||
|
||||
# Create a honeytoken admin account
|
||||
$honeyAdmin = New-HoneytokenAdmin `
|
||||
-SamAccountName "svc_sqlbackup_legacy" `
|
||||
-DisplayName "SQL Backup Service (Legacy)" `
|
||||
-Description "Legacy SQL Server backup service account - DO NOT DELETE" `
|
||||
-OU "OU=Service Accounts,DC=corp,DC=example,DC=com" `
|
||||
-PasswordLength 128 `
|
||||
-SetAdminCount $true
|
||||
|
||||
Write-Host "Honeytoken admin created: $($honeyAdmin.DistinguishedName)"
|
||||
```
|
||||
|
||||
### Step 2: Deploy Fake SPN for Kerberoasting Detection
|
||||
|
||||
Assign a realistic but fake SPN to the honeytoken account. Any TGS request
|
||||
for this SPN is definitively malicious (honeyroasting).
|
||||
|
||||
```powershell
|
||||
# Add fake SPN to honeytoken account
|
||||
$honeySPN = Add-HoneytokenSPN `
|
||||
-SamAccountName "svc_sqlbackup_legacy" `
|
||||
-ServiceClass "MSSQLSvc" `
|
||||
-Hostname "sql-legacy-bak01.corp.example.com" `
|
||||
-Port 1433
|
||||
|
||||
Write-Host "Honey SPN registered: $($honeySPN.SPN)"
|
||||
Write-Host "Monitor Event ID 4769 for TGS requests targeting this SPN"
|
||||
```
|
||||
|
||||
### Step 3: Deploy Decoy GPO with Credential Trap
|
||||
|
||||
Create a fake GPO in SYSVOL with an embedded cpassword (Group Policy Preference
|
||||
password). Attackers using tools like Get-GPPPassword or gpp-decrypt will find
|
||||
and attempt to use these credentials, triggering detection.
|
||||
|
||||
```powershell
|
||||
# Create decoy GPO with cpassword trap
|
||||
$decoyGPO = New-DecoyGPO `
|
||||
-GPOName "Server Maintenance Policy (Legacy)" `
|
||||
-DecoyUsername "admin_maintenance" `
|
||||
-DecoyDomain "CORP" `
|
||||
-SYSVOLPath "\\corp.example.com\SYSVOL\corp.example.com\Policies" `
|
||||
-EnableAuditSACL $true
|
||||
|
||||
Write-Host "Decoy GPO created: $($decoyGPO.GPOGuid)"
|
||||
Write-Host "SACL audit enabled - any read attempt will generate Event ID 4663"
|
||||
```
|
||||
|
||||
### Step 4: Create Deceptive BloodHound Paths
|
||||
|
||||
Set ACL permissions that create fake attack paths visible to BloodHound/SharpHound
|
||||
reconnaissance, leading attackers toward monitored honeytokens.
|
||||
|
||||
```powershell
|
||||
# Create fake BloodHound attack path
|
||||
$deceptivePath = New-DeceptiveBloodHoundPath `
|
||||
-HoneytokenSamAccount "svc_sqlbackup_legacy" `
|
||||
-TargetHighValueGroup "Domain Admins" `
|
||||
-IntermediateOU "OU=Service Accounts,DC=corp,DC=example,DC=com"
|
||||
|
||||
Write-Host "Deceptive path created: $($deceptivePath.PathDescription)"
|
||||
```
|
||||
|
||||
### Step 5: Configure Detection Rules
|
||||
|
||||
Set up SIEM detection rules to alert on any honeytoken interaction.
|
||||
|
||||
```python
|
||||
# Using the Python detection agent
|
||||
from agent import ADHoneytokenMonitor
|
||||
|
||||
monitor = ADHoneytokenMonitor(config_path="honeytoken_config.json")
|
||||
|
||||
# Register all honeytokens for monitoring
|
||||
monitor.register_honeytoken("svc_sqlbackup_legacy", token_type="admin_account")
|
||||
monitor.register_honeytoken("MSSQLSvc/sql-legacy-bak01.corp.example.com:1433", token_type="spn")
|
||||
monitor.register_honeytoken("admin_maintenance", token_type="gpo_credential")
|
||||
|
||||
# Generate SIEM detection rules
|
||||
splunk_rules = monitor.generate_detection_rules(siem="splunk")
|
||||
sentinel_rules = monitor.generate_detection_rules(siem="sentinel")
|
||||
sigma_rules = monitor.generate_detection_rules(siem="sigma")
|
||||
|
||||
for rule in sigma_rules:
|
||||
print(f"Rule: {rule['title']}")
|
||||
print(f" Detection: {rule['detection_logic']}")
|
||||
```
|
||||
|
||||
### Step 6: Validate Deployment
|
||||
|
||||
Test the honeytokens to ensure detection fires correctly.
|
||||
|
||||
```powershell
|
||||
# Validate honeytoken deployment
|
||||
$validation = Test-HoneytokenDeployment `
|
||||
-SamAccountName "svc_sqlbackup_legacy" `
|
||||
-ValidateAdminCount `
|
||||
-ValidateSPN `
|
||||
-ValidateGPODecoy `
|
||||
-ValidateAuditPolicy
|
||||
|
||||
$validation | Format-Table Check, Status, Details -AutoSize
|
||||
```
|
||||
|
||||
## Examples
|
||||
|
||||
### Full Deployment Pipeline
|
||||
|
||||
```powershell
|
||||
Import-Module .\scripts\Deploy-ADHoneytokens.ps1
|
||||
|
||||
# Deploy complete honeytoken suite
|
||||
$deployment = Deploy-FullHoneytokenSuite `
|
||||
-Environment "Production" `
|
||||
-ServiceAccountOU "OU=Service Accounts,DC=corp,DC=example,DC=com" `
|
||||
-SYSVOLPath "\\corp.example.com\SYSVOL\corp.example.com\Policies" `
|
||||
-TokenCount 3 `
|
||||
-IncludeSPN $true `
|
||||
-IncludeGPODecoy $true `
|
||||
-IncludeBloodHoundPath $true `
|
||||
-SIEMType "Splunk"
|
||||
|
||||
# Output deployment report
|
||||
$deployment.Tokens | Format-Table Name, Type, SPN, DetectionRule -AutoSize
|
||||
$deployment | Export-Csv "honeytoken_deployment_report.csv" -NoTypeInformation
|
||||
```
|
||||
|
||||
### Kerberoasting Detection Query (Splunk)
|
||||
|
||||
```spl
|
||||
index=wineventlog EventCode=4769 ServiceName="svc_sqlbackup_legacy"
|
||||
| eval alert_severity="critical"
|
||||
| eval alert_type="honeytoken_kerberoast"
|
||||
| table _time, src_ip, Account_Name, ServiceName, Ticket_Encryption_Type
|
||||
| sort - _time
|
||||
```
|
||||
|
||||
### Microsoft Sentinel KQL Detection
|
||||
|
||||
```kql
|
||||
SecurityEvent
|
||||
| where EventID == 4769
|
||||
| where ServiceName in ("svc_sqlbackup_legacy", "svc_exchange_legacy")
|
||||
| extend AlertType = "Honeytoken Kerberoast Detected"
|
||||
| project TimeGenerated, Computer, Account, ServiceName, IpAddress, TicketEncryptionType
|
||||
```
|
||||
|
||||
## References
|
||||
|
||||
- Trimarc Security - The Art of the Honeypot Account: https://www.hub.trimarcsecurity.com/post/the-art-of-the-honeypot-account-making-the-unusual-look-normal
|
||||
- ADSecurity.org - Detecting Kerberoasting Activity Part 2 (Honeypot): https://adsecurity.org/?p=3513
|
||||
- Microsoft Defender for Identity Honeytokens: https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/deceptive-defense-best-practices-for-identity-based-honeytokens-in-microsoft-def/3851641
|
||||
- SpecterOps - Kerberoasting and AES-256: https://specterops.io/blog/2025/10/21/is-kerberoasting-still-a-risk-when-aes-256-kerberos-encryption-is-enabled/
|
||||
- APT29a Blog - Deploying Honeytokens in AD: https://apt29a.blogspot.com/2019/11/deploying-honeytokens-in-active.html
|
||||
- ADSecurity.org - Detecting Kerberoasting Activity: https://adsecurity.org/?p=3458
|
||||
@@ -0,0 +1,326 @@
|
||||
# API Reference: Active Directory Honeytoken Deployment
|
||||
|
||||
## PowerShellGenerator
|
||||
|
||||
Generates PowerShell scripts for AD honeytoken deployment operations.
|
||||
|
||||
### Methods
|
||||
|
||||
#### `generate_create_honeytoken_account(...)`
|
||||
Generate PowerShell to create a honeytoken AD account with AdminCount=1, backdated password, group memberships, and SACL audit rules.
|
||||
|
||||
| Parameter | Type | Default | Description |
|
||||
|-----------|------|---------|-------------|
|
||||
| `sam_account_name` | `str` | required | sAMAccountName for the honeytoken |
|
||||
| `display_name` | `str` | required | Display name |
|
||||
| `description` | `str` | required | Description field |
|
||||
| `ou_dn` | `str` | required | Distinguished Name of target OU |
|
||||
| `password_length` | `int` | `128` | Random password length |
|
||||
| `set_admin_count` | `bool` | `True` | Set AdminCount=1 |
|
||||
| `account_age_days` | `int` | `5475` | Days to backdate password (~15 years) |
|
||||
|
||||
**Returns:** `str` -- Complete PowerShell script.
|
||||
|
||||
**AD Operations Performed:**
|
||||
- Creates AD user account with strong random password
|
||||
- Sets AdminCount=1 (appears as privileged account to BloodHound)
|
||||
- Backdates pwdLastSet to simulate aged service account
|
||||
- Adds to Remote Desktop Users group
|
||||
- Configures SACL audit rule (Everyone/ReadProperty/Success)
|
||||
|
||||
**Detection:** Event ID 4662 (directory service object accessed)
|
||||
|
||||
#### `generate_add_honey_spn(...)`
|
||||
Generate PowerShell to add a fake SPN for Kerberoasting detection (honeyroasting).
|
||||
|
||||
| Parameter | Type | Default | Description |
|
||||
|-----------|------|---------|-------------|
|
||||
| `sam_account_name` | `str` | required | Account to add SPN to |
|
||||
| `service_class` | `str` | `"MSSQLSvc"` | SPN service class |
|
||||
| `hostname` | `str` | required | Fake hostname |
|
||||
| `port` | `int` | `1433` | Service port |
|
||||
|
||||
**Returns:** `str` -- PowerShell script that registers the SPN and enables RC4+AES encryption.
|
||||
|
||||
**Detection:** Event ID 4769 (Kerberos TGS ticket requested) where ServiceName matches the honeytoken account. Any TGS request for this SPN is definitively malicious.
|
||||
|
||||
#### `generate_decoy_gpo(...)`
|
||||
Generate PowerShell to create a decoy GPO with cpassword credential trap in SYSVOL.
|
||||
|
||||
| Parameter | Type | Default | Description |
|
||||
|-----------|------|---------|-------------|
|
||||
| `gpo_name` | `str` | required | GPO display name |
|
||||
| `decoy_username` | `str` | required | Username in cpassword trap |
|
||||
| `decoy_domain` | `str` | required | Short domain name (e.g., CORP) |
|
||||
| `sysvol_path` | `str` | required | SYSVOL Policies path |
|
||||
| `enable_sacl` | `bool` | `True` | Set SACL audit on GPO folder |
|
||||
|
||||
**Returns:** `str` -- PowerShell script that creates GPO folder structure, plants Groups.xml with cpassword, creates trap AD account with different password, and sets SACL.
|
||||
|
||||
**Detection Chain:**
|
||||
1. Event ID 4663 (SYSVOL folder read)
|
||||
2. Offline: Attacker decrypts cpassword
|
||||
3. Event ID 4625 (failed logon with decoy credentials)
|
||||
4. Correlation: 4663 + 4625 from same source IP = confirmed attacker
|
||||
|
||||
#### `generate_deceptive_bloodhound_path(...)`
|
||||
Generate PowerShell to create fake BloodHound attack paths leading to monitored honeytokens.
|
||||
|
||||
| Parameter | Type | Default | Description |
|
||||
|-----------|------|---------|-------------|
|
||||
| `honeytoken_sam` | `str` | required | Honeytoken account name |
|
||||
| `target_group` | `str` | `"Domain Admins"` | High-value group for deceptive path |
|
||||
| `intermediate_ou` | `str` | `"OU=Service Accounts"` | OU for intermediate objects |
|
||||
|
||||
**Returns:** `str` -- PowerShell script that creates GenericAll ACE, deceptive intermediate group, and WriteDacl edge with deny safety net.
|
||||
|
||||
**BloodHound Path Created:**
|
||||
```
|
||||
Remote Desktop Users -[GenericAll]-> honeytoken_account
|
||||
honeytoken_account -[MemberOf]-> IT-Infrastructure-Admins
|
||||
honeytoken_account -[WriteDacl]-> Domain Admins (blocked by deny ACE)
|
||||
```
|
||||
|
||||
#### `generate_validation_script(sam_account_name)`
|
||||
Generate PowerShell to validate honeytoken deployment integrity.
|
||||
|
||||
**Checks Performed:**
|
||||
|
||||
| Check | Pass Criteria |
|
||||
|-------|---------------|
|
||||
| Account Exists | Account found in AD |
|
||||
| Account Enabled | Enabled = True |
|
||||
| AdminCount=1 | AdminCount attribute is 1 |
|
||||
| SPN Configured | At least one SPN registered |
|
||||
| Password Age | > 365 days |
|
||||
| SACL Audit | At least one audit rule configured |
|
||||
| Group Memberships | Lists all group memberships |
|
||||
| RC4 Supported | msDS-SupportedEncryptionTypes includes 0x4 |
|
||||
| Kerberos Audit | auditpol shows Kerberos TGS auditing enabled |
|
||||
|
||||
---
|
||||
|
||||
## SIEMRuleGenerator
|
||||
|
||||
Generates detection rules for SIEM platforms targeting honeytoken activity.
|
||||
|
||||
### Methods
|
||||
|
||||
#### `generate_detection_rules(honeytoken_accounts, honey_spns, gpo_trap_accounts, siem="sigma")`
|
||||
|
||||
| Parameter | Type | Description |
|
||||
|-----------|------|-------------|
|
||||
| `honeytoken_accounts` | `list[str]` | Account names to monitor |
|
||||
| `honey_spns` | `list[str]` | SPN values to monitor |
|
||||
| `gpo_trap_accounts` | `list[str]` | GPO credential trap usernames |
|
||||
| `siem` | `str` | Target platform: `sigma`, `splunk`, or `sentinel` |
|
||||
|
||||
**Returns:** `list[dict]` -- Each rule contains `title`, `detection_logic`, and `rule` (full query text).
|
||||
|
||||
### Generated Rules by Platform
|
||||
|
||||
**Sigma Rules:**
|
||||
|
||||
| Rule | Event ID | MITRE Technique |
|
||||
|------|----------|-----------------|
|
||||
| Honeytoken Kerberoast Detected | 4769 | T1558.003 |
|
||||
| Honeytoken GPO Credential Use Detected | 4624, 4625 | T1552.006 |
|
||||
| Honeytoken AD Object Accessed | 4662 | T1087.002 |
|
||||
|
||||
**Splunk SPL Rules:**
|
||||
|
||||
| Rule | Description |
|
||||
|------|-------------|
|
||||
| Honeytoken Kerberoast Detection | Index wineventlog EventCode=4769 with ServiceName filter |
|
||||
| Honeytoken GPO Credential Use | EventCode 4624/4625 with TargetUserName filter |
|
||||
| Attack Chain Correlation | SYSVOL enum (4663) -> credential use (4625) by same source IP |
|
||||
|
||||
**Microsoft Sentinel KQL Rules:**
|
||||
|
||||
| Rule | Description |
|
||||
|------|-------------|
|
||||
| Honeytoken Kerberoast Detection | SecurityEvent EventID 4769 with ServiceName filter |
|
||||
| Honeytoken GPO Credential Use | SecurityEvent EventID 4624/4625 with TargetUserName filter |
|
||||
|
||||
#### `export_rules(output_dir, format="json")`
|
||||
Export all generated rules to files on disk.
|
||||
|
||||
**Returns:** `list[str]` of saved file paths.
|
||||
|
||||
---
|
||||
|
||||
## ADHoneytokenMonitor
|
||||
|
||||
Monitors Windows Event Logs for honeytoken interactions and generates alerts.
|
||||
|
||||
### Constructor
|
||||
```python
|
||||
ADHoneytokenMonitor(config_path=None)
|
||||
```
|
||||
|
||||
### Methods
|
||||
|
||||
#### `register_honeytoken(identifier, token_type="admin_account", metadata=None)`
|
||||
Register a honeytoken for monitoring.
|
||||
|
||||
| Token Type | Description |
|
||||
|------------|-------------|
|
||||
| `admin_account` | Fake privileged AD account |
|
||||
| `spn` | Fake Service Principal Name |
|
||||
| `gpo_credential` | Decoy GPO cpassword trap account |
|
||||
|
||||
#### `analyze_event_log(events)`
|
||||
Analyze Windows Event Log entries for honeytoken interactions.
|
||||
|
||||
| Event ID | Alert Type | Severity |
|
||||
|----------|------------|----------|
|
||||
| 4769 | `KERBEROAST_HONEYTOKEN` | critical |
|
||||
| 4624 | `HONEYTOKEN_LOGON` | critical |
|
||||
| 4625 | `HONEYTOKEN_LOGON_FAILED` | critical |
|
||||
| 4662 | `HONEYTOKEN_DACL_READ` | high |
|
||||
| 5136 | `HONEYTOKEN_GPO_MODIFIED` | critical |
|
||||
|
||||
**Returns:** `list[dict]` -- Alerts with `alert_id`, `alert_type`, `severity`, `description`, `mitre_technique`, `source_ip`, `source_host`.
|
||||
|
||||
#### `generate_detection_rules(siem="sigma")`
|
||||
Generate SIEM detection rules for all registered honeytokens.
|
||||
|
||||
#### `get_alert_summary()`
|
||||
Get aggregated summary of all alerts by severity, type, and source IP.
|
||||
|
||||
---
|
||||
|
||||
## HoneytokenDeployer
|
||||
|
||||
Orchestrates full honeytoken deployment and generates all artifacts.
|
||||
|
||||
### Constructor
|
||||
```python
|
||||
HoneytokenDeployer(domain="corp.example.com",
|
||||
service_account_ou="OU=Service Accounts",
|
||||
sysvol_path="")
|
||||
```
|
||||
|
||||
### Methods
|
||||
|
||||
#### `generate_realistic_name()`
|
||||
Generate a realistic service account name using templates matching common organizational patterns.
|
||||
|
||||
**Returns:** `dict` with `sam_account_name`, `display_name`, `hostname`.
|
||||
|
||||
#### `deploy_full_suite(...)`
|
||||
Generate complete deployment artifacts for a full honeytoken suite.
|
||||
|
||||
| Parameter | Type | Default | Description |
|
||||
|-----------|------|---------|-------------|
|
||||
| `token_count` | `int` | `3` | Number of honeytoken accounts |
|
||||
| `include_spn` | `bool` | `True` | Add fake SPNs |
|
||||
| `include_gpo` | `bool` | `True` | Create decoy GPO |
|
||||
| `include_bloodhound` | `bool` | `True` | Create deceptive BloodHound paths |
|
||||
| `siem_type` | `str` | `"sigma"` | Target SIEM for detection rules |
|
||||
|
||||
**Returns:** `dict` with `deployment_id`, `tokens`, `scripts`, `detection_rules`.
|
||||
|
||||
#### `save_deployment(deployment, output_dir)`
|
||||
Save all deployment artifacts (PowerShell scripts, detection rules, manifest) to disk.
|
||||
|
||||
**Returns:** `list[str]` of saved file paths.
|
||||
|
||||
---
|
||||
|
||||
## PowerShell Module: Deploy-ADHoneytokens.ps1
|
||||
|
||||
### Exported Functions
|
||||
|
||||
| Function | Description |
|
||||
|----------|-------------|
|
||||
| `New-HoneytokenAdmin` | Create honeytoken AD account with AdminCount=1, SACL, backdated password |
|
||||
| `Add-HoneytokenSPN` | Register fake SPN for Kerberoasting detection |
|
||||
| `New-DecoyGPO` | Create decoy GPO with cpassword trap in SYSVOL |
|
||||
| `New-DeceptiveBloodHoundPath` | Create fake BloodHound attack paths |
|
||||
| `Test-HoneytokenDeployment` | Validate honeytoken deployment integrity |
|
||||
| `Deploy-FullHoneytokenSuite` | Deploy complete honeytoken suite |
|
||||
|
||||
### Prerequisites
|
||||
```powershell
|
||||
#Requires -Modules ActiveDirectory
|
||||
#Requires -Version 5.1
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Windows Event IDs for Honeytoken Detection
|
||||
|
||||
| Event ID | Description | Honeytoken Use |
|
||||
|----------|-------------|----------------|
|
||||
| 4769 | Kerberos TGS ticket requested | Kerberoast against honey SPN |
|
||||
| 4768 | Kerberos TGT requested | AS-REP roasting of honey account |
|
||||
| 4625 | Failed logon attempt | Credential use from decoy GPO |
|
||||
| 4624 | Successful logon | Honeytoken account compromise |
|
||||
| 4662 | Directory service object accessed | DACL read on honeytoken user |
|
||||
| 4648 | Logon with explicit credentials | Pass-the-hash detection |
|
||||
| 5136 | Directory service object modified | GPO modification |
|
||||
| 5137 | Directory service object created | GPO creation |
|
||||
| 4663 | Attempt to access object | SYSVOL decoy file read |
|
||||
|
||||
---
|
||||
|
||||
## CLI Usage
|
||||
|
||||
```bash
|
||||
# Full deployment (generates all scripts, rules, and manifest)
|
||||
python agent.py --action full_deploy \
|
||||
--domain corp.example.com \
|
||||
--ou "OU=Service Accounts" \
|
||||
--token-count 3 \
|
||||
--siem sigma \
|
||||
--output-dir honeytoken_deployment
|
||||
|
||||
# Generate detection rules only
|
||||
python agent.py --action generate_rules \
|
||||
--account-name svc_sqlbackup_legacy \
|
||||
--siem splunk
|
||||
|
||||
# Generate single account creation script
|
||||
python agent.py --action deploy_account \
|
||||
--account-name svc_sqlbackup_legacy \
|
||||
--domain corp.example.com
|
||||
|
||||
# Generate SPN addition script
|
||||
python agent.py --action deploy_spn \
|
||||
--account-name svc_sqlbackup_legacy
|
||||
|
||||
# Generate decoy GPO script
|
||||
python agent.py --action deploy_gpo \
|
||||
--domain corp.example.com
|
||||
|
||||
# Generate BloodHound deception script
|
||||
python agent.py --action deploy_bloodhound \
|
||||
--account-name svc_sqlbackup_legacy
|
||||
|
||||
# Validate deployment
|
||||
python agent.py --action validate \
|
||||
--account-name svc_sqlbackup_legacy
|
||||
|
||||
# Analyze event logs for honeytoken alerts
|
||||
python agent.py --action analyze_logs \
|
||||
--account-name svc_sqlbackup_legacy \
|
||||
--event-log events.json
|
||||
```
|
||||
|
||||
### CLI Arguments
|
||||
|
||||
| Argument | Default | Description |
|
||||
|----------|---------|-------------|
|
||||
| `--action` | `full_deploy` | Action to perform |
|
||||
| `--domain` | `corp.example.com` | AD domain FQDN |
|
||||
| `--ou` | `OU=Service Accounts` | OU for honeytoken accounts |
|
||||
| `--sysvol` | auto | SYSVOL Policies path |
|
||||
| `--account-name` | `svc_sqlbackup_legacy` | Honeytoken account name |
|
||||
| `--token-count` | `3` | Number of honeytokens to deploy |
|
||||
| `--siem` | `sigma` | Target SIEM: `sigma`, `splunk`, `sentinel` |
|
||||
| `--output-dir` | `honeytoken_deployment` | Output directory |
|
||||
| `--include-spn` | `True` | Include fake SPNs |
|
||||
| `--include-gpo` | `True` | Include decoy GPO |
|
||||
| `--include-bloodhound` | `True` | Include BloodHound deception |
|
||||
| `--event-log` | `None` | Path to event log JSON for analysis |
|
||||
@@ -0,0 +1,659 @@
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Active Directory Honeytoken Deployment Module
|
||||
|
||||
.DESCRIPTION
|
||||
Deploys deception-based honeytokens in Active Directory including:
|
||||
- Fake privileged accounts with AdminCount=1
|
||||
- Fake SPNs for Kerberoasting detection (honeyroasting)
|
||||
- Decoy GPOs with cpassword traps
|
||||
- Deceptive BloodHound attack paths
|
||||
- SACL audit rules for detection
|
||||
|
||||
.NOTES
|
||||
Author: mukul975
|
||||
Version: 1.0
|
||||
References:
|
||||
- Trimarc Security: The Art of the Honeypot Account
|
||||
- ADSecurity.org: Detecting Kerberoasting Activity Part 2
|
||||
- Microsoft Defender for Identity Honeytokens
|
||||
- SpecterOps: Kerberoasting and AES-256
|
||||
#>
|
||||
|
||||
#Requires -Modules ActiveDirectory
|
||||
#Requires -Version 5.1
|
||||
|
||||
Set-StrictMode -Version Latest
|
||||
$ErrorActionPreference = "Stop"
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
# Module-level variables
|
||||
# ---------------------------------------------------------------------------
|
||||
|
||||
$Script:DeployedTokens = @()
|
||||
$Script:DeploymentLog = @()
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
# Helper Functions
|
||||
# ---------------------------------------------------------------------------
|
||||
|
||||
function Write-DeployLog {
|
||||
param(
|
||||
[string]$Message,
|
||||
[ValidateSet("INFO", "WARN", "ERROR", "SUCCESS")]
|
||||
[string]$Level = "INFO"
|
||||
)
|
||||
$entry = [PSCustomObject]@{
|
||||
Timestamp = (Get-Date -Format "yyyy-MM-dd HH:mm:ss")
|
||||
Level = $Level
|
||||
Message = $Message
|
||||
}
|
||||
$Script:DeploymentLog += $entry
|
||||
$color = switch ($Level) {
|
||||
"INFO" { "White" }
|
||||
"WARN" { "Yellow" }
|
||||
"ERROR" { "Red" }
|
||||
"SUCCESS" { "Green" }
|
||||
}
|
||||
Write-Host "[$Level] $Message" -ForegroundColor $color
|
||||
}
|
||||
|
||||
function New-SecureRandomPassword {
|
||||
param([int]$Length = 128)
|
||||
$chars = 'abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789!@#$%^&*()-_=+[]{}|;:,.<>?'
|
||||
$password = -join (1..$Length | ForEach-Object { $chars[(Get-Random -Maximum $chars.Length)] })
|
||||
return $password
|
||||
}
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
# New-HoneytokenAdmin
|
||||
# ---------------------------------------------------------------------------
|
||||
|
||||
function New-HoneytokenAdmin {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Creates a honeytoken admin account in Active Directory.
|
||||
|
||||
.DESCRIPTION
|
||||
Creates a realistic-looking service account with AdminCount=1 set,
|
||||
backdated password age, group memberships, and SACL audit rules.
|
||||
The account appears as a high-value target to attackers using
|
||||
BloodHound, SharpHound, or manual AD enumeration.
|
||||
|
||||
.PARAMETER SamAccountName
|
||||
The sAMAccountName for the honeytoken account.
|
||||
|
||||
.PARAMETER DisplayName
|
||||
The display name for the account.
|
||||
|
||||
.PARAMETER Description
|
||||
The description field (should look legitimate).
|
||||
|
||||
.PARAMETER OU
|
||||
The Distinguished Name of the OU to create the account in.
|
||||
|
||||
.PARAMETER PasswordLength
|
||||
Length of the random password (default: 128).
|
||||
|
||||
.PARAMETER SetAdminCount
|
||||
If true, sets AdminCount=1 on the account (default: true).
|
||||
|
||||
.PARAMETER AccountAgeDays
|
||||
Number of days to backdate the password (default: 5475 = ~15 years).
|
||||
|
||||
.EXAMPLE
|
||||
New-HoneytokenAdmin -SamAccountName "svc_sqlbackup_legacy" `
|
||||
-DisplayName "SQL Backup Service (Legacy)" `
|
||||
-Description "Legacy SQL Server backup service account - DO NOT DELETE" `
|
||||
-OU "OU=Service Accounts,DC=corp,DC=example,DC=com"
|
||||
#>
|
||||
[CmdletBinding()]
|
||||
param(
|
||||
[Parameter(Mandatory)]
|
||||
[string]$SamAccountName,
|
||||
|
||||
[Parameter(Mandatory)]
|
||||
[string]$DisplayName,
|
||||
|
||||
[string]$Description = "Legacy service account - DO NOT DELETE",
|
||||
|
||||
[Parameter(Mandatory)]
|
||||
[string]$OU,
|
||||
|
||||
[int]$PasswordLength = 128,
|
||||
|
||||
[bool]$SetAdminCount = $true,
|
||||
|
||||
[int]$AccountAgeDays = 5475
|
||||
)
|
||||
|
||||
Write-DeployLog "Creating honeytoken admin: $SamAccountName" "INFO"
|
||||
|
||||
# Generate strong random password
|
||||
$Password = New-SecureRandomPassword -Length $PasswordLength
|
||||
$SecurePassword = ConvertTo-SecureString -String $Password -AsPlainText -Force
|
||||
|
||||
# Create the account
|
||||
$Domain = Get-ADDomain
|
||||
$UPN = "$SamAccountName@$($Domain.DNSRoot)"
|
||||
|
||||
$UserParams = @{
|
||||
Name = $DisplayName
|
||||
SamAccountName = $SamAccountName
|
||||
UserPrincipalName = $UPN
|
||||
DisplayName = $DisplayName
|
||||
Description = $Description
|
||||
Path = $OU
|
||||
AccountPassword = $SecurePassword
|
||||
Enabled = $true
|
||||
PasswordNeverExpires = $true
|
||||
CannotChangePassword = $true
|
||||
ChangePasswordAtLogon = $false
|
||||
}
|
||||
|
||||
try {
|
||||
New-ADUser @UserParams
|
||||
Write-DeployLog "Account created: $SamAccountName" "SUCCESS"
|
||||
}
|
||||
catch {
|
||||
Write-DeployLog "Failed to create account: $_" "ERROR"
|
||||
throw
|
||||
}
|
||||
|
||||
# Set AdminCount=1
|
||||
if ($SetAdminCount) {
|
||||
Set-ADUser -Identity $SamAccountName -Replace @{AdminCount = 1}
|
||||
Write-DeployLog "AdminCount set to 1" "SUCCESS"
|
||||
}
|
||||
|
||||
# Backdate password
|
||||
$AgeDate = (Get-Date).AddDays(-$AccountAgeDays)
|
||||
$FileTime = $AgeDate.ToFileTime()
|
||||
Set-ADUser -Identity $SamAccountName -Replace @{pwdLastSet = $FileTime}
|
||||
Write-DeployLog "Password backdated to: $($AgeDate.ToString('yyyy-MM-dd'))" "SUCCESS"
|
||||
|
||||
# Add to visible groups
|
||||
Add-ADGroupMember -Identity "Remote Desktop Users" -Members $SamAccountName
|
||||
Write-DeployLog "Added to Remote Desktop Users" "SUCCESS"
|
||||
|
||||
# Set SACL for audit
|
||||
$UserDN = (Get-ADUser -Identity $SamAccountName).DistinguishedName
|
||||
$Acl = Get-Acl "AD:\$UserDN"
|
||||
$AuditRule = New-Object System.DirectoryServices.ActiveDirectoryAuditRule(
|
||||
[System.Security.Principal.SecurityIdentifier]"S-1-1-0",
|
||||
[System.DirectoryServices.ActiveDirectoryRights]"ReadProperty",
|
||||
[System.Security.AccessControl.AuditFlags]"Success",
|
||||
[System.DirectoryServices.ActiveDirectorySecurityInheritance]"None"
|
||||
)
|
||||
$Acl.AddAuditRule($AuditRule)
|
||||
Set-Acl "AD:\$UserDN" $Acl
|
||||
Write-DeployLog "SACL audit rule configured (Event ID 4662)" "SUCCESS"
|
||||
|
||||
$result = Get-ADUser -Identity $SamAccountName -Properties *
|
||||
$Script:DeployedTokens += $result
|
||||
|
||||
return $result
|
||||
}
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
# Add-HoneytokenSPN
|
||||
# ---------------------------------------------------------------------------
|
||||
|
||||
function Add-HoneytokenSPN {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Adds a fake SPN to a honeytoken account for Kerberoasting detection.
|
||||
|
||||
.DESCRIPTION
|
||||
Registers a fake Service Principal Name on a honeytoken account.
|
||||
Any TGS ticket request for this SPN is definitively malicious since
|
||||
the associated service does not exist. This is known as "honeyroasting".
|
||||
|
||||
.PARAMETER SamAccountName
|
||||
The honeytoken account to add the SPN to.
|
||||
|
||||
.PARAMETER ServiceClass
|
||||
The SPN service class (default: MSSQLSvc).
|
||||
|
||||
.PARAMETER Hostname
|
||||
The fake hostname for the SPN.
|
||||
|
||||
.PARAMETER Port
|
||||
The service port (default: 1433).
|
||||
#>
|
||||
[CmdletBinding()]
|
||||
param(
|
||||
[Parameter(Mandatory)]
|
||||
[string]$SamAccountName,
|
||||
|
||||
[string]$ServiceClass = "MSSQLSvc",
|
||||
|
||||
[Parameter(Mandatory)]
|
||||
[string]$Hostname,
|
||||
|
||||
[int]$Port = 1433
|
||||
)
|
||||
|
||||
$SPN = "$ServiceClass/${Hostname}:$Port"
|
||||
Write-DeployLog "Adding honey SPN: $SPN to $SamAccountName" "INFO"
|
||||
|
||||
# Verify account exists
|
||||
$User = Get-ADUser -Identity $SamAccountName -Properties ServicePrincipalNames -ErrorAction Stop
|
||||
|
||||
# Add SPN
|
||||
Set-ADUser -Identity $SamAccountName -ServicePrincipalNames @{Add = $SPN}
|
||||
Write-DeployLog "SPN registered: $SPN" "SUCCESS"
|
||||
|
||||
# Enable RC4 + AES encryption (makes it attractive to Kerberoast tools)
|
||||
Set-ADUser -Identity $SamAccountName -Replace @{"msDS-SupportedEncryptionTypes" = 28}
|
||||
Write-DeployLog "Encryption types set to RC4+AES128+AES256" "SUCCESS"
|
||||
|
||||
return [PSCustomObject]@{
|
||||
SamAccountName = $SamAccountName
|
||||
SPN = $SPN
|
||||
ServiceClass = $ServiceClass
|
||||
Hostname = $Hostname
|
||||
Port = $Port
|
||||
}
|
||||
}
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
# New-DecoyGPO
|
||||
# ---------------------------------------------------------------------------
|
||||
|
||||
function New-DecoyGPO {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Creates a decoy GPO with cpassword credential trap.
|
||||
|
||||
.DESCRIPTION
|
||||
Creates a fake GPO folder in SYSVOL containing a Groups.xml with
|
||||
encrypted credentials (cpassword). Attackers using Get-GPPPassword,
|
||||
gpp-decrypt, or CrackMapExec will find and attempt to use these
|
||||
credentials, which triggers Event ID 4625 (failed logon).
|
||||
|
||||
.PARAMETER GPOName
|
||||
Descriptive name for the decoy GPO.
|
||||
|
||||
.PARAMETER DecoyUsername
|
||||
The username to embed in the cpassword trap.
|
||||
|
||||
.PARAMETER DecoyDomain
|
||||
The short domain name (e.g., CORP).
|
||||
|
||||
.PARAMETER SYSVOLPath
|
||||
The path to the SYSVOL Policies folder.
|
||||
|
||||
.PARAMETER EnableAuditSACL
|
||||
Whether to set SACL audit on the GPO folder (default: true).
|
||||
#>
|
||||
[CmdletBinding()]
|
||||
param(
|
||||
[Parameter(Mandatory)]
|
||||
[string]$GPOName,
|
||||
|
||||
[Parameter(Mandatory)]
|
||||
[string]$DecoyUsername,
|
||||
|
||||
[Parameter(Mandatory)]
|
||||
[string]$DecoyDomain,
|
||||
|
||||
[Parameter(Mandatory)]
|
||||
[string]$SYSVOLPath,
|
||||
|
||||
[bool]$EnableAuditSACL = $true
|
||||
)
|
||||
|
||||
$GPOGuid = [guid]::NewGuid().ToString().ToUpper()
|
||||
Write-DeployLog "Creating decoy GPO: $GPOName (GUID: $GPOGuid)" "INFO"
|
||||
|
||||
# Create folder structure
|
||||
$GPOPath = Join-Path $SYSVOLPath "{$GPOGuid}"
|
||||
$MachinePath = Join-Path $GPOPath "Machine\Preferences\Groups"
|
||||
New-Item -ItemType Directory -Path $MachinePath -Force | Out-Null
|
||||
|
||||
# Generate fake cpassword
|
||||
$FakePassword = "H0n3yT0k3n_Tr4p_$(Get-Date -Format 'yyyy')!"
|
||||
$FakeCPassword = [Convert]::ToBase64String([Text.Encoding]::Unicode.GetBytes($FakePassword))
|
||||
$UserGuid = [guid]::NewGuid().ToString().ToUpper()
|
||||
|
||||
# Create Groups.xml with cpassword trap
|
||||
$GroupsXml = @"
|
||||
<?xml version="1.0" encoding="utf-8"?>
|
||||
<Groups clsid="{3125E937-EB16-4b4c-9934-544FC6D24D26}">
|
||||
<User clsid="{DF5F1855-51E5-4d24-8B1A-D9BDE98BA1D1}"
|
||||
name="$DecoyUsername"
|
||||
image="2"
|
||||
changed="2011-07-15 08:30:22"
|
||||
uid="{$UserGuid}">
|
||||
<Properties action="U"
|
||||
newName=""
|
||||
fullName="Maintenance Administrator"
|
||||
description="Legacy maintenance account"
|
||||
cpassword="$FakeCPassword"
|
||||
changeLogon="0"
|
||||
noChange="1"
|
||||
neverExpires="1"
|
||||
acctDisabled="0"
|
||||
userName="$DecoyDomain\$DecoyUsername" />
|
||||
</User>
|
||||
</Groups>
|
||||
"@
|
||||
|
||||
$GroupsXml | Out-File -FilePath (Join-Path $MachinePath "Groups.xml") -Encoding UTF8
|
||||
Write-DeployLog "Groups.xml planted with cpassword trap" "SUCCESS"
|
||||
|
||||
# Create corresponding trap AD account with different password
|
||||
$TrapPassword = New-SecureRandomPassword -Length 64
|
||||
$SecureTrap = ConvertTo-SecureString -String $TrapPassword -AsPlainText -Force
|
||||
|
||||
try {
|
||||
New-ADUser -Name $DecoyUsername `
|
||||
-SamAccountName $DecoyUsername `
|
||||
-Description "Maintenance account - legacy" `
|
||||
-AccountPassword $SecureTrap `
|
||||
-Enabled $true `
|
||||
-PasswordNeverExpires $true
|
||||
Write-DeployLog "Trap account created: $DecoyUsername (password differs from GPP)" "SUCCESS"
|
||||
}
|
||||
catch {
|
||||
Write-DeployLog "Trap account creation: $_" "WARN"
|
||||
}
|
||||
|
||||
# Set SACL
|
||||
if ($EnableAuditSACL) {
|
||||
$FolderAcl = Get-Acl $GPOPath
|
||||
$AuditRule = New-Object System.Security.AccessControl.FileSystemAuditRule(
|
||||
"Everyone", "ReadData", "ContainerInherit,ObjectInherit", "None", "Success"
|
||||
)
|
||||
$FolderAcl.AddAuditRule($AuditRule)
|
||||
Set-Acl $GPOPath $FolderAcl
|
||||
Write-DeployLog "SACL set on GPO folder (Event ID 4663)" "SUCCESS"
|
||||
}
|
||||
|
||||
return [PSCustomObject]@{
|
||||
GPOGuid = $GPOGuid
|
||||
GPOName = $GPOName
|
||||
GPOPath = $GPOPath
|
||||
DecoyUsername = $DecoyUsername
|
||||
DecoyDomain = $DecoyDomain
|
||||
}
|
||||
}
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
# New-DeceptiveBloodHoundPath
|
||||
# ---------------------------------------------------------------------------
|
||||
|
||||
function New-DeceptiveBloodHoundPath {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Creates fake BloodHound attack paths pointing to monitored honeytokens.
|
||||
|
||||
.DESCRIPTION
|
||||
Sets ACL permissions that create apparent attack paths visible to
|
||||
BloodHound/SharpHound reconnaissance. These paths lead attackers toward
|
||||
monitored honeytoken accounts, triggering alerts when abused.
|
||||
|
||||
.PARAMETER HoneytokenSamAccount
|
||||
The honeytoken account to create paths toward.
|
||||
|
||||
.PARAMETER TargetHighValueGroup
|
||||
The high-value group to create a deceptive path to (default: Domain Admins).
|
||||
|
||||
.PARAMETER IntermediateOU
|
||||
OU path for intermediate objects.
|
||||
#>
|
||||
[CmdletBinding()]
|
||||
param(
|
||||
[Parameter(Mandatory)]
|
||||
[string]$HoneytokenSamAccount,
|
||||
|
||||
[string]$TargetHighValueGroup = "Domain Admins",
|
||||
|
||||
[string]$IntermediateOU = "OU=Service Accounts"
|
||||
)
|
||||
|
||||
Write-DeployLog "Creating deceptive BloodHound paths for: $HoneytokenSamAccount" "INFO"
|
||||
|
||||
$UserDN = (Get-ADUser -Identity $HoneytokenSamAccount).DistinguishedName
|
||||
|
||||
# Create GenericAll edge from regular group to honeytoken
|
||||
$GroupSID = (Get-ADGroup -Identity "Remote Desktop Users").SID
|
||||
$Acl = Get-Acl "AD:\$UserDN"
|
||||
$AceRule = New-Object System.DirectoryServices.ActiveDirectoryAccessRule(
|
||||
$GroupSID,
|
||||
[System.DirectoryServices.ActiveDirectoryRights]"GenericAll",
|
||||
[System.Security.AccessControl.AccessControlType]"Allow"
|
||||
)
|
||||
$Acl.AddAccessRule($AceRule)
|
||||
Set-Acl "AD:\$UserDN" $Acl
|
||||
Write-DeployLog "GenericAll ACE: Remote Desktop Users -> $HoneytokenSamAccount" "SUCCESS"
|
||||
|
||||
# Create deceptive intermediate group
|
||||
$DeceptiveGroup = "IT-Infrastructure-Admins"
|
||||
try {
|
||||
New-ADGroup -Name $DeceptiveGroup -GroupScope DomainLocal `
|
||||
-GroupCategory Security `
|
||||
-Description "Infrastructure administration delegation"
|
||||
Write-DeployLog "Created deceptive group: $DeceptiveGroup" "SUCCESS"
|
||||
}
|
||||
catch {
|
||||
Write-DeployLog "Deceptive group may already exist" "WARN"
|
||||
}
|
||||
|
||||
Add-ADGroupMember -Identity $DeceptiveGroup -Members $HoneytokenSamAccount
|
||||
Write-DeployLog "Added honeytoken to $DeceptiveGroup" "SUCCESS"
|
||||
|
||||
# Create WriteDacl edge with deny safety net
|
||||
$DAGroupDN = (Get-ADGroup -Identity $TargetHighValueGroup).DistinguishedName
|
||||
$HoneySID = (Get-ADUser -Identity $HoneytokenSamAccount).SID
|
||||
|
||||
$DAGroupAcl = Get-Acl "AD:\$DAGroupDN"
|
||||
$DenyRule = New-Object System.DirectoryServices.ActiveDirectoryAccessRule(
|
||||
$HoneySID,
|
||||
[System.DirectoryServices.ActiveDirectoryRights]"GenericAll",
|
||||
[System.Security.AccessControl.AccessControlType]"Deny"
|
||||
)
|
||||
$WriteDaclRule = New-Object System.DirectoryServices.ActiveDirectoryAccessRule(
|
||||
$HoneySID,
|
||||
[System.DirectoryServices.ActiveDirectoryRights]"WriteDacl",
|
||||
[System.Security.AccessControl.AccessControlType]"Allow"
|
||||
)
|
||||
$DAGroupAcl.AddAccessRule($DenyRule)
|
||||
$DAGroupAcl.AddAccessRule($WriteDaclRule)
|
||||
Set-Acl "AD:\$DAGroupDN" $DAGroupAcl
|
||||
Write-DeployLog "Deceptive WriteDacl path created (with deny safety)" "SUCCESS"
|
||||
|
||||
return [PSCustomObject]@{
|
||||
HoneytokenAccount = $HoneytokenSamAccount
|
||||
PathDescription = "Remote Desktop Users -> $HoneytokenSamAccount -> $DeceptiveGroup -> $TargetHighValueGroup (blocked)"
|
||||
DeceptiveGroup = $DeceptiveGroup
|
||||
}
|
||||
}
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
# Test-HoneytokenDeployment
|
||||
# ---------------------------------------------------------------------------
|
||||
|
||||
function Test-HoneytokenDeployment {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Validates honeytoken deployment integrity.
|
||||
#>
|
||||
[CmdletBinding()]
|
||||
param(
|
||||
[Parameter(Mandatory)]
|
||||
[string]$SamAccountName,
|
||||
|
||||
[switch]$ValidateAdminCount,
|
||||
[switch]$ValidateSPN,
|
||||
[switch]$ValidateGPODecoy,
|
||||
[switch]$ValidateAuditPolicy
|
||||
)
|
||||
|
||||
$Results = @()
|
||||
|
||||
# Account existence
|
||||
$User = Get-ADUser -Identity $SamAccountName -Properties * -ErrorAction SilentlyContinue
|
||||
if ($User) {
|
||||
$Results += [PSCustomObject]@{Check="Account Exists"; Status="PASS"; Details=$User.DistinguishedName}
|
||||
$Results += [PSCustomObject]@{Check="Account Enabled"; Status=$(if($User.Enabled){"PASS"}else{"FAIL"}); Details=$(if($User.Enabled){"Enabled"}else{"Disabled"})}
|
||||
} else {
|
||||
$Results += [PSCustomObject]@{Check="Account Exists"; Status="FAIL"; Details="Not found"}
|
||||
return $Results
|
||||
}
|
||||
|
||||
if ($ValidateAdminCount) {
|
||||
$Results += [PSCustomObject]@{
|
||||
Check = "AdminCount=1"
|
||||
Status = $(if($User.AdminCount -eq 1){"PASS"}else{"WARN"})
|
||||
Details = "AdminCount=$($User.AdminCount)"
|
||||
}
|
||||
}
|
||||
|
||||
if ($ValidateSPN) {
|
||||
$SPNs = $User.ServicePrincipalNames
|
||||
$Results += [PSCustomObject]@{
|
||||
Check = "SPN Configured"
|
||||
Status = $(if($SPNs -and $SPNs.Count -gt 0){"PASS"}else{"WARN"})
|
||||
Details = $(if($SPNs){$SPNs -join ", "}else{"No SPNs"})
|
||||
}
|
||||
}
|
||||
|
||||
if ($ValidateAuditPolicy) {
|
||||
$AuditCheck = auditpol /get /subcategory:"Kerberos Service Ticket Operations" 2>$null
|
||||
$Results += [PSCustomObject]@{
|
||||
Check = "Kerberos TGS Auditing"
|
||||
Status = $(if($AuditCheck -match "Success"){"PASS"}else{"FAIL"})
|
||||
Details = $(if($AuditCheck -match "Success"){"Enabled"}else{"Run: auditpol /set /subcategory:'Kerberos Service Ticket Operations' /success:enable"})
|
||||
}
|
||||
}
|
||||
|
||||
# Password age
|
||||
$PwdAge = (Get-Date) - $User.PasswordLastSet
|
||||
$Results += [PSCustomObject]@{
|
||||
Check = "Password Age"
|
||||
Status = $(if($PwdAge.Days -gt 365){"PASS"}else{"WARN"})
|
||||
Details = "$($PwdAge.Days) days"
|
||||
}
|
||||
|
||||
return $Results
|
||||
}
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
# Deploy-FullHoneytokenSuite
|
||||
# ---------------------------------------------------------------------------
|
||||
|
||||
function Deploy-FullHoneytokenSuite {
|
||||
<#
|
||||
.SYNOPSIS
|
||||
Deploys a complete honeytoken suite in Active Directory.
|
||||
#>
|
||||
[CmdletBinding()]
|
||||
param(
|
||||
[string]$Environment = "Production",
|
||||
[Parameter(Mandatory)]
|
||||
[string]$ServiceAccountOU,
|
||||
[Parameter(Mandatory)]
|
||||
[string]$SYSVOLPath,
|
||||
[int]$TokenCount = 3,
|
||||
[bool]$IncludeSPN = $true,
|
||||
[bool]$IncludeGPODecoy = $true,
|
||||
[bool]$IncludeBloodHoundPath = $true,
|
||||
[string]$SIEMType = "Splunk"
|
||||
)
|
||||
|
||||
Write-DeployLog "Starting full honeytoken suite deployment for $Environment" "INFO"
|
||||
Write-DeployLog "Token count: $TokenCount, SPN: $IncludeSPN, GPO: $IncludeGPODecoy" "INFO"
|
||||
|
||||
$Tokens = @()
|
||||
|
||||
# Service account name templates
|
||||
$ServiceNames = @(
|
||||
@{Sam="svc_sqlbackup_legacy"; Display="SQL Backup Service (Legacy)"; SPN_Class="MSSQLSvc"; Host="sql-bak-legacy01"; Port=1433},
|
||||
@{Sam="svc_exchange_transport"; Display="Exchange Transport Agent"; SPN_Class="exchangeMDB"; Host="exch-hub-legacy02"; Port=443},
|
||||
@{Sam="svc_scom_monitor"; Display="SCOM Monitoring Service"; SPN_Class="HTTP"; Host="scom-legacy-mgmt01"; Port=5723},
|
||||
@{Sam="svc_adfs_proxy_old"; Display="ADFS Proxy Service (Old)"; SPN_Class="HTTP"; Host="adfs-proxy-legacy01"; Port=443},
|
||||
@{Sam="svc_citrix_storefront"; Display="Citrix StoreFront Service"; SPN_Class="HTTP"; Host="ctx-sf-legacy01"; Port=443}
|
||||
)
|
||||
|
||||
$Domain = (Get-ADDomain).DNSRoot
|
||||
|
||||
for ($i = 0; $i -lt [Math]::Min($TokenCount, $ServiceNames.Count); $i++) {
|
||||
$svc = $ServiceNames[$i]
|
||||
|
||||
# Create admin account
|
||||
$admin = New-HoneytokenAdmin `
|
||||
-SamAccountName $svc.Sam `
|
||||
-DisplayName $svc.Display `
|
||||
-Description "Legacy $($svc.Display.ToLower()) - DO NOT DELETE" `
|
||||
-OU $ServiceAccountOU
|
||||
|
||||
$tokenInfo = [PSCustomObject]@{
|
||||
Name = $svc.Sam
|
||||
Type = "admin_account"
|
||||
SPN = ""
|
||||
DetectionRule = "Event ID 4662 (object access)"
|
||||
}
|
||||
|
||||
# Add SPN
|
||||
if ($IncludeSPN) {
|
||||
$Hostname = "$($svc.Host).$Domain"
|
||||
$spnResult = Add-HoneytokenSPN `
|
||||
-SamAccountName $svc.Sam `
|
||||
-ServiceClass $svc.SPN_Class `
|
||||
-Hostname $Hostname `
|
||||
-Port $svc.Port
|
||||
$tokenInfo.SPN = $spnResult.SPN
|
||||
$tokenInfo.DetectionRule = "Event ID 4769 (Kerberoast)"
|
||||
}
|
||||
|
||||
$Tokens += $tokenInfo
|
||||
}
|
||||
|
||||
# Deploy GPO decoy
|
||||
if ($IncludeGPODecoy) {
|
||||
$DomainShort = ($Domain -split '\.')[0].ToUpper()
|
||||
$gpo = New-DecoyGPO `
|
||||
-GPOName "Server Maintenance Policy (Legacy)" `
|
||||
-DecoyUsername "admin_maintenance" `
|
||||
-DecoyDomain $DomainShort `
|
||||
-SYSVOLPath $SYSVOLPath
|
||||
|
||||
$Tokens += [PSCustomObject]@{
|
||||
Name = "admin_maintenance"
|
||||
Type = "gpo_credential"
|
||||
SPN = ""
|
||||
DetectionRule = "Event ID 4625 (failed logon with GPP creds)"
|
||||
}
|
||||
}
|
||||
|
||||
# Create BloodHound deception
|
||||
if ($IncludeBloodHoundPath -and $Tokens.Count -gt 0) {
|
||||
$bhPath = New-DeceptiveBloodHoundPath `
|
||||
-HoneytokenSamAccount $Tokens[0].Name
|
||||
}
|
||||
|
||||
$deployment = [PSCustomObject]@{
|
||||
Environment = $Environment
|
||||
Tokens = $Tokens
|
||||
DeployedAt = (Get-Date -Format "yyyy-MM-dd HH:mm:ss")
|
||||
Log = $Script:DeploymentLog
|
||||
}
|
||||
|
||||
Write-DeployLog "Deployment complete: $($Tokens.Count) tokens deployed" "SUCCESS"
|
||||
return $deployment
|
||||
}
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
# Export module members
|
||||
# ---------------------------------------------------------------------------
|
||||
|
||||
Export-ModuleMember -Function @(
|
||||
'New-HoneytokenAdmin',
|
||||
'Add-HoneytokenSPN',
|
||||
'New-DecoyGPO',
|
||||
'New-DeceptiveBloodHoundPath',
|
||||
'Test-HoneytokenDeployment',
|
||||
'Deploy-FullHoneytokenSuite'
|
||||
)
|
||||
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user