Add 30 new production-grade cybersecurity skills: AI security, supply chain, firmware, cloud-native, compliance, deception, crypto, threat hunting, purple team, OT, privacy

This commit is contained in:
mukul975
2026-03-19 19:14:25 +01:00
parent d43cc7a766
commit d833f0eab9
125 changed files with 47874 additions and 334 deletions
@@ -0,0 +1,201 @@
Apache License
Version 2.0, January 2004
http://www.apache.org/licenses/
TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
1. Definitions.
"License" shall mean the terms and conditions for use, reproduction,
and distribution as defined by Sections 1 through 9 of this document.
"Licensor" shall mean the copyright owner or entity authorized by
the copyright owner that is granting the License.
"Legal Entity" shall mean the union of the acting entity and all
other entities that control, are controlled by, or are under common
control with that entity. For the purposes of this definition,
"control" means (i) the power, direct or indirect, to cause the
direction or management of such entity, whether by contract or
otherwise, or (ii) ownership of fifty percent (50%) or more of the
outstanding shares, or (iii) beneficial ownership of such entity.
"You" (or "Your") shall mean an individual or Legal Entity
exercising permissions granted by this License.
"Source" form shall mean the preferred form for making modifications,
including but not limited to software source code, documentation
source, and configuration files.
"Object" form shall mean any form resulting from mechanical
transformation or translation of a Source form, including but
not limited to compiled object code, generated documentation,
and conversions to other media types.
"Work" shall mean the work of authorship, whether in Source or
Object form, made available under the License, as indicated by a
copyright notice that is included in or attached to the work
(an example is provided in the Appendix below).
"Derivative Works" shall mean any work, whether in Source or Object
form, that is based on (or derived from) the Work and for which the
editorial revisions, annotations, elaborations, or other modifications
represent, as a whole, an original work of authorship. For the purposes
of this License, Derivative Works shall not include works that remain
separable from, or merely link (or bind by name) to the interfaces of,
the Work and Derivative Works thereof.
"Contribution" shall mean any work of authorship, including
the original version of the Work and any modifications or additions
to that Work or Derivative Works thereof, that is intentionally
submitted to the Licensor for inclusion in the Work by the copyright owner
or by an individual or Legal Entity authorized to submit on behalf of
the copyright owner. For the purposes of this definition, "submitted"
means any form of electronic, verbal, or written communication sent
to the Licensor or its representatives, including but not limited to
communication on electronic mailing lists, source code control systems,
and issue tracking systems that are managed by, or on behalf of, the
Licensor for the purpose of discussing and improving the Work, but
excluding communication that is conspicuously marked or otherwise
designated in writing by the copyright owner as "Not a Contribution."
"Contributor" shall mean Licensor and any individual or Legal Entity
on behalf of whom a Contribution has been received by the Licensor and
subsequently incorporated within the Work.
2. Grant of Copyright License. Subject to the terms and conditions of
this License, each Contributor hereby grants to You a perpetual,
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
copyright license to reproduce, prepare Derivative Works of,
publicly display, publicly perform, sublicense, and distribute the
Work and such Derivative Works in Source or Object form.
3. Grant of Patent License. Subject to the terms and conditions of
this License, each Contributor hereby grants to You a perpetual,
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
(except as stated in this section) patent license to make, have made,
use, offer to sell, sell, import, and otherwise transfer the Work,
where such license applies only to those patent claims licensable
by such Contributor that are necessarily infringed by their
Contribution(s) alone or by combination of their Contribution(s)
with the Work to which such Contribution(s) was submitted. If You
institute patent litigation against any entity (including a
cross-claim or counterclaim in a lawsuit) alleging that the Work
or a Contribution incorporated within the Work constitutes direct
or contributory patent infringement, then any patent licenses
granted to You under this License for that Work shall terminate
as of the date such litigation is filed.
4. Redistribution. You may reproduce and distribute copies of the
Work or Derivative Works thereof in any medium, with or without
modifications, and in Source or Object form, provided that You
meet the following conditions:
(a) You must give any other recipients of the Work or
Derivative Works a copy of this License; and
(b) You must cause any modified files to carry prominent notices
stating that You changed the files; and
(c) You must retain, in the Source form of any Derivative Works
that You distribute, all copyright, patent, trademark, and
attribution notices from the Source form of the Work,
excluding those notices that do not pertain to any part of
the Derivative Works; and
(d) If the Work includes a "NOTICE" text file as part of its
distribution, then any Derivative Works that You distribute must
include a readable copy of the attribution notices contained
within such NOTICE file, excluding any notices that do not
pertain to any part of the Derivative Works, in at least one
of the following places: within a NOTICE text file distributed
as part of the Derivative Works; within the Source form or
documentation, if provided along with the Derivative Works; or,
within a display generated by the Derivative Works, if and
wherever such third-party notices normally appear. The contents
of the NOTICE file are for informational purposes only and
do not modify the License. You may add Your own attribution
notices within Derivative Works that You distribute, alongside
or as an addendum to the NOTICE text from the Work, provided
that such additional attribution notices cannot be construed
as modifying the License.
You may add Your own copyright statement to Your modifications and
may provide additional or different license terms and conditions
for use, reproduction, or distribution of Your modifications, or
for any such Derivative Works as a whole, provided Your use,
reproduction, and distribution of the Work otherwise complies with
the conditions stated in this License.
5. Submission of Contributions. Unless You explicitly state otherwise,
any Contribution intentionally submitted for inclusion in the Work
by You to the Licensor shall be under the terms and conditions of
this License, without any additional terms or conditions.
Notwithstanding the above, nothing herein shall supersede or modify
the terms of any separate license agreement you may have executed
with Licensor regarding such Contributions.
6. Trademarks. This License does not grant permission to use the trade
names, trademarks, service marks, or product names of the Licensor,
except as required for reasonable and customary use in describing the
origin of the Work and reproducing the content of the NOTICE file.
7. Disclaimer of Warranty. Unless required by applicable law or
agreed to in writing, Licensor provides the Work (and each
Contributor provides its Contributions) on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
implied, including, without limitation, any warranties or conditions
of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
PARTICULAR PURPOSE. You are solely responsible for determining the
appropriateness of using or redistributing the Work and assume any
risks associated with Your exercise of permissions under this License.
8. Limitation of Liability. In no event and under no legal theory,
whether in tort (including negligence), contract, or otherwise,
unless required by applicable law (such as deliberate and grossly
negligent acts) or agreed to in writing, shall any Contributor be
liable to You for damages, including any direct, indirect, special,
incidental, or consequential damages of any character arising as a
result of this License or out of the use or inability to use the
Work (including but not limited to damages for loss of goodwill,
work stoppage, computer failure or malfunction, or any and all
other commercial damages or losses), even if such Contributor
has been advised of the possibility of such damages.
9. Accepting Warranty or Additional Liability. While redistributing
the Work or Derivative Works thereof, You may choose to offer,
and charge a fee for, acceptance of support, warranty, indemnity,
or other liability obligations and/or rights consistent with this
License. However, in accepting such obligations, You may act only
on Your own behalf and on Your sole responsibility, not on behalf
of any other Contributor, and only if You agree to indemnify,
defend, and hold each Contributor harmless for any liability
incurred by, or claims asserted against, such Contributor by reason
of your accepting any such warranty or additional liability.
END OF TERMS AND CONDITIONS
APPENDIX: How to apply the Apache License to your work.
To apply the Apache License to your work, attach the following
boilerplate notice, with the fields enclosed by brackets "[]"
replaced with your own identifying information. (Don't include
the brackets!) The text should be enclosed in the appropriate
comment syntax for the file format. Please do not remove or change
the license header comment from a contributed file except when
necessary.
Copyright 2026 mukul975
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
@@ -0,0 +1,242 @@
---
name: deploying-active-directory-honeytokens
description: >
Deploys deception-based honeytokens in Active Directory including fake privileged accounts
with AdminCount=1, fake SPNs for Kerberoasting detection (honeyroasting), decoy GPOs with
cpassword traps, and fake BloodHound paths. Monitors Windows Security Event IDs 4769, 4625,
4662, 5136 for honeytoken interaction. Use when implementing AD deception defenses for
detecting lateral movement, credential theft, and reconnaissance.
domain: cybersecurity
subdomain: deception-technology
tags: [active-directory, honeytokens, kerberoasting, deception, detection, bloodhound, gpo]
version: "1.0"
author: mukul975
license: Apache-2.0
---
# Deploying Active Directory Honeytokens
## When to Use
- When deploying deception-based detection in Active Directory environments
- When detecting Kerberoasting attacks via fake SPN honeytokens (honeyroasting)
- When creating tripwire accounts to detect credential theft and lateral movement
- When building decoy GPOs to detect Group Policy Preference password harvesting
- When creating deceptive BloodHound paths to misdirect and detect attackers
- When supplementing existing AD monitoring with high-fidelity detection signals
## Prerequisites
- Domain Admin or delegated AD administration privileges
- Active Directory domain (Windows Server 2016+ recommended)
- Windows Event Log forwarding to SIEM (Splunk, Sentinel, Elastic)
- PowerShell 5.1+ with ActiveDirectory module
- Group Policy Management Console (GPMC)
- Understanding of AD security, Kerberos, and BloodHound attack paths
## Background
### Why AD Honeytokens
Traditional signature-based detection misses novel attack techniques. Honeytokens
provide high-fidelity detection with near-zero false positives because any interaction
with a decoy object is inherently suspicious. In Active Directory:
- **Fake privileged accounts** detect credential dumping (DCSync, NTDS.dit extraction)
- **Fake SPNs** detect Kerberoasting reconnaissance (TGS requests for nonexistent services)
- **Decoy GPOs** detect Group Policy Preference password harvesting
- **Fake BloodHound paths** mislead attackers using graph-based AD analysis
### Key Detection Event IDs
| Event ID | Description | Honeytoken Use |
|----------|-------------|----------------|
| 4769 | Kerberos TGS ticket requested | Detect Kerberoast against honey SPN |
| 4625 | Failed logon attempt | Detect use of fake credentials from decoy GPO |
| 4662 | Directory service object accessed | Detect DACL read on honeytoken user |
| 5136 | Directory service object modified | Detect modification of decoy GPO |
| 5137 | Directory service object created | Detect GPO creation mimicking decoy |
| 4768 | Kerberos TGT requested | Detect AS-REP roasting of honey account |
### Making Honeytokens Realistic
Per Trimarc Security research, effective honeytokens must appear legitimate:
- **Age the account**: Repurpose old inactive accounts (10-15 year old accounts in
similarly aged domains appear authentic)
- **Set AdminCount=1**: Flags the account as having elevated AD rights, making it
an attractive Kerberoasting target
- **Use realistic naming**: Match organizational naming conventions (svc_sqlbackup,
admin.maintenance, svc_exchange_legacy)
- **Set old password date**: Password age of 10+ years with an SPN looks like a
high-value, neglected service account to attackers
- **Add group memberships**: Place in visible groups like "Remote Desktop Users" or
a custom "Backup Operators" to increase attacker interest
- **Avoid detection tells**: Attackers check creation date vs. last logon vs.
password change date for consistency
## Instructions
### Step 1: Deploy Fake Privileged Admin Account
Create a honeytoken account that mimics a legacy privileged service account.
```powershell
# Import the deployment module
Import-Module .\scripts\Deploy-ADHoneytokens.ps1
# Create a honeytoken admin account
$honeyAdmin = New-HoneytokenAdmin `
-SamAccountName "svc_sqlbackup_legacy" `
-DisplayName "SQL Backup Service (Legacy)" `
-Description "Legacy SQL Server backup service account - DO NOT DELETE" `
-OU "OU=Service Accounts,DC=corp,DC=example,DC=com" `
-PasswordLength 128 `
-SetAdminCount $true
Write-Host "Honeytoken admin created: $($honeyAdmin.DistinguishedName)"
```
### Step 2: Deploy Fake SPN for Kerberoasting Detection
Assign a realistic but fake SPN to the honeytoken account. Any TGS request
for this SPN is definitively malicious (honeyroasting).
```powershell
# Add fake SPN to honeytoken account
$honeySPN = Add-HoneytokenSPN `
-SamAccountName "svc_sqlbackup_legacy" `
-ServiceClass "MSSQLSvc" `
-Hostname "sql-legacy-bak01.corp.example.com" `
-Port 1433
Write-Host "Honey SPN registered: $($honeySPN.SPN)"
Write-Host "Monitor Event ID 4769 for TGS requests targeting this SPN"
```
### Step 3: Deploy Decoy GPO with Credential Trap
Create a fake GPO in SYSVOL with an embedded cpassword (Group Policy Preference
password). Attackers using tools like Get-GPPPassword or gpp-decrypt will find
and attempt to use these credentials, triggering detection.
```powershell
# Create decoy GPO with cpassword trap
$decoyGPO = New-DecoyGPO `
-GPOName "Server Maintenance Policy (Legacy)" `
-DecoyUsername "admin_maintenance" `
-DecoyDomain "CORP" `
-SYSVOLPath "\\corp.example.com\SYSVOL\corp.example.com\Policies" `
-EnableAuditSACL $true
Write-Host "Decoy GPO created: $($decoyGPO.GPOGuid)"
Write-Host "SACL audit enabled - any read attempt will generate Event ID 4663"
```
### Step 4: Create Deceptive BloodHound Paths
Set ACL permissions that create fake attack paths visible to BloodHound/SharpHound
reconnaissance, leading attackers toward monitored honeytokens.
```powershell
# Create fake BloodHound attack path
$deceptivePath = New-DeceptiveBloodHoundPath `
-HoneytokenSamAccount "svc_sqlbackup_legacy" `
-TargetHighValueGroup "Domain Admins" `
-IntermediateOU "OU=Service Accounts,DC=corp,DC=example,DC=com"
Write-Host "Deceptive path created: $($deceptivePath.PathDescription)"
```
### Step 5: Configure Detection Rules
Set up SIEM detection rules to alert on any honeytoken interaction.
```python
# Using the Python detection agent
from agent import ADHoneytokenMonitor
monitor = ADHoneytokenMonitor(config_path="honeytoken_config.json")
# Register all honeytokens for monitoring
monitor.register_honeytoken("svc_sqlbackup_legacy", token_type="admin_account")
monitor.register_honeytoken("MSSQLSvc/sql-legacy-bak01.corp.example.com:1433", token_type="spn")
monitor.register_honeytoken("admin_maintenance", token_type="gpo_credential")
# Generate SIEM detection rules
splunk_rules = monitor.generate_detection_rules(siem="splunk")
sentinel_rules = monitor.generate_detection_rules(siem="sentinel")
sigma_rules = monitor.generate_detection_rules(siem="sigma")
for rule in sigma_rules:
print(f"Rule: {rule['title']}")
print(f" Detection: {rule['detection_logic']}")
```
### Step 6: Validate Deployment
Test the honeytokens to ensure detection fires correctly.
```powershell
# Validate honeytoken deployment
$validation = Test-HoneytokenDeployment `
-SamAccountName "svc_sqlbackup_legacy" `
-ValidateAdminCount `
-ValidateSPN `
-ValidateGPODecoy `
-ValidateAuditPolicy
$validation | Format-Table Check, Status, Details -AutoSize
```
## Examples
### Full Deployment Pipeline
```powershell
Import-Module .\scripts\Deploy-ADHoneytokens.ps1
# Deploy complete honeytoken suite
$deployment = Deploy-FullHoneytokenSuite `
-Environment "Production" `
-ServiceAccountOU "OU=Service Accounts,DC=corp,DC=example,DC=com" `
-SYSVOLPath "\\corp.example.com\SYSVOL\corp.example.com\Policies" `
-TokenCount 3 `
-IncludeSPN $true `
-IncludeGPODecoy $true `
-IncludeBloodHoundPath $true `
-SIEMType "Splunk"
# Output deployment report
$deployment.Tokens | Format-Table Name, Type, SPN, DetectionRule -AutoSize
$deployment | Export-Csv "honeytoken_deployment_report.csv" -NoTypeInformation
```
### Kerberoasting Detection Query (Splunk)
```spl
index=wineventlog EventCode=4769 ServiceName="svc_sqlbackup_legacy"
| eval alert_severity="critical"
| eval alert_type="honeytoken_kerberoast"
| table _time, src_ip, Account_Name, ServiceName, Ticket_Encryption_Type
| sort - _time
```
### Microsoft Sentinel KQL Detection
```kql
SecurityEvent
| where EventID == 4769
| where ServiceName in ("svc_sqlbackup_legacy", "svc_exchange_legacy")
| extend AlertType = "Honeytoken Kerberoast Detected"
| project TimeGenerated, Computer, Account, ServiceName, IpAddress, TicketEncryptionType
```
## References
- Trimarc Security - The Art of the Honeypot Account: https://www.hub.trimarcsecurity.com/post/the-art-of-the-honeypot-account-making-the-unusual-look-normal
- ADSecurity.org - Detecting Kerberoasting Activity Part 2 (Honeypot): https://adsecurity.org/?p=3513
- Microsoft Defender for Identity Honeytokens: https://techcommunity.microsoft.com/blog/microsoftthreatprotectionblog/deceptive-defense-best-practices-for-identity-based-honeytokens-in-microsoft-def/3851641
- SpecterOps - Kerberoasting and AES-256: https://specterops.io/blog/2025/10/21/is-kerberoasting-still-a-risk-when-aes-256-kerberos-encryption-is-enabled/
- APT29a Blog - Deploying Honeytokens in AD: https://apt29a.blogspot.com/2019/11/deploying-honeytokens-in-active.html
- ADSecurity.org - Detecting Kerberoasting Activity: https://adsecurity.org/?p=3458
@@ -0,0 +1,326 @@
# API Reference: Active Directory Honeytoken Deployment
## PowerShellGenerator
Generates PowerShell scripts for AD honeytoken deployment operations.
### Methods
#### `generate_create_honeytoken_account(...)`
Generate PowerShell to create a honeytoken AD account with AdminCount=1, backdated password, group memberships, and SACL audit rules.
| Parameter | Type | Default | Description |
|-----------|------|---------|-------------|
| `sam_account_name` | `str` | required | sAMAccountName for the honeytoken |
| `display_name` | `str` | required | Display name |
| `description` | `str` | required | Description field |
| `ou_dn` | `str` | required | Distinguished Name of target OU |
| `password_length` | `int` | `128` | Random password length |
| `set_admin_count` | `bool` | `True` | Set AdminCount=1 |
| `account_age_days` | `int` | `5475` | Days to backdate password (~15 years) |
**Returns:** `str` -- Complete PowerShell script.
**AD Operations Performed:**
- Creates AD user account with strong random password
- Sets AdminCount=1 (appears as privileged account to BloodHound)
- Backdates pwdLastSet to simulate aged service account
- Adds to Remote Desktop Users group
- Configures SACL audit rule (Everyone/ReadProperty/Success)
**Detection:** Event ID 4662 (directory service object accessed)
#### `generate_add_honey_spn(...)`
Generate PowerShell to add a fake SPN for Kerberoasting detection (honeyroasting).
| Parameter | Type | Default | Description |
|-----------|------|---------|-------------|
| `sam_account_name` | `str` | required | Account to add SPN to |
| `service_class` | `str` | `"MSSQLSvc"` | SPN service class |
| `hostname` | `str` | required | Fake hostname |
| `port` | `int` | `1433` | Service port |
**Returns:** `str` -- PowerShell script that registers the SPN and enables RC4+AES encryption.
**Detection:** Event ID 4769 (Kerberos TGS ticket requested) where ServiceName matches the honeytoken account. Any TGS request for this SPN is definitively malicious.
#### `generate_decoy_gpo(...)`
Generate PowerShell to create a decoy GPO with cpassword credential trap in SYSVOL.
| Parameter | Type | Default | Description |
|-----------|------|---------|-------------|
| `gpo_name` | `str` | required | GPO display name |
| `decoy_username` | `str` | required | Username in cpassword trap |
| `decoy_domain` | `str` | required | Short domain name (e.g., CORP) |
| `sysvol_path` | `str` | required | SYSVOL Policies path |
| `enable_sacl` | `bool` | `True` | Set SACL audit on GPO folder |
**Returns:** `str` -- PowerShell script that creates GPO folder structure, plants Groups.xml with cpassword, creates trap AD account with different password, and sets SACL.
**Detection Chain:**
1. Event ID 4663 (SYSVOL folder read)
2. Offline: Attacker decrypts cpassword
3. Event ID 4625 (failed logon with decoy credentials)
4. Correlation: 4663 + 4625 from same source IP = confirmed attacker
#### `generate_deceptive_bloodhound_path(...)`
Generate PowerShell to create fake BloodHound attack paths leading to monitored honeytokens.
| Parameter | Type | Default | Description |
|-----------|------|---------|-------------|
| `honeytoken_sam` | `str` | required | Honeytoken account name |
| `target_group` | `str` | `"Domain Admins"` | High-value group for deceptive path |
| `intermediate_ou` | `str` | `"OU=Service Accounts"` | OU for intermediate objects |
**Returns:** `str` -- PowerShell script that creates GenericAll ACE, deceptive intermediate group, and WriteDacl edge with deny safety net.
**BloodHound Path Created:**
```
Remote Desktop Users -[GenericAll]-> honeytoken_account
honeytoken_account -[MemberOf]-> IT-Infrastructure-Admins
honeytoken_account -[WriteDacl]-> Domain Admins (blocked by deny ACE)
```
#### `generate_validation_script(sam_account_name)`
Generate PowerShell to validate honeytoken deployment integrity.
**Checks Performed:**
| Check | Pass Criteria |
|-------|---------------|
| Account Exists | Account found in AD |
| Account Enabled | Enabled = True |
| AdminCount=1 | AdminCount attribute is 1 |
| SPN Configured | At least one SPN registered |
| Password Age | > 365 days |
| SACL Audit | At least one audit rule configured |
| Group Memberships | Lists all group memberships |
| RC4 Supported | msDS-SupportedEncryptionTypes includes 0x4 |
| Kerberos Audit | auditpol shows Kerberos TGS auditing enabled |
---
## SIEMRuleGenerator
Generates detection rules for SIEM platforms targeting honeytoken activity.
### Methods
#### `generate_detection_rules(honeytoken_accounts, honey_spns, gpo_trap_accounts, siem="sigma")`
| Parameter | Type | Description |
|-----------|------|-------------|
| `honeytoken_accounts` | `list[str]` | Account names to monitor |
| `honey_spns` | `list[str]` | SPN values to monitor |
| `gpo_trap_accounts` | `list[str]` | GPO credential trap usernames |
| `siem` | `str` | Target platform: `sigma`, `splunk`, or `sentinel` |
**Returns:** `list[dict]` -- Each rule contains `title`, `detection_logic`, and `rule` (full query text).
### Generated Rules by Platform
**Sigma Rules:**
| Rule | Event ID | MITRE Technique |
|------|----------|-----------------|
| Honeytoken Kerberoast Detected | 4769 | T1558.003 |
| Honeytoken GPO Credential Use Detected | 4624, 4625 | T1552.006 |
| Honeytoken AD Object Accessed | 4662 | T1087.002 |
**Splunk SPL Rules:**
| Rule | Description |
|------|-------------|
| Honeytoken Kerberoast Detection | Index wineventlog EventCode=4769 with ServiceName filter |
| Honeytoken GPO Credential Use | EventCode 4624/4625 with TargetUserName filter |
| Attack Chain Correlation | SYSVOL enum (4663) -> credential use (4625) by same source IP |
**Microsoft Sentinel KQL Rules:**
| Rule | Description |
|------|-------------|
| Honeytoken Kerberoast Detection | SecurityEvent EventID 4769 with ServiceName filter |
| Honeytoken GPO Credential Use | SecurityEvent EventID 4624/4625 with TargetUserName filter |
#### `export_rules(output_dir, format="json")`
Export all generated rules to files on disk.
**Returns:** `list[str]` of saved file paths.
---
## ADHoneytokenMonitor
Monitors Windows Event Logs for honeytoken interactions and generates alerts.
### Constructor
```python
ADHoneytokenMonitor(config_path=None)
```
### Methods
#### `register_honeytoken(identifier, token_type="admin_account", metadata=None)`
Register a honeytoken for monitoring.
| Token Type | Description |
|------------|-------------|
| `admin_account` | Fake privileged AD account |
| `spn` | Fake Service Principal Name |
| `gpo_credential` | Decoy GPO cpassword trap account |
#### `analyze_event_log(events)`
Analyze Windows Event Log entries for honeytoken interactions.
| Event ID | Alert Type | Severity |
|----------|------------|----------|
| 4769 | `KERBEROAST_HONEYTOKEN` | critical |
| 4624 | `HONEYTOKEN_LOGON` | critical |
| 4625 | `HONEYTOKEN_LOGON_FAILED` | critical |
| 4662 | `HONEYTOKEN_DACL_READ` | high |
| 5136 | `HONEYTOKEN_GPO_MODIFIED` | critical |
**Returns:** `list[dict]` -- Alerts with `alert_id`, `alert_type`, `severity`, `description`, `mitre_technique`, `source_ip`, `source_host`.
#### `generate_detection_rules(siem="sigma")`
Generate SIEM detection rules for all registered honeytokens.
#### `get_alert_summary()`
Get aggregated summary of all alerts by severity, type, and source IP.
---
## HoneytokenDeployer
Orchestrates full honeytoken deployment and generates all artifacts.
### Constructor
```python
HoneytokenDeployer(domain="corp.example.com",
service_account_ou="OU=Service Accounts",
sysvol_path="")
```
### Methods
#### `generate_realistic_name()`
Generate a realistic service account name using templates matching common organizational patterns.
**Returns:** `dict` with `sam_account_name`, `display_name`, `hostname`.
#### `deploy_full_suite(...)`
Generate complete deployment artifacts for a full honeytoken suite.
| Parameter | Type | Default | Description |
|-----------|------|---------|-------------|
| `token_count` | `int` | `3` | Number of honeytoken accounts |
| `include_spn` | `bool` | `True` | Add fake SPNs |
| `include_gpo` | `bool` | `True` | Create decoy GPO |
| `include_bloodhound` | `bool` | `True` | Create deceptive BloodHound paths |
| `siem_type` | `str` | `"sigma"` | Target SIEM for detection rules |
**Returns:** `dict` with `deployment_id`, `tokens`, `scripts`, `detection_rules`.
#### `save_deployment(deployment, output_dir)`
Save all deployment artifacts (PowerShell scripts, detection rules, manifest) to disk.
**Returns:** `list[str]` of saved file paths.
---
## PowerShell Module: Deploy-ADHoneytokens.ps1
### Exported Functions
| Function | Description |
|----------|-------------|
| `New-HoneytokenAdmin` | Create honeytoken AD account with AdminCount=1, SACL, backdated password |
| `Add-HoneytokenSPN` | Register fake SPN for Kerberoasting detection |
| `New-DecoyGPO` | Create decoy GPO with cpassword trap in SYSVOL |
| `New-DeceptiveBloodHoundPath` | Create fake BloodHound attack paths |
| `Test-HoneytokenDeployment` | Validate honeytoken deployment integrity |
| `Deploy-FullHoneytokenSuite` | Deploy complete honeytoken suite |
### Prerequisites
```powershell
#Requires -Modules ActiveDirectory
#Requires -Version 5.1
```
---
## Windows Event IDs for Honeytoken Detection
| Event ID | Description | Honeytoken Use |
|----------|-------------|----------------|
| 4769 | Kerberos TGS ticket requested | Kerberoast against honey SPN |
| 4768 | Kerberos TGT requested | AS-REP roasting of honey account |
| 4625 | Failed logon attempt | Credential use from decoy GPO |
| 4624 | Successful logon | Honeytoken account compromise |
| 4662 | Directory service object accessed | DACL read on honeytoken user |
| 4648 | Logon with explicit credentials | Pass-the-hash detection |
| 5136 | Directory service object modified | GPO modification |
| 5137 | Directory service object created | GPO creation |
| 4663 | Attempt to access object | SYSVOL decoy file read |
---
## CLI Usage
```bash
# Full deployment (generates all scripts, rules, and manifest)
python agent.py --action full_deploy \
--domain corp.example.com \
--ou "OU=Service Accounts" \
--token-count 3 \
--siem sigma \
--output-dir honeytoken_deployment
# Generate detection rules only
python agent.py --action generate_rules \
--account-name svc_sqlbackup_legacy \
--siem splunk
# Generate single account creation script
python agent.py --action deploy_account \
--account-name svc_sqlbackup_legacy \
--domain corp.example.com
# Generate SPN addition script
python agent.py --action deploy_spn \
--account-name svc_sqlbackup_legacy
# Generate decoy GPO script
python agent.py --action deploy_gpo \
--domain corp.example.com
# Generate BloodHound deception script
python agent.py --action deploy_bloodhound \
--account-name svc_sqlbackup_legacy
# Validate deployment
python agent.py --action validate \
--account-name svc_sqlbackup_legacy
# Analyze event logs for honeytoken alerts
python agent.py --action analyze_logs \
--account-name svc_sqlbackup_legacy \
--event-log events.json
```
### CLI Arguments
| Argument | Default | Description |
|----------|---------|-------------|
| `--action` | `full_deploy` | Action to perform |
| `--domain` | `corp.example.com` | AD domain FQDN |
| `--ou` | `OU=Service Accounts` | OU for honeytoken accounts |
| `--sysvol` | auto | SYSVOL Policies path |
| `--account-name` | `svc_sqlbackup_legacy` | Honeytoken account name |
| `--token-count` | `3` | Number of honeytokens to deploy |
| `--siem` | `sigma` | Target SIEM: `sigma`, `splunk`, `sentinel` |
| `--output-dir` | `honeytoken_deployment` | Output directory |
| `--include-spn` | `True` | Include fake SPNs |
| `--include-gpo` | `True` | Include decoy GPO |
| `--include-bloodhound` | `True` | Include BloodHound deception |
| `--event-log` | `None` | Path to event log JSON for analysis |
@@ -0,0 +1,659 @@
<#
.SYNOPSIS
Active Directory Honeytoken Deployment Module
.DESCRIPTION
Deploys deception-based honeytokens in Active Directory including:
- Fake privileged accounts with AdminCount=1
- Fake SPNs for Kerberoasting detection (honeyroasting)
- Decoy GPOs with cpassword traps
- Deceptive BloodHound attack paths
- SACL audit rules for detection
.NOTES
Author: mukul975
Version: 1.0
References:
- Trimarc Security: The Art of the Honeypot Account
- ADSecurity.org: Detecting Kerberoasting Activity Part 2
- Microsoft Defender for Identity Honeytokens
- SpecterOps: Kerberoasting and AES-256
#>
#Requires -Modules ActiveDirectory
#Requires -Version 5.1
Set-StrictMode -Version Latest
$ErrorActionPreference = "Stop"
# ---------------------------------------------------------------------------
# Module-level variables
# ---------------------------------------------------------------------------
$Script:DeployedTokens = @()
$Script:DeploymentLog = @()
# ---------------------------------------------------------------------------
# Helper Functions
# ---------------------------------------------------------------------------
function Write-DeployLog {
param(
[string]$Message,
[ValidateSet("INFO", "WARN", "ERROR", "SUCCESS")]
[string]$Level = "INFO"
)
$entry = [PSCustomObject]@{
Timestamp = (Get-Date -Format "yyyy-MM-dd HH:mm:ss")
Level = $Level
Message = $Message
}
$Script:DeploymentLog += $entry
$color = switch ($Level) {
"INFO" { "White" }
"WARN" { "Yellow" }
"ERROR" { "Red" }
"SUCCESS" { "Green" }
}
Write-Host "[$Level] $Message" -ForegroundColor $color
}
function New-SecureRandomPassword {
param([int]$Length = 128)
$chars = 'abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789!@#$%^&*()-_=+[]{}|;:,.<>?'
$password = -join (1..$Length | ForEach-Object { $chars[(Get-Random -Maximum $chars.Length)] })
return $password
}
# ---------------------------------------------------------------------------
# New-HoneytokenAdmin
# ---------------------------------------------------------------------------
function New-HoneytokenAdmin {
<#
.SYNOPSIS
Creates a honeytoken admin account in Active Directory.
.DESCRIPTION
Creates a realistic-looking service account with AdminCount=1 set,
backdated password age, group memberships, and SACL audit rules.
The account appears as a high-value target to attackers using
BloodHound, SharpHound, or manual AD enumeration.
.PARAMETER SamAccountName
The sAMAccountName for the honeytoken account.
.PARAMETER DisplayName
The display name for the account.
.PARAMETER Description
The description field (should look legitimate).
.PARAMETER OU
The Distinguished Name of the OU to create the account in.
.PARAMETER PasswordLength
Length of the random password (default: 128).
.PARAMETER SetAdminCount
If true, sets AdminCount=1 on the account (default: true).
.PARAMETER AccountAgeDays
Number of days to backdate the password (default: 5475 = ~15 years).
.EXAMPLE
New-HoneytokenAdmin -SamAccountName "svc_sqlbackup_legacy" `
-DisplayName "SQL Backup Service (Legacy)" `
-Description "Legacy SQL Server backup service account - DO NOT DELETE" `
-OU "OU=Service Accounts,DC=corp,DC=example,DC=com"
#>
[CmdletBinding()]
param(
[Parameter(Mandatory)]
[string]$SamAccountName,
[Parameter(Mandatory)]
[string]$DisplayName,
[string]$Description = "Legacy service account - DO NOT DELETE",
[Parameter(Mandatory)]
[string]$OU,
[int]$PasswordLength = 128,
[bool]$SetAdminCount = $true,
[int]$AccountAgeDays = 5475
)
Write-DeployLog "Creating honeytoken admin: $SamAccountName" "INFO"
# Generate strong random password
$Password = New-SecureRandomPassword -Length $PasswordLength
$SecurePassword = ConvertTo-SecureString -String $Password -AsPlainText -Force
# Create the account
$Domain = Get-ADDomain
$UPN = "$SamAccountName@$($Domain.DNSRoot)"
$UserParams = @{
Name = $DisplayName
SamAccountName = $SamAccountName
UserPrincipalName = $UPN
DisplayName = $DisplayName
Description = $Description
Path = $OU
AccountPassword = $SecurePassword
Enabled = $true
PasswordNeverExpires = $true
CannotChangePassword = $true
ChangePasswordAtLogon = $false
}
try {
New-ADUser @UserParams
Write-DeployLog "Account created: $SamAccountName" "SUCCESS"
}
catch {
Write-DeployLog "Failed to create account: $_" "ERROR"
throw
}
# Set AdminCount=1
if ($SetAdminCount) {
Set-ADUser -Identity $SamAccountName -Replace @{AdminCount = 1}
Write-DeployLog "AdminCount set to 1" "SUCCESS"
}
# Backdate password
$AgeDate = (Get-Date).AddDays(-$AccountAgeDays)
$FileTime = $AgeDate.ToFileTime()
Set-ADUser -Identity $SamAccountName -Replace @{pwdLastSet = $FileTime}
Write-DeployLog "Password backdated to: $($AgeDate.ToString('yyyy-MM-dd'))" "SUCCESS"
# Add to visible groups
Add-ADGroupMember -Identity "Remote Desktop Users" -Members $SamAccountName
Write-DeployLog "Added to Remote Desktop Users" "SUCCESS"
# Set SACL for audit
$UserDN = (Get-ADUser -Identity $SamAccountName).DistinguishedName
$Acl = Get-Acl "AD:\$UserDN"
$AuditRule = New-Object System.DirectoryServices.ActiveDirectoryAuditRule(
[System.Security.Principal.SecurityIdentifier]"S-1-1-0",
[System.DirectoryServices.ActiveDirectoryRights]"ReadProperty",
[System.Security.AccessControl.AuditFlags]"Success",
[System.DirectoryServices.ActiveDirectorySecurityInheritance]"None"
)
$Acl.AddAuditRule($AuditRule)
Set-Acl "AD:\$UserDN" $Acl
Write-DeployLog "SACL audit rule configured (Event ID 4662)" "SUCCESS"
$result = Get-ADUser -Identity $SamAccountName -Properties *
$Script:DeployedTokens += $result
return $result
}
# ---------------------------------------------------------------------------
# Add-HoneytokenSPN
# ---------------------------------------------------------------------------
function Add-HoneytokenSPN {
<#
.SYNOPSIS
Adds a fake SPN to a honeytoken account for Kerberoasting detection.
.DESCRIPTION
Registers a fake Service Principal Name on a honeytoken account.
Any TGS ticket request for this SPN is definitively malicious since
the associated service does not exist. This is known as "honeyroasting".
.PARAMETER SamAccountName
The honeytoken account to add the SPN to.
.PARAMETER ServiceClass
The SPN service class (default: MSSQLSvc).
.PARAMETER Hostname
The fake hostname for the SPN.
.PARAMETER Port
The service port (default: 1433).
#>
[CmdletBinding()]
param(
[Parameter(Mandatory)]
[string]$SamAccountName,
[string]$ServiceClass = "MSSQLSvc",
[Parameter(Mandatory)]
[string]$Hostname,
[int]$Port = 1433
)
$SPN = "$ServiceClass/${Hostname}:$Port"
Write-DeployLog "Adding honey SPN: $SPN to $SamAccountName" "INFO"
# Verify account exists
$User = Get-ADUser -Identity $SamAccountName -Properties ServicePrincipalNames -ErrorAction Stop
# Add SPN
Set-ADUser -Identity $SamAccountName -ServicePrincipalNames @{Add = $SPN}
Write-DeployLog "SPN registered: $SPN" "SUCCESS"
# Enable RC4 + AES encryption (makes it attractive to Kerberoast tools)
Set-ADUser -Identity $SamAccountName -Replace @{"msDS-SupportedEncryptionTypes" = 28}
Write-DeployLog "Encryption types set to RC4+AES128+AES256" "SUCCESS"
return [PSCustomObject]@{
SamAccountName = $SamAccountName
SPN = $SPN
ServiceClass = $ServiceClass
Hostname = $Hostname
Port = $Port
}
}
# ---------------------------------------------------------------------------
# New-DecoyGPO
# ---------------------------------------------------------------------------
function New-DecoyGPO {
<#
.SYNOPSIS
Creates a decoy GPO with cpassword credential trap.
.DESCRIPTION
Creates a fake GPO folder in SYSVOL containing a Groups.xml with
encrypted credentials (cpassword). Attackers using Get-GPPPassword,
gpp-decrypt, or CrackMapExec will find and attempt to use these
credentials, which triggers Event ID 4625 (failed logon).
.PARAMETER GPOName
Descriptive name for the decoy GPO.
.PARAMETER DecoyUsername
The username to embed in the cpassword trap.
.PARAMETER DecoyDomain
The short domain name (e.g., CORP).
.PARAMETER SYSVOLPath
The path to the SYSVOL Policies folder.
.PARAMETER EnableAuditSACL
Whether to set SACL audit on the GPO folder (default: true).
#>
[CmdletBinding()]
param(
[Parameter(Mandatory)]
[string]$GPOName,
[Parameter(Mandatory)]
[string]$DecoyUsername,
[Parameter(Mandatory)]
[string]$DecoyDomain,
[Parameter(Mandatory)]
[string]$SYSVOLPath,
[bool]$EnableAuditSACL = $true
)
$GPOGuid = [guid]::NewGuid().ToString().ToUpper()
Write-DeployLog "Creating decoy GPO: $GPOName (GUID: $GPOGuid)" "INFO"
# Create folder structure
$GPOPath = Join-Path $SYSVOLPath "{$GPOGuid}"
$MachinePath = Join-Path $GPOPath "Machine\Preferences\Groups"
New-Item -ItemType Directory -Path $MachinePath -Force | Out-Null
# Generate fake cpassword
$FakePassword = "H0n3yT0k3n_Tr4p_$(Get-Date -Format 'yyyy')!"
$FakeCPassword = [Convert]::ToBase64String([Text.Encoding]::Unicode.GetBytes($FakePassword))
$UserGuid = [guid]::NewGuid().ToString().ToUpper()
# Create Groups.xml with cpassword trap
$GroupsXml = @"
<?xml version="1.0" encoding="utf-8"?>
<Groups clsid="{3125E937-EB16-4b4c-9934-544FC6D24D26}">
<User clsid="{DF5F1855-51E5-4d24-8B1A-D9BDE98BA1D1}"
name="$DecoyUsername"
image="2"
changed="2011-07-15 08:30:22"
uid="{$UserGuid}">
<Properties action="U"
newName=""
fullName="Maintenance Administrator"
description="Legacy maintenance account"
cpassword="$FakeCPassword"
changeLogon="0"
noChange="1"
neverExpires="1"
acctDisabled="0"
userName="$DecoyDomain\$DecoyUsername" />
</User>
</Groups>
"@
$GroupsXml | Out-File -FilePath (Join-Path $MachinePath "Groups.xml") -Encoding UTF8
Write-DeployLog "Groups.xml planted with cpassword trap" "SUCCESS"
# Create corresponding trap AD account with different password
$TrapPassword = New-SecureRandomPassword -Length 64
$SecureTrap = ConvertTo-SecureString -String $TrapPassword -AsPlainText -Force
try {
New-ADUser -Name $DecoyUsername `
-SamAccountName $DecoyUsername `
-Description "Maintenance account - legacy" `
-AccountPassword $SecureTrap `
-Enabled $true `
-PasswordNeverExpires $true
Write-DeployLog "Trap account created: $DecoyUsername (password differs from GPP)" "SUCCESS"
}
catch {
Write-DeployLog "Trap account creation: $_" "WARN"
}
# Set SACL
if ($EnableAuditSACL) {
$FolderAcl = Get-Acl $GPOPath
$AuditRule = New-Object System.Security.AccessControl.FileSystemAuditRule(
"Everyone", "ReadData", "ContainerInherit,ObjectInherit", "None", "Success"
)
$FolderAcl.AddAuditRule($AuditRule)
Set-Acl $GPOPath $FolderAcl
Write-DeployLog "SACL set on GPO folder (Event ID 4663)" "SUCCESS"
}
return [PSCustomObject]@{
GPOGuid = $GPOGuid
GPOName = $GPOName
GPOPath = $GPOPath
DecoyUsername = $DecoyUsername
DecoyDomain = $DecoyDomain
}
}
# ---------------------------------------------------------------------------
# New-DeceptiveBloodHoundPath
# ---------------------------------------------------------------------------
function New-DeceptiveBloodHoundPath {
<#
.SYNOPSIS
Creates fake BloodHound attack paths pointing to monitored honeytokens.
.DESCRIPTION
Sets ACL permissions that create apparent attack paths visible to
BloodHound/SharpHound reconnaissance. These paths lead attackers toward
monitored honeytoken accounts, triggering alerts when abused.
.PARAMETER HoneytokenSamAccount
The honeytoken account to create paths toward.
.PARAMETER TargetHighValueGroup
The high-value group to create a deceptive path to (default: Domain Admins).
.PARAMETER IntermediateOU
OU path for intermediate objects.
#>
[CmdletBinding()]
param(
[Parameter(Mandatory)]
[string]$HoneytokenSamAccount,
[string]$TargetHighValueGroup = "Domain Admins",
[string]$IntermediateOU = "OU=Service Accounts"
)
Write-DeployLog "Creating deceptive BloodHound paths for: $HoneytokenSamAccount" "INFO"
$UserDN = (Get-ADUser -Identity $HoneytokenSamAccount).DistinguishedName
# Create GenericAll edge from regular group to honeytoken
$GroupSID = (Get-ADGroup -Identity "Remote Desktop Users").SID
$Acl = Get-Acl "AD:\$UserDN"
$AceRule = New-Object System.DirectoryServices.ActiveDirectoryAccessRule(
$GroupSID,
[System.DirectoryServices.ActiveDirectoryRights]"GenericAll",
[System.Security.AccessControl.AccessControlType]"Allow"
)
$Acl.AddAccessRule($AceRule)
Set-Acl "AD:\$UserDN" $Acl
Write-DeployLog "GenericAll ACE: Remote Desktop Users -> $HoneytokenSamAccount" "SUCCESS"
# Create deceptive intermediate group
$DeceptiveGroup = "IT-Infrastructure-Admins"
try {
New-ADGroup -Name $DeceptiveGroup -GroupScope DomainLocal `
-GroupCategory Security `
-Description "Infrastructure administration delegation"
Write-DeployLog "Created deceptive group: $DeceptiveGroup" "SUCCESS"
}
catch {
Write-DeployLog "Deceptive group may already exist" "WARN"
}
Add-ADGroupMember -Identity $DeceptiveGroup -Members $HoneytokenSamAccount
Write-DeployLog "Added honeytoken to $DeceptiveGroup" "SUCCESS"
# Create WriteDacl edge with deny safety net
$DAGroupDN = (Get-ADGroup -Identity $TargetHighValueGroup).DistinguishedName
$HoneySID = (Get-ADUser -Identity $HoneytokenSamAccount).SID
$DAGroupAcl = Get-Acl "AD:\$DAGroupDN"
$DenyRule = New-Object System.DirectoryServices.ActiveDirectoryAccessRule(
$HoneySID,
[System.DirectoryServices.ActiveDirectoryRights]"GenericAll",
[System.Security.AccessControl.AccessControlType]"Deny"
)
$WriteDaclRule = New-Object System.DirectoryServices.ActiveDirectoryAccessRule(
$HoneySID,
[System.DirectoryServices.ActiveDirectoryRights]"WriteDacl",
[System.Security.AccessControl.AccessControlType]"Allow"
)
$DAGroupAcl.AddAccessRule($DenyRule)
$DAGroupAcl.AddAccessRule($WriteDaclRule)
Set-Acl "AD:\$DAGroupDN" $DAGroupAcl
Write-DeployLog "Deceptive WriteDacl path created (with deny safety)" "SUCCESS"
return [PSCustomObject]@{
HoneytokenAccount = $HoneytokenSamAccount
PathDescription = "Remote Desktop Users -> $HoneytokenSamAccount -> $DeceptiveGroup -> $TargetHighValueGroup (blocked)"
DeceptiveGroup = $DeceptiveGroup
}
}
# ---------------------------------------------------------------------------
# Test-HoneytokenDeployment
# ---------------------------------------------------------------------------
function Test-HoneytokenDeployment {
<#
.SYNOPSIS
Validates honeytoken deployment integrity.
#>
[CmdletBinding()]
param(
[Parameter(Mandatory)]
[string]$SamAccountName,
[switch]$ValidateAdminCount,
[switch]$ValidateSPN,
[switch]$ValidateGPODecoy,
[switch]$ValidateAuditPolicy
)
$Results = @()
# Account existence
$User = Get-ADUser -Identity $SamAccountName -Properties * -ErrorAction SilentlyContinue
if ($User) {
$Results += [PSCustomObject]@{Check="Account Exists"; Status="PASS"; Details=$User.DistinguishedName}
$Results += [PSCustomObject]@{Check="Account Enabled"; Status=$(if($User.Enabled){"PASS"}else{"FAIL"}); Details=$(if($User.Enabled){"Enabled"}else{"Disabled"})}
} else {
$Results += [PSCustomObject]@{Check="Account Exists"; Status="FAIL"; Details="Not found"}
return $Results
}
if ($ValidateAdminCount) {
$Results += [PSCustomObject]@{
Check = "AdminCount=1"
Status = $(if($User.AdminCount -eq 1){"PASS"}else{"WARN"})
Details = "AdminCount=$($User.AdminCount)"
}
}
if ($ValidateSPN) {
$SPNs = $User.ServicePrincipalNames
$Results += [PSCustomObject]@{
Check = "SPN Configured"
Status = $(if($SPNs -and $SPNs.Count -gt 0){"PASS"}else{"WARN"})
Details = $(if($SPNs){$SPNs -join ", "}else{"No SPNs"})
}
}
if ($ValidateAuditPolicy) {
$AuditCheck = auditpol /get /subcategory:"Kerberos Service Ticket Operations" 2>$null
$Results += [PSCustomObject]@{
Check = "Kerberos TGS Auditing"
Status = $(if($AuditCheck -match "Success"){"PASS"}else{"FAIL"})
Details = $(if($AuditCheck -match "Success"){"Enabled"}else{"Run: auditpol /set /subcategory:'Kerberos Service Ticket Operations' /success:enable"})
}
}
# Password age
$PwdAge = (Get-Date) - $User.PasswordLastSet
$Results += [PSCustomObject]@{
Check = "Password Age"
Status = $(if($PwdAge.Days -gt 365){"PASS"}else{"WARN"})
Details = "$($PwdAge.Days) days"
}
return $Results
}
# ---------------------------------------------------------------------------
# Deploy-FullHoneytokenSuite
# ---------------------------------------------------------------------------
function Deploy-FullHoneytokenSuite {
<#
.SYNOPSIS
Deploys a complete honeytoken suite in Active Directory.
#>
[CmdletBinding()]
param(
[string]$Environment = "Production",
[Parameter(Mandatory)]
[string]$ServiceAccountOU,
[Parameter(Mandatory)]
[string]$SYSVOLPath,
[int]$TokenCount = 3,
[bool]$IncludeSPN = $true,
[bool]$IncludeGPODecoy = $true,
[bool]$IncludeBloodHoundPath = $true,
[string]$SIEMType = "Splunk"
)
Write-DeployLog "Starting full honeytoken suite deployment for $Environment" "INFO"
Write-DeployLog "Token count: $TokenCount, SPN: $IncludeSPN, GPO: $IncludeGPODecoy" "INFO"
$Tokens = @()
# Service account name templates
$ServiceNames = @(
@{Sam="svc_sqlbackup_legacy"; Display="SQL Backup Service (Legacy)"; SPN_Class="MSSQLSvc"; Host="sql-bak-legacy01"; Port=1433},
@{Sam="svc_exchange_transport"; Display="Exchange Transport Agent"; SPN_Class="exchangeMDB"; Host="exch-hub-legacy02"; Port=443},
@{Sam="svc_scom_monitor"; Display="SCOM Monitoring Service"; SPN_Class="HTTP"; Host="scom-legacy-mgmt01"; Port=5723},
@{Sam="svc_adfs_proxy_old"; Display="ADFS Proxy Service (Old)"; SPN_Class="HTTP"; Host="adfs-proxy-legacy01"; Port=443},
@{Sam="svc_citrix_storefront"; Display="Citrix StoreFront Service"; SPN_Class="HTTP"; Host="ctx-sf-legacy01"; Port=443}
)
$Domain = (Get-ADDomain).DNSRoot
for ($i = 0; $i -lt [Math]::Min($TokenCount, $ServiceNames.Count); $i++) {
$svc = $ServiceNames[$i]
# Create admin account
$admin = New-HoneytokenAdmin `
-SamAccountName $svc.Sam `
-DisplayName $svc.Display `
-Description "Legacy $($svc.Display.ToLower()) - DO NOT DELETE" `
-OU $ServiceAccountOU
$tokenInfo = [PSCustomObject]@{
Name = $svc.Sam
Type = "admin_account"
SPN = ""
DetectionRule = "Event ID 4662 (object access)"
}
# Add SPN
if ($IncludeSPN) {
$Hostname = "$($svc.Host).$Domain"
$spnResult = Add-HoneytokenSPN `
-SamAccountName $svc.Sam `
-ServiceClass $svc.SPN_Class `
-Hostname $Hostname `
-Port $svc.Port
$tokenInfo.SPN = $spnResult.SPN
$tokenInfo.DetectionRule = "Event ID 4769 (Kerberoast)"
}
$Tokens += $tokenInfo
}
# Deploy GPO decoy
if ($IncludeGPODecoy) {
$DomainShort = ($Domain -split '\.')[0].ToUpper()
$gpo = New-DecoyGPO `
-GPOName "Server Maintenance Policy (Legacy)" `
-DecoyUsername "admin_maintenance" `
-DecoyDomain $DomainShort `
-SYSVOLPath $SYSVOLPath
$Tokens += [PSCustomObject]@{
Name = "admin_maintenance"
Type = "gpo_credential"
SPN = ""
DetectionRule = "Event ID 4625 (failed logon with GPP creds)"
}
}
# Create BloodHound deception
if ($IncludeBloodHoundPath -and $Tokens.Count -gt 0) {
$bhPath = New-DeceptiveBloodHoundPath `
-HoneytokenSamAccount $Tokens[0].Name
}
$deployment = [PSCustomObject]@{
Environment = $Environment
Tokens = $Tokens
DeployedAt = (Get-Date -Format "yyyy-MM-dd HH:mm:ss")
Log = $Script:DeploymentLog
}
Write-DeployLog "Deployment complete: $($Tokens.Count) tokens deployed" "SUCCESS"
return $deployment
}
# ---------------------------------------------------------------------------
# Export module members
# ---------------------------------------------------------------------------
Export-ModuleMember -Function @(
'New-HoneytokenAdmin',
'Add-HoneytokenSPN',
'New-DecoyGPO',
'New-DeceptiveBloodHoundPath',
'Test-HoneytokenDeployment',
'Deploy-FullHoneytokenSuite'
)
File diff suppressed because it is too large Load Diff