CTD-000185

Failed logon attempts targeting honey account

Medium
Active Directory
Credential Access Discovery
v18

Signature Identity

CTD-000185
Threat ID
18
Version
IOA
Indicator Type

Threat Description

Honey accounts are non-operational, decoy accounts intentionally created to attract and monitor unauthorized access attempts by threat actors. A series of failed logon attempts targeting these accounts may indicate brute-force attacks, reconnaissance activity, or the presence of an unauthorized user probing the environment. Such activity often precedes lateral movement or privilege escalation attempts. Because honey accounts are not used in legitimate operations, any authentication attempt against them is considered inherently suspicious.

For more information, see Microsoft’s documentation on Event ID 4625 – An account failed to log on..

NOTE: This threat rule includes a built-in lookback parameter set to 25 hours. Only events that occurred within this timeframe are processed by the rule.

MITRE ATT&CK: Attack Tactics

Credential Access Discovery

D3FEND: Defend Tactics

D3-CCSA (Credential Compromise Scope Analysis) Domain Account Monitoring

Remediation

  1. Investigate the source IP and host initiating failed logon attempts against the honey account.
  2. Isolate the endpoint if it exhibits additional signs of compromise, such as lateral movement or credential dumping.

Frequently Asked Questions

What does Failed logon attempts targeting honey account mean?

A failed logon attempt against a honey account occurs when an attacker submits incorrect credentials, triggering authentication failures. These decoy accounts are not used for legitimate operations and any authentication attempt against them is inherently suspicious.

Repeated failed logon attempts against a honey account may indicate a brute-force attack or reconnaissance activity, which can lead to lateral movement or privilege escalation attempts. This type of behavior often precedes potential compromise and should be investigated promptly.

Attackers can use failed logon attempts against honey accounts to gather information about the environment, identify vulnerabilities, and plan future attacks. This activity often goes unnoticed because it appears as normal login traffic, allowing attackers to maintain persistence.

Cayosoft Guardian detects failed logon attempts against honey accounts by continuously monitoring authentication events in the Active Directory environment. When repeated, unsuccessful login attempts are detected, Guardian flags the issue so administrators can investigate and take action.

Cayosoft Guardian helps reduce the risk of failed logon attempts against honey accounts by providing visibility into attacker activity, showing change history, and supporting investigation to catch similar activity in the future.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Account protection
Attack Tactics
Credential Access Discovery
Defend Tactics
D3-CCSA (Credential Compromise Scope Analysis) Domain Account Monitoring
Indicator Types
IOA
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical