Hunting Active Directory Honeypots: Reading lastLogon as a Decoy Oracle
Original text: “Hunting Honey Pots as Red Teamers” — Charles F. Hamilton, CYPFER Offensive Practice (June 15, 2026). Screenshots and the sam_honeypot_enum.c source are reproduced verbatim with attribution captions.
Executive Summary
Honeytokens and honeypot accounts are some of the highest-signal tripwires defenders can place inside Active Directory: any interaction with them is, by construction, illegitimate.…
https://core-jmp.org/2026/06/hunting-active-directory-honeypots-lastlogon-oracle/
Post #3479
4.63K

- 🔥 6
- 👍 1