Step 5 of 8
🚨
Lure touched — confirmed breach indicator
fake_admin@corp.local credential used
Source IP: 185.220.101.47 (Tor exit node — DE)
2026-06-13 09:14:32 UTC
Source IP: 185.220.101.47 (Tor exit node — DE)
2026-06-13 09:14:32 UTC
This account does not exist in production. Any authentication attempt is a confirmed attacker action — zero false positives.
Breach signal detected
An attacker used a honeypot credential against your Entra ID tenant. HoneyNet blocked the attempt and is reconstructing the attacker's path.
Signal details
Lure typeEntra ID service account
Lure namefake_admin@corp.local
Source IP185.220.101.47
Country🇩🇪 Germany (Tor exit)
Auth methodPassword spray
Attempts3 in 40s
ConfidenceHigh — 100%
MITRE D3FEND mapping
ATT&CK T1078
Valid Accounts — using harvested credentials to access services
ATT&CK T1110.003
Password Spraying — low-and-slow authentication attacks
D3FEND D3-CHN
Credential Honeypot Notification — active deception countermeasure
Related activity — same source IP (last 24h)
- 09:08:14 — Probed 14 M365 user accounts (no lures hit)
- 09:11:50 — Attempted access to S3 bucket
corp-backup-archive-hn17(lure bucket) - 09:14:32 — Auth attempt on fake_admin@corp.local (lure triggered)
- 09:14:35 — IP automatically blocked at Entra ID Conditional Access