Step 5 of 8 — Lure Triggered
Step 5 of 8
🚨
Lure touched — confirmed breach indicator
fake_admin@corp.local credential used
Source IP: 185.220.101.47 (Tor exit node — DE)
2026-06-13 09:14:32 UTC
This account does not exist in production. Any authentication attempt is a confirmed attacker action — zero false positives.

Breach signal detected

An attacker used a honeypot credential against your Entra ID tenant. HoneyNet blocked the attempt and is reconstructing the attacker's path.

Signal details

Lure typeEntra ID service account
Lure namefake_admin@corp.local
Source IP185.220.101.47
Country🇩🇪 Germany (Tor exit)
Auth methodPassword spray
Attempts3 in 40s
ConfidenceHigh — 100%

MITRE D3FEND mapping

ATT&CK T1078
Valid Accounts — using harvested credentials to access services
ATT&CK T1110.003
Password Spraying — low-and-slow authentication attacks
D3FEND D3-CHN
Credential Honeypot Notification — active deception countermeasure

Related activity — same source IP (last 24h)