A honeytoken-based tripwire for detecting Active Directory credential theft and privilege escalation attempts.
DCEPT is a honeytoken-based tripwire for Microsoft Active Directory that detects credential theft and privilege escalation attempts. It deploys fake credentials cached on endpoints, and any logon attempt using these tokens signals an intruder is inside the network. The tool provides forensic timelines and helps administrators identify breaches before they escalate.
Windows system administrators and security teams managing Active Directory environments who need to detect lateral movement and credential theft attacks.
Developers choose DCEPT because it offers a free, open-source alternative to commercial detection tools, with a simple deployment via Docker and a focus on educating about real-world attack patterns. Its honeytoken approach provides low-risk, high-visibility detection without compromising valid credentials.
A tool for deploying and detecting use of Active Directory honeytokens
Agents cache invalid credentials in endpoint memory, posing no compromise risk while creating forensic trails, as specified in the README.
Tokens are uniquely tied to workstations and time windows, aiding investigation scope narrowing, which is highlighted in the overview.
Docker container builds for server components make deployment straightforward, with scripts provided for building and running.
Designed to educate administrators about credential theft attacks, offering a free, open-source alternative to commercial tools.
The agent is provided as C# source code only, requiring administrators to audit and compile it before deployment, adding setup complexity.
Currently only supports notifications via rsyslog, lacking built-in integrations with other alerting systems or SIEMs beyond syslog.
Only monitors for logon attempts without active response capabilities, meaning it detects intrusions but doesn't prevent them.
🍯 T-Pot - The All In One Multi Honeypot Platform 🐝
SSH tarpit that slowly sends an endless banner
Reverse engineering and pentesting for Android applications
Modular and decentralised honeypot
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.