@Oddvarmoe@424f424f We'll retest against ATP as it's been some time. When we first tested this against ATP, it did not detect the technique nor the DC Sync with the account. The fake computer object looks like a DC, so we think it ignores it.
@Oddvarmoe@mubix Thanks for the nudge on that one -- we've added a warning and confirmation requirement. We'll also make an update to allow the user to specify which security principal to use and change the default away from 'Authenticated Users'.