Delinea Privilege Manager detected a password disclosure event
Cette page n'est pas encore disponible en français, sa traduction est en cours.
Si vous avez des questions ou des retours sur notre projet de traduction actuel,
n'hésitez pas à nous contacter.
Goal
Detects password disclosure events.
Strategy
This rule monitors the Delinea Privilege Manager logs to detect password disclosure events.
Triage and Response
- Investigate the password disclosure event log associated with the managed user:
{{@ManagedUserName}}
. - Assess whether the managed user account (username:
{{@ManagedUserName}}
, ID:{{@_ManagedUserId}}
) is associated with a critical system or application. - Identify the user to confirm the identity and permissions of the user who disclosed the password.
- If the password is disclosed for a critical system, contact the disclosing user to confirm whether the password disclosure was intentional and authorized.
- If the disclosure was unauthorized, proceed with account remediation.
- Reset the password for the managed user account (username:
{{@ManagedUserName}}
, ID:{{@_ManagedUserId}}
) to prevent potential misuse. - Evaluate and improve access policies to prevent future occurrences.