For AI agents: A markdown version of this page is available at https://docs.datadoghq.com/security/default_rules/def-000-twy.md. A documentation index is available at /llms.txt.

Keeper high risk password detected for user

This rule is part of a beta feature. To learn more, contact Support.

Goal

Flag users with high-risk passwords stored in Keeper.

Strategy

This rule allows monitoring of events where Keeper has detected high risk password stored by user in Keeper.

Triage and response

  • Reach out to the user with email: {{@usr.email}} in enterprise id: {{@enterprise_id}}.
  • Ensure the user rotates the password on all accounts where they may have reused this password.
  • Ensure the user is aware of strong password guidelines.