Delinea Privilege Manager detected a password disclosure event
Set up the delinea-privilege-manager integration.
このページは日本語には対応しておりません。随時翻訳に取り組んでいます。
翻訳に関してご質問やご意見ございましたら、
お気軽にご連絡ください。
Goal
Detects password disclosure events.
Strategy
This rule monitors the Delinea Privilege Manager logs to detect password disclosure events.
Triage and Response
- Investigate the password disclosure event log associated with the managed user:
{{@ManagedUserName}}
. - Assess whether the managed user account (username:
{{@ManagedUserName}}
, ID:{{@_ManagedUserId}}
) is associated with a critical system or application. - Identify the user to confirm the identity and permissions of the user who disclosed the password.
- If the password is disclosed for a critical system, contact the disclosing user to confirm whether the password disclosure was intentional and authorized.
- If the disclosure was unauthorized, proceed with account remediation.
- Reset the password for the managed user account (username:
{{@ManagedUserName}}
, ID:{{@_ManagedUserId}}
) to prevent potential misuse. - Evaluate and improve access policies to prevent future occurrences.