Delinea Privilege Manager detected a password disclosure event

This rule is part of a beta feature. To learn more, contact Support.

Goal

Detects password disclosure events.

Strategy

This rule monitors the Delinea Privilege Manager logs to detect password disclosure events.

Triage and Response

  1. Investigate the password disclosure event log associated with the managed user: {{@ManagedUserName}}.
  2. Assess whether the managed user account (username: {{@ManagedUserName}}, ID:{{@_ManagedUserId}}) is associated with a critical system or application.
  3. Identify the user to confirm the identity and permissions of the user who disclosed the password.
  4. If the password is disclosed for a critical system, contact the disclosing user to confirm whether the password disclosure was intentional and authorized.
  5. If the disclosure was unauthorized, proceed with account remediation.
  6. Reset the password for the managed user account (username: {{@ManagedUserName}}, ID:{{@_ManagedUserId}}) to prevent potential misuse.
  7. Evaluate and improve access policies to prevent future occurrences.
OSZAR »