Threat DS.Auth.HPsACd-pDS-V.1.6

URI: DS.Auth.HPsACd-pDS-V.1.6

Package: DataLifecycle

< prev | next >

Description: Use of compromised key at Process to alter Data stored on Host: someone with the rights of Process on its host device Host can alter the local encrypted copy of data Data by using a cryptographic key assigned to Process allowing it to serve the data.

Threat Type: Primary Threat

Matching Pattern:

DS.Auth.HPsACd-pDS-V.1.6
MP-HPsACd-pDS-V

Finds a host running a Process with write/delete access (crudd) to a locally stored data copy not controlled by a key vault, which it does not process (i.e., it serves the data), plus the data access asset representing the data deserialization, the access contexts for the process on this host, any data fields included in the stored data, and optionally the host manager.

        (empty)

        CSG-DataAccessKey

        (empty)