Threat DS.Auth.HPsACd-pDS-V.1

URI: DS.Auth.HPsACd-pDS-V.1

Package: DataLifecycle

< prev | next >

Description: Use of Process to alter Data stored on Host: someone with the rights of Process on its host device Host can exploit the rights of Process to serve and update the locally stored copy of Data.

Threat Type: Primary Threat

Matching Pattern:

DS.Auth.HPsACd-pDS-V.1
MP-HPsACd-pDS-V

Finds a host running a Process with write/delete access (crudd) to a locally stored data copy not controlled by a key vault, which it does not process (i.e., it serves the data), plus the data access asset representing the data deserialization, the access contexts for the process on this host, any data fields included in the stored data, and optionally the host manager.

        (empty)

        (empty)

CSG-DataStorageIntegrityProtection

Makes it possible to check if the stored copy of Data on Host has been altered by an unauthorised process.