Threat DS.Auth.HPsACdDSCCV.1

URI: DS.Auth.HPsACdDSCCV.1

Package: ProcessComms

< prev | next >

Description: Use of Process to access Data stored on Host: someone with the rights of Process on its host device Host, and able to obtain a key from Vault can exploit the rights of Process to alter the locally stored copy of Data.

Threat Type: Primary Threat

Matching Pattern:

DS.Auth.HPsACdDSCCV.1
MP-HPsACdDSCCV

Finds a host running a Process with write/delete access (crudd) to a locally stored data copy, plus the data access asset representing the data deserialization, and a channel to a key vault that controls the stored data, plus any data fields included in the data copy and used by the process, the process access contexts (a non-unique sufficient match), and optionally the process host manager.

        (empty)

        (empty)

        (empty)