Threat DS.C.HPsACr-pDS-V.2.6

URI: DS.C.HPsACr-pDS-V.2.6

Package: Theft

< prev | next >

Description: Use of compromised key at Process to access Data stored on stolen device Host: if an attacker can access Process on stolen device Host, they can access the local encrypted copy of data Data by using a cryptographic key assigned to Process allowing it to serve the data.

Threat Type: Primary Threat

Matching Pattern:

DS.C.HPsACr-pDS-V.2.6
MP-HPsACr-pDS-V

Finds a host running a Process with read access (crudr) to a locally stored data copy not controlled by a key vault, which it does not process (i.e., it serves the data), plus the data access asset representing the data deserialization, the access contexts for the process on this host, any data fields included in the stored data, and optionally the host manager.

        (empty)

        CSG-DataAccessKey

        (empty)