Threat DS.C.HPsACr-pDS-V.2

URI: DS.C.HPsACr-pDS-V.2

Package: Theft

< prev | next >

Description: Use of Process to access Data stored on stolen device Host: if an attacker can access Process on stolen device Host, they can exploit the rights of Process to read and serve the locally stored copy of Data.

Threat Type: Primary Threat

Matching Pattern:

DS.C.HPsACr-pDS-V.2
MP-HPsACr-pDS-V

Finds a host running a Process with read access (crudr) to a locally stored data copy not controlled by a key vault, which it does not process (i.e., it serves the data), plus the data access asset representing the data deserialization, the access contexts for the process on this host, any data fields included in the stored data, and optionally the host manager.

        (empty)

        (empty)

CSG-DataStorageEncryption

The copy of Data stored on Host is encrypted.