Skip to main content

Secrets Discovery Assessment

Service Overview

Secrets and Passwords Discovery Assessment involves a focused enumeration of the organization’s data storage platforms to identify the exposure of credentials and authentication secrets.

The goal is to provide insight into the current state of secrets management by locating hard‑coded, stored, or otherwise accessible passwords, API keys, tokens, certificates, and other credentials across the following environments:

  • OneDrive

  • SharePoint

  • Network shares

  • Employee workstations


Methodology

Using in-house tools and techniques, Cye team conducts keyword-based searches to locate and analyze sensitive data across accessible locations.

The activity can be executed using either:

  • A standard domain user account to explore authorization and data disclosure risks

  • A privileged domain user account to identify unprotected sensitive data

  • If no on-prem domain present, then IdP standard account + read only user


Deliverables

  • All discovered findings are shown in Cye Exposure Management Platform

  • A comprehensive report detailing accessible data across each reviewed platform


Prerequisites

  • A domain-joined endpoint and domain-joined user account

  • Privileged network access to AD-connected devices

  • A list of organization-specific keywords to support targeted data probing and analysis

  • Productivity suite access


Customer Engagement

A point of contact from the organization might be required to support the assessment process, with expected involvement of no more than one hour per week.


Relevant Standards

The proprietary methodology is based on the following standards:

  • NIST Cybersecurity Framework

  • ISO/IEC 27001

  • ISO/IEC 27002


Security Domains Covered

  • Cross-organization policies, procedures, and governance

  • Sensitive data and information management

  • Identity management and remote access

Did this answer your question?