Service Overview
Secrets and Passwords Discovery Assessment involves a focused enumeration of the organization’s data storage platforms to identify the exposure of credentials and authentication secrets.
The goal is to provide insight into the current state of secrets management by locating hard‑coded, stored, or otherwise accessible passwords, API keys, tokens, certificates, and other credentials across the following environments:
OneDrive
SharePoint
Network shares
Employee workstations
Methodology
Using in-house tools and techniques, Cye team conducts keyword-based searches to locate and analyze sensitive data across accessible locations.
The activity can be executed using either:
A standard domain user account to explore authorization and data disclosure risks
A privileged domain user account to identify unprotected sensitive data
If no on-prem domain present, then IdP standard account + read only user
Deliverables
All discovered findings are shown in Cye Exposure Management Platform
A comprehensive report detailing accessible data across each reviewed platform
Prerequisites
A domain-joined endpoint and domain-joined user account
Privileged network access to AD-connected devices
A list of organization-specific keywords to support targeted data probing and analysis
Productivity suite access
Customer Engagement
A point of contact from the organization might be required to support the assessment process, with expected involvement of no more than one hour per week.
Relevant Standards
The proprietary methodology is based on the following standards:
NIST Cybersecurity Framework
ISO/IEC 27001
ISO/IEC 27002
Security Domains Covered
Cross-organization policies, procedures, and governance
Sensitive data and information management
Identity management and remote access
