Leaked Credentials Events
11 min
as flare collects data from various sources, leaked credentials are continuously extracted from ingested documents and indexed in two places the tenant feed docid\ dtls7nx5g qwodcs3ydpd and the credentials browser docid\ d3onszzq0knmu79ma 5oe any leaked credentials that match your configured identifiers are automatically added to your tenant feed, enabling you to actively monitor for exposures directly affecting your organization how they work each newly detected credential that matches your identifiers appears as its own individual card in the events feed as soon as it is detected newly detected credentials appear instantly in both the tenant feed and the credentials browser docid\ d3onszzq0knmu79ma 5oe the number of leaked credential events in your tenant feed will always match the count shown in the credentials browser and the dashboard credential validation can be triggered manually from the credentials browser or run automatically each validation check generates an event, creating an audit trail of when validation occurred and what the result was event categories leaked credential events are grouped into four categories based on their validation status event category description all credentials all leaked credentials discovered by flare valid credentials credentials confirmed to have a correct leaked password invalid credentials credentials confirmed to have an incorrect leaked password mitigated credentials credentials confirmed to have a correct password, but where mitigation actions have since been taken alerts can be created alert central docid\ eqfosnlszdt49 kdw6xts based on specific event categories, allowing your team to prioritize and respond to confirmed active exposures more efficiently each leaked credential event includes the following details, depending on its category event title and source displays the event type and the source where the credential was found severity displayed as a badge at the top of the summary tab and indicates the urgency of the event creation date the date and time the event was created use this to correlate the event with your own sign in logs to see activity around the same time identity name the affected identity or email address see all credentials located in the content section select this link to open the credentials browser and view all credentials associated with that identity identity profile the affected identity select the email address under the email / username column in the content section to navigate directly to the identity profile mitigation action for mitigated events, the action taken is also displayed here is a snapshot of the information that each leaked credentials event displays remediating and ignoring events to remediate or ignore an event, expand the actions menu in the top right of the event card and select the required option remediation and ignore statuses for events are synchronized between the tenant feed and the credentials browser remediating a leaked credential event in the feed will remediate the corresponding credential pair in the credentials browser, and vice versa remediating a credential pair will also automatically remediate future credentials with the same username/password combination ignoring a leaked credential event will ignore all credential pairs associated with the same email address or username configuring alerts alerts can be configured for any credential event category, allowing your team to act at each stage of the validation process for example, you can create an alert docid\ eqfosnlszdt49 kdw6xts when a credential is confirmed valid, and a separate alert when a mitigation action has been completed even though credential events appear in the tenant feed instantly, alerts are triggered on an hourly cadence , even when configured to send as soon as possible each alert message includes all events added to the feed during that time window even though leaked credential events appear in the tenant feed instantly, alerts are triggered on an hourly cadence , even when configured to send as soon as possible each alert message includes all individual events added to the feed during that time window alerts never include password values, regardless of tenant permissions this applies to email alerts and all other notification channel types searching leaked credentials in global search searching for leaked credentials in global search generates a grouped card for results note that global search results are capped at 1,000 credentials per card for broader searches without this limitation, use the credentials browser docid\ d3onszzq0knmu79ma 5oe , which supports unrestricted searching and exploration of leaked credentials filter events using password attributes leaked credential events can be filtered by a set of password attributes that describe the leaked password, including its length and the counts of lowercase, uppercase, numeric, and special characters these attributes are available when searching for events in the events feed or global search and in matching policies here are the available password attributes looking for search passwords shorter than 10 characters password attributes password length <10 passwords with no lowercase letters password attributes password lowercase count 0 passwords with no uppercase letters password attributes password uppercase count 0 passwords with no numbers password attributes password number count 0 passwords with no special characters password attributes password special count 0 passwords meeting a full policy (10+ characters, 1+ number, 1+ special) password attributes password length >=10 and password attributes password number count >=1 and password attributes password special count >=1