Identity Exposure
What it is
Identity Exposure monitors local user accounts on endpoint agents and detects identity-related security risks that traditional vulnerability scanning misses — dormant admin accounts, brute-force patterns, and shared credentials across machines.
Finding categories
| Category | What it detects |
|---|---|
| Privileged Account | User belongs to the Administrators group |
| Excessive Login Failures | Three or more failed login attempts in a single day |
| Stale Account | No login activity for more than 90 days |
| Shared Account | Same username appears on more than one agent |
Highlights
- Per-user tracking — monitors username, security identifier (SID), group membership, and login activity.
- AI-enriched findings — each finding receives a severity rating, description, solution, and mitigation guidance.
- Automatic resolution — findings close when the underlying condition no longer applies (e.g., admin rights removed).
- Severity-based — findings are rated Low, Medium, High, or Critical (no separate numeric score).
Why it matters
Compromised or misconfigured identities are a leading attack vector. This module surfaces account hygiene issues before they become breach entry points.
In the application
- Identities (Exposure) — identity findings across the organization
- Identities (Assets) — identity context per endpoint
- Asset detail → Identity exposure tab