Skip to main content

Identity Exposure

What it is

Identity Exposure monitors local user accounts on endpoint agents and detects identity-related security risks that traditional vulnerability scanning misses — dormant admin accounts, brute-force patterns, and shared credentials across machines.

Finding categories

CategoryWhat it detects
Privileged AccountUser belongs to the Administrators group
Excessive Login FailuresThree or more failed login attempts in a single day
Stale AccountNo login activity for more than 90 days
Shared AccountSame username appears on more than one agent

Highlights

  • Per-user tracking — monitors username, security identifier (SID), group membership, and login activity.
  • AI-enriched findings — each finding receives a severity rating, description, solution, and mitigation guidance.
  • Automatic resolution — findings close when the underlying condition no longer applies (e.g., admin rights removed).
  • Severity-based — findings are rated Low, Medium, High, or Critical (no separate numeric score).

Why it matters

Compromised or misconfigured identities are a leading attack vector. This module surfaces account hygiene issues before they become breach entry points.

In the application