This document provides information on how to discover service-associated credentials. Segura® Platform can identify credentials used by running Windows services.
Requirements
To ensure the correct functioning of the credential search functionality associated with Windows services, you must meet the following requirements:
- A device discovery must be configured to find credentials.
- At least one local credential must be identified during the scan to enable the service search.
- The target machine must have an active connection via WinRM to find the credentials associated with the services.
- The target machine must have Powershell installed, and the credential used in the search must be authorized to access the
Win32_Servicerecords and perform queries.
Info
This feature can’t discover credentials associated with domain accounts.
Discover service-associated credentials
To configure the discovery of credentials associated with Windows services, see the following steps:
- On Segura® Platform, in the navigation bar, hover over the Products menu and select Discovery.
- In the side menu, select Management > Discovery.
- In the Discovery report, click Add.
- Select Device as the discovery type.
- In the Settings tab, enter the following information:
- In the Name * field, enter a name for the discovery.
- Optional: In the Enable origin-based segregation (IP range) field, toggle to enable origin-based segregation. Make sure to have an IP segregation configured; otherwise, this field won’t work.
- In the Initial IP * field, enter the starting IP of the range.
- Optional: In the Final IP field, enter the final IP of the range.
- Optional: In the Site field, enter the site where your device is located.
- In the Enabled * field, select Yes or No to enable or disable the discovery.
- Click Continue.
- In the Connection tab, enter the following information:
- In the Access credential field, select a credential.
- Optional: In the Network Connector field, select the network connector responsible for performing the scan.
- Optional: In the Configuration password (ex: enable) field, enter the configuration password for devices such as switches.
- Optional: In the Force sudo use field, enable to force the commands to run with
sudoon Linux or Unix. - Optional: In the Pool of credentials section, click + Add to select the pool of credentials.
- Select the pool and click Add.
- Click Continue.
- In the Searches tab, select the following information:
- In the Search for credentials field, select to discover credentials.
- In the Identify Windows accounts associated with a service field, select to discover Windows credentials associated with services.
- Click Continue.
- In the Plugin Information tab, select the following information:
- In the Plugins for discovery section, click + Add to select the plugins used for discovery.
- Select the Windows plugin, use the default port or change it to a different port.
- In the Plugins for discovery section, click + Add to select the plugins used for discovery.
- Click Continue.
- Optional: In the Execution tab, enter the following information:
- In the Keep scan active after import? * field, select to keep the discovery looking for new credentials after the first import.
- In the Days allowed for execution section, select when the discovery will run.
- In the Periods allowed for execution section, select at what times the discovery will run.
- In the Interval between executions (in hours) * field, select the interval between each scan of the discovery.
- Click Continue.
- Optional: In the Import tab, enter the following information:
- In the Enable automatic importation of devices and credentials? * field, toggle it to enable automatic importation of devices and credentials directly into PAM Core.
- In the Credential import section, click + Add to enter the credentials’ username to be imported automatically.
- Click Continue.
- In the Review tab, review all information entered previously and click Save.
View service-associated credentials
After the discovery is completed, it’s possible to view the credentials associated with services in a report. See the following steps:
- On Segura® Platform, in the navigation bar, hover over the Products menu and select Discovery.
- In the side menu, select Discoveries > Services.
- In the Device services report, fill in the search fields with the required information to locate the desired credential.