Enable/disable credential reports per organisation instead of global
complete
R
Robbin Klein Gunnewiek
Currently, credential reports can only be enabled or disabled globally. In the past, we chose to disable this feature globally due to the high volume of noise it generated.
However, we would now like to reintroduce credential reporting in a more controlled and targeted manner.
We would like the ability to enable or disable credential reports on a per-organisation basis, rather than only at a global level.
Russ Bashaw - Huntress
updated the status to
complete
Hey Robbin and others! We've updated this capability with a new dashboard and file allow-listing to cut down on the alert fatigue! That one is for you Kevin!
We've also allowed you to access org and endpoint level exclusions easier by accessing the settings from within the new dashboard.
You can view it at /account/credential_files or through the Process Insights dashboard within EDR. Thanks for the feedback everyone!
K
Kevin Tetreault
This looks great in first glance. You can exclude based on file, host, or entire org. Thanks for a great update as usual team.
Russ Bashaw - Huntress
updated the status to
complete
Hey Robbin and others! We've updated this capability with a new dashboard and file allow-listing to cut down on the alert fatigue! That one is for you Kevin!
We've also allowed you to access org and endpoint level exclusions easier by accessing the settings from within the new dashboard.
You can view it at /account/credential_files or through the Process Insights dashboard within EDR. Thanks for the feedback everyone!
Simon Behr
I believe you can already achieve this by excluding whole organisations.
Enable it globally, then set exclusions for "Process Insight > Credential Report" for organisations where you want it disabled. Going the opposite way (disabling globally but enabling specific orgs) may not be possible right now.
K
Kevin Tetreault
I would love to be able to exclude files from being alerted for some clients. Some are not true password files but something along the lines of "New Hire Password Best Practices" or something.
R
Rob Snijders
This would be great :)