Password File Detection - Add Scan Option
complete
Patrick Sofo [Security Product Manager]
complete
Patrick Sofo [Security Product Manager]
Update from my comment on 10/11 the features are now available in the Huntress Portal
More info here: https://support.huntress.io/hc/en-us/articles/21966460493331
For the time being existing accounts will be opted out by default, but you can opt in within Account Settings.
Patrick Sofo [Security Product Manager]
The Huntress team is working on a feature to provide these reports on a weekly cadence that can be opted into or out of... along with host/org level exclusions. We also plan to provide partners some additional mgmt. capabilities, such as bulk incident report resolve and a CSV download for these findings.
More details coming soon!
C
Corey Ames
I agree this would be very helpful. But the Huntress scan was not good enough. I know for a fact that other of my customers have password files, but they were not found. If you can't find a password file, I would not find it inappropriate to scan possible files for passwords. I'm sure you can find some criteria for red flagging files like finding the word "password", "#1", random strings of letters and what not. You can call it a monthly compliance check.
S
Spencer Doucet
I think this is a great idea and would like it to become an option as well
Y
Yvone'la Kiehn'la
If it could exclude password protected xlsx files, that would be a nice option. Some customers stubbornly still won't use a password manager, a good password on an encrypted xlsx is a compromise, I'd hate to have it flag those files though.
C
Corey Ames
Yvone'la Kiehn'la: Unfortunately, password protected Microsoft 365 files can be submitted to the web and have the files returned immediately with the password stripped off. They are not safe. Google it, show it to your customers using that compromise and then sell them your password manager service.