What is permission and group discovery?¶
Permission and group discovery is how somebody works out who has access to what.
That might mean identifying administrator groups, cloud roles, delegated access, service accounts, file permissions or other privileges.
For an investigator, this can be useful because it may explain why a particular account or resource was selected later.
What might the result look like?¶
Imagine a query returns:
Group: Domain Admins
Members:
helpdesk-admin
svc-backup
That tells the session that those identities appear to have elevated access.
If svc-backup then shows up in a login attempt against another server, the earlier group query gives that later activity useful context.
Direct membership is not always the whole story¶
Permissions can come from:
- direct group membership;
- nested groups;
- inherited rights;
- delegated roles;
- temporary role activation;
- application permissions; or
- local permissions on a particular resource.
So if the exact access level matters, try to establish the effective access at the relevant time, not just what one screen shows now.
A post-incident cleanup may also have changed the membership by the time you inspect it.
Preserve enough to follow the privilege¶
Useful things to keep include:
- the query or API call;
- the account and process that made it;
- the group, role or resource being examined;
- stable object or role IDs where available;
- the returned membership or permission;
- the time; and
- any later activity using the discovered account or privilege.
svc-backup appears in an admin groupThe session learns that the identity may have useful access.The distinction matters because discovering privilege is not the same as exercising it.
Compare it with expected administration¶
Identity teams, cloud administrators and security tools routinely inspect roles and memberships.
If the activity may be legitimate, compare it with the normal source system, account, maintenance activity and management platform.
The practical point is: permission discovery shows what access looked valuable or available. Use that result to follow the account, role or resource into the next records.