Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is permission and group discovery?

Permission and group discovery is how somebody works out who has access to what.

That might mean identifying administrator groups, cloud roles, delegated access, service accounts, file permissions or other privileges.

For an investigator, this can be useful because it may explain why a particular account or resource was selected later.

What might the result look like?

Imagine a query returns:

Group: Domain Admins
Members:
  helpdesk-admin
  svc-backup

That tells the session that those identities appear to have elevated access.

If svc-backup then shows up in a login attempt against another server, the earlier group query gives that later activity useful context.

Direct membership is not always the whole story

Permissions can come from:

  • direct group membership;
  • nested groups;
  • inherited rights;
  • delegated roles;
  • temporary role activation;
  • application permissions; or
  • local permissions on a particular resource.

So if the exact access level matters, try to establish the effective access at the relevant time, not just what one screen shows now.

A post-incident cleanup may also have changed the membership by the time you inspect it.

Preserve enough to follow the privilege

Useful things to keep include:

  • the query or API call;
  • the account and process that made it;
  • the group, role or resource being examined;
  • stable object or role IDs where available;
  • the returned membership or permission;
  • the time; and
  • any later activity using the discovered account or privilege.
Discoverysvc-backup appears in an admin groupThe session learns that the identity may have useful access.
SelectionThe account is targetedLater authentication uses the same identity.
UsePrivilege is exercisedTarget records show whether elevated access was actually used.

The distinction matters because discovering privilege is not the same as exercising it.

Compare it with expected administration

Identity teams, cloud administrators and security tools routinely inspect roles and memberships.

If the activity may be legitimate, compare it with the normal source system, account, maintenance activity and management platform.

The practical point is: permission discovery shows what access looked valuable or available. Use that result to follow the account, role or resource into the next records.

Reference: CIM-124Cyber Incidents & Offender Methods