Skip to content

If logged onto a server with user credentials, simulate anomalous behaviour as that user #832

@ShayNehmad

Description

@ShayNehmad

Is your feature request related to a problem? Please describe.
Increase our ZT coverage in the People pillar

Describe the solution you'd like
If the Monkey managed to breach to a server using user creds, it will try to run an anomalous behaviour module as that user. This requires the Monkey to know which cred pairs belong to users and which are "system" creds, which will probably require a small configuration change (small checkbox next to usernames maybe?). The module can do several things, like #827 or just a few requests to Monkey Island - something that's 100% not that user's job.

ZT info:

  • Pillars: People, Visibility
  • Principle: Adopt security user behavior analytics.

Describe alternatives you've considered
Just adding this as a use case for the documentation and not as a streamlined part of the ZT report is obviously easier (no development).

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions