- Notifications
You must be signed in to change notification settings - Fork 818
Description
Is your feature request related to a problem? Please describe.
Increase our ZT coverage in the People pillar
Describe the solution you'd like
If the Monkey managed to breach to a server using user creds, it will try to run an anomalous behaviour module as that user. This requires the Monkey to know which cred pairs belong to users and which are "system" creds, which will probably require a small configuration change (small checkbox next to usernames maybe?). The module can do several things, like #827 or just a few requests to Monkey Island - something that's 100% not that user's job.
ZT info:
- Pillars: People, Visibility
- Principle: Adopt security user behavior analytics.
Describe alternatives you've considered
Just adding this as a use case for the documentation and not as a streamlined part of the ZT report is obviously easier (no development).