Privileged Account Discovery
You cannot protect an account you do not know about. The AIC Enterprise Privilege Suite™ finds live systems on your network, the privileged accounts on each one, and every service, task, and file that depends on those accounts. Discovery rules then bring matching accounts under management, so rotation and propagation start from a complete inventory.
Short answers
What does AIC Enterprise Privilege Suite™ discover?
Live systems on IPv4 and IPv6 networks, systems in Active Directory and Lightweight Directory Access Protocol (LDAP) directories, local and domain accounts, privileged group members, service accounts and where they are used, Secure Shell (SSH) keys, cloud accounts and access keys, database accounts, and devices still using a known default credential.
Does it need an agent?
No. Discovery runs agentless over Windows Remote Management (WinRM) and SSH. The Agent is optional where an agent is preferred.
Can it reach networks the server cannot?
Yes. Discovery engines run inside each network zone or demilitarized zone (DMZ) and connect out to the server.
What happens to what it finds?
Discovery rules bring matching accounts under management automatically. Exclusion rules keep chosen accounts and systems out.
What AIC Enterprise Privilege Suite™ discovers
| What is found | How | Status |
|---|---|---|
| Live systems on IPv4 and IPv6 networks | ICMP, ARP, port scan, SMB, NetBIOS, SNMP, SSDP, HTTP, Redfish, and Telnet probes with device fingerprinting | Available now |
| Systems in the directory | Active Directory and LDAP, read over verified LDAPS | Available now |
| Windows accounts and privileged groups | Native Windows and WinRM | Available now |
| Linux, Unix, and macOS accounts and privileged groups | SSH | Available now |
| Password age and last sign-in | Password last set and last logon for each account | Available now |
| Service accounts and their dependencies | Windows services, scheduled tasks, IIS application pools, COM+ and DCOM applications, and configuration files | Available now |
| SSH keys and trust relationships | SSH key discovery on Linux, Unix, and Windows | Available now |
| Cloud accounts and access keys | Amazon Web Services Identity and Access Management (IAM), Microsoft Entra ID, Salesforce, Rackspace, and IBM Cloud Classic | Available now |
| Database accounts | Microsoft SQL Server, MySQL, Oracle, and PostgreSQL | Available now |
| Network devices and hardware management | Cisco, VMware ESXi, Redfish, Dell iDRAC, HPE iLO, IPMI baseboard management controllers, and Xerox devices | Available now |
| Known default credentials still in use | Signature match against licensed public dictionaries | Available now |
| Database instances running on a discovered host | Automatic instance discovery for SQL Server, MySQL, Oracle, and PostgreSQL | Planned |
| SSH certificates on targets | Certificate discovery on managed systems | Planned |
| Certificates across certificate authorities | Certificate lifecycle management | Planned |
Keep the inventory current
| Capability | Status |
|---|---|
| Discovery rules that bring matching accounts under management | Available now |
| Exclusion rules for accounts and systems | Available now |
| Targeted refresh of one system, one set, or one account type | Available now |
| Pruning accounts that no longer exist on the target | Available now |
| Retiring systems disabled or removed in Active Directory | Available now |
| Active Directory synchronization of users, groups, and computers | Available now |
Findings from discovery
Discovery results feed findings that show where risk sits, and each finding links to the fix.
| Finding | Status |
|---|---|
| Blast radius per credential: hosts and services that use it | Available now |
| One shared service account on five or more hosts | Available now |
| Domain Admin used as a service on a system that is not a domain controller | Available now |
| Service running as local Administrator | Available now |
| Unreviewed members of the local Administrators group | Available now |
| Stale administrator password | Available now |
| Known default credential in use | Available now |
See discovery on your network
Try AIC Enterprise Privilege Suite™ in the free cloud demo environment, or evaluate it on site for 30 days against your own systems.