The "Stolen Keys" Principle

S

What is The "Stolen Keys" Principle?

The "Stolen Keys" Principle in cybersecurity is an identity and access management doctrine stating that adversaries rarely breach technical perimeters with complex exploits when they can simply log in with legitimate, stolen credentials.

The principle asserts that the modern enterprise security perimeter has shifted from network boundaries and software codebases to identity and authentication systems. Rather than investing significant time and capital developing zero-day exploits or bypassing web application firewalls, threat actors obtain valid human credentials, session tokens, and Non-Human Identities (NHIs) to access enterprise environments under the guise of authorized users. Once inside, an attacker using legitimate keys generates little to no abnormal signature traffic, rendering traditional signature-based intrusion detection systems largely ineffective.

Core Categories of "Keys" Targeted by Adversaries

In modern cloud, hybrid, and software-as-a-service (SaaS) environments, the "keys" targeted by cybercriminals extend well beyond basic usernames and passwords:

  • Human User Credentials: Plaintext or hashed combinations of usernames, corporate email addresses, and passwords harvested via credential stuffing, password spraying, or adversary-in-the-middle (AitM) phishing.

  • Active Session Tokens and Cookies: Stolen authentication cookies (such as OAuth tokens, SAML assertions, and browser session cookies) extracted by infostealer malware, which allow threat actors to bypass Multi-Factor Authentication (MFA) by directly hijacking authenticated sessions.

  • Non-Human Identities (NHIs) and Machine Secrets: Programmatic authentication mechanisms used by software to communicate with other services, including cloud access keys, service account credentials, Application Programming Interface (API) tokens, and private SSH keys.

  • Cryptographic Certificates and Signing Keys: Private TLS/SSL certificates and code-signing keys that enable adversaries to decrypt sensitive network traffic, spoof internal infrastructure, or sign malicious binaries to bypass endpoint execution controls.

  • Webhook and CI/CD Pipeline Secrets: Access tokens embedded in continuous integration and continuous deployment (CI/CD) configuration scripts, repository environment variables, and build automation workflows.

How Threat Actors Acquire Stolen Keys

Adversaries use automated, scalable reconnaissance and harvesting techniques to acquire corporate authentication keys:


  • Dark Web Infostealer Logs: Malicious infostealer strains (such as RedLine, Lumma, and Vidar) infect employees' personal computers or unmanaged endpoints, vacuuming up stored browser credentials, active session cookies, cryptocurrency wallets, and VPN configuration files, which they then package and sell on dark web marketplaces.

  • Public Code and Repository Leaks: Developers and third-party contractors accidentally commit source code, configuration files (such as .env, docker-compose.yml, or AWS credentials files), and infrastructure-as-code scripts containing hardcoded API tokens and private keys to public repositories like GitHub, GitLab, and Bitbucket.

  • Adversary-in-the-Middle (AitM) Reverse Proxies: Attackers set up deceptive lookalike portals using tools like Evilginx to intercept employee credentials and session tokens in real time, capturing the session cookie immediately after the user completes MFA.

  • Exposed Cloud Storage and Misconfigured Buckets: Unprotected cloud object storage containers (such as AWS S3 buckets or Azure Blobs) often contain unencrypted database dumps, backup archives, and application configuration files that house machine keys.

  • Third-Party Vendor and Supply Chain Breaches: Compromising a software vendor, marketing agency, or SaaS integration partner allows attackers to harvest shared API keys, federated tokens, and trusted partner credentials to pivot into the primary enterprise target.

Why Traditional Defenses Fail Against Stolen Keys

The "Stolen Keys" Principle explains why conventional, perimeter-centric security models struggle to stop identity-driven intrusions:

  • Absence of Malicious Signatures: When an adversary presents a valid API key or session token, internal security controls—such as Network Intrusion Detection Systems (NIDS) and Web Application Firewalls (WAFs)—interpret the traffic as legitimate business activity.

  • MFA Bypass via Session Hijacking: While Multi-Factor Authentication prevents simple credential replay, it does not protect against stolen session tokens. If an attacker acquires an active browser cookie from an infostealer log, the authentication step is already completed, granting immediate access without triggering an MFA prompt.

  • Lack of Visibility into Non-Human Identities: Traditional Identity and Access Management (IAM) tools focus primarily on human user directories. Programmatic service accounts, long-lived API tokens, and webhook keys often lack lifecycle governance, automated rotation policies, and contextual anomaly monitoring.

  • The "Living off the Land" Advantage: Attackers armed with stolen credentials use native administrative tools (such as PowerShell, Azure CLI, or AWS Management Consoles) rather than custom malware, blending their behavior into baseline operational noise.

Defensive Strategies: Mitigating the "Stolen Keys" Risk

Neutralizing the threat of stolen credentials requires shifting from reactive network defense to continuous identity exposure governance:

  • Continuous Secret and Repository Surveillance: Automatically scan public code repositories, paste sites, and developer forums to identify and revoke accidentally committed corporate secrets, API keys, and machine tokens within minutes of exposure.

  • Dark Web and Infostealer Monitoring: Monitor underground marketplaces, breach databases, and infostealer telemetry to detect compromised employee credentials and active session tokens before adversaries use them for initial access.

  • Enforce Strict Machine Identity Governance: Treat Non-Human Identities with the same rigor as human identities. Eliminate long-lived static API tokens, enforce short-lived ephemeral credentials, and mandate automated secret rotation using centralized vaults.

  • Implement Phishing-Resistant MFA and Token Binding: Transition from SMS or push-based MFA to FIDO2/WebAuthn hardware security keys that bind credentials to the cryptographic origin of the authentic site, neutralizing AitM reverse-proxy phishing.

  • Behavioral Identity Anomaly Detection: Deploy User and Entity Behavior Analytics (UEBA) to identify impossible travel scenarios, anomalous API call sequences, atypical access times, and sudden privilege escalations executed by otherwise valid accounts.

Frequently Asked Questions

Why do cybercriminals prefer using stolen keys over software exploits?

Using stolen keys is significantly faster, cheaper, and more reliable than developing or purchasing zero-day software exploits. Logging in with valid credentials completely bypasses network firewalls and endpoint security tools without generating malicious exploit signatures.

What is the difference between a stolen credential and a stolen session token?

A stolen credential typically consists of a username and password, which may still be blocked by a Multi-Factor Authentication (MFA) challenge. A stolen session token is a cryptographic cookie generated after successful authentication (including MFA), allowing an adversary to bypass the MFA prompt entirely and access the account directly.

How does the "Stolen Keys" Principle relate to Zero Trust architecture?

The "Stolen Keys" Principle serves as a foundational justification for Zero Trust. Because any incoming connection might use stolen credentials, Zero Trust dictates that no user or machine account is implicitly trusted based on network location or key possession. Instead, access must be continuously authenticated, authorized, and validated based on contextual telemetry.

Immediate Actionable Verification Checklist

  1. Audit Public Code Repositories for Corporate Secrets: Run automated scans across public GitHub, GitLab, and Bitbucket profiles linked to internal developers to verify no hardcoded API keys or credentials exist.

  2. Review Long-Lived Cloud Access Keys: Inspect all AWS IAM, Azure Service Principal, and GCP Service Account keys; identify and revoke any programmatic keys older than 90 days or lacking automated rotation.

  3. Check Dark Web Infostealer Feeds for Enterprise Logins: Query threat intelligence archives to identify whether corporate email domains or single sign-on (SSO) credentials appear in recent infostealer botnet logs.

  4. Enforce Ingress Controls on Exposed Management Panels: Verify that administrative portals, remote desktop interfaces, and cloud consoles require corporate VPN access or phishing-resistant MFA, not static passwords alone.

  5. Establish an Immediate Credential Revocation Workflow: Ensure your identity team has an automated, one-click mechanism to instantly invalidate active session tokens and force password resets for compromised accounts across all connected SaaS applications.

Operationalizing The "Stolen Keys" Principle with ThreatNG

The "Stolen Keys" Principle in cybersecurity is an identity and access management doctrine stating that adversaries rarely break through technical perimeters using complex exploits when they can simply log in using legitimate, stolen credentials. The modern enterprise security perimeter has shifted from network boundaries and software codebases to identity and authentication systems. Rather than investing significant time and capital developing zero-day exploits or bypassing web application firewalls, threat actors obtain valid human credentials, session tokens, and Non-Human Identities (NHIs) to access enterprise environments under the guise of authorized users. Once inside, an attacker using legitimate keys generates little to no abnormal signature traffic, rendering traditional signature-based intrusion detection systems largely ineffective.

Enterprises face the Contextual Certainty Deficit because conventional internal security tools operate from the inside out. Defensive controls—such as Network Intrusion Detection Systems (NIDS), internal Identity and Access Management (IAM) governance tools, and Web Application Firewalls (WAFs)—rely on internal telemetry and signature matching. They assume that any request authenticated with a valid key, API token, or session cookie is benign. They remain blind to external adversary harvesting operations: employee credentials traded in dark web infostealer logs, machine secrets leaked on public code repositories, and adversary-in-the-middle (AitM) phishing portals capturing session cookies in real time.

ThreatNG operationalizes defense against the "Stolen Keys" Principle by functioning as an unauthenticated external scout. Unifying External Attack Surface Management (EASM), Digital Risk Protection (DRP), and continuous Security Ratings into a single platform, ThreatNG discovers, evaluates, categorizes, and monitors an enterprise’s complete public digital perimeter alongside adversary staging infrastructure from an outside-in, adversary-centric perspective. It correlates exposed machine secrets, stolen credentials, and public authentication portals into deterministic attack paths via DarChain, evaluates weaponization probability through its 4-Dimensional (4D) Data Model, and delivers Legal-Grade Attribution without requiring internal software agents, Application Programming Interface (API) access keys, or administrative credentials.

External Discovery

Defending against stolen credentials and machine tokens requires an automated, outside-in discovery tier that can identify every external authentication interface, exposed secret, and lookalike harvesting domain across public infrastructure without prior internal knowledge. ThreatNG establishes this inventory baseline through connectorless external discovery.

  • Non-Human Identity (NHI) and Leaked Secret Discovery: ThreatNG continuously discovers exposed programmatic machine identities, API tokens, cloud access keys, and webhook secrets across the public web. It monitors public version control systems (such as GitHub, GitLab, and Bitbucket), paste sites, and public cloud environments to uncover machine keys inadvertently committed by internal developers or third-party contractors.

  • Connectorless Asset and Perimeter Discovery: ThreatNG maps the entire public-facing digital footprint using unauthenticated discovery with zero internal connectors, software agents, or network credentials. It evaluates public domain registries, authoritative Domain Name System (DNS) zone files, Secure Sockets Layer/Transport Layer Security (SSL/TLS) certificate transparency logs, Regional Internet Registry (RIR) databases, and global Border Gateway Protocol (BGP) routing tables to catalog every legitimate public IP block, subdomain, cloud environment, and Single Sign-On (SSO) web application.

  • Algorithmic Permutation Discovery for Credential Harvesters: ThreatNG automatically computes, generates, and evaluates mathematical permutations of corporate domain names (typosquatting, combosquatting, and homoglyphs). It categorizes permutations into taken or available, mapping resolving IP addresses, authoritative nameservers, ASNs, and active Mail Exchange (MX) records to uncover adversary staging infrastructure designed to harvest employee credentials via AitM reverse proxies before phishing campaigns launch.

  • Third-Party Dependency and SaaS Mapping (SaaSqwatch): ThreatNG evaluates public digital exhaust—such as DNS Canonical Name (CNAME) routing chains, Hypertext Transfer Protocol (HTTP) headers, and SSL/TLS certificates—to discover third-party Software as a Service (SaaS) platforms, cloud tools, and external service providers used across business units. This reveals where third-party systems bridge internal corporate data with external suppliers, exposing supply chain trust relationships susceptible to stolen key replay.

  • Decentralized and Web3 Domain Discovery: Beyond traditional DNS registries, ThreatNG identifies taken and available Web3 domains across decentralized naming platforms (such as Ethereum Name Service/ENS and Unstoppable Domains), uncovering decentralized brand-hijacking attempts before deceptive phishing frontends resolve.

  • Subsidiary and Extended Ecosystem Scoping: Because ThreatNG operates without internal credentials or vendor permissions, organizations can execute unauthenticated discovery across operating subsidiaries, joint ventures, prospective acquisition targets (M&A due diligence), and supply chain partners, determining where partner organizations leak credentials that provide federated access to the primary enterprise.

External Assessment

ThreatNG elevates the evaluation of stolen identities and exposed secrets from passive notifications to deterministic, evidence-backed assessment using its Known Vulnerability Exposure Verification (KVEV) engine, proprietary Security Ratings, and 4-Dimensional (4D) Data Model. The 4D model cross-references National Vulnerability Database (NVD) baselines, 30-day Exploit Prediction Scoring System (EPSS) probabilities, Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) listings, and verified Proof-of-Concept (PoC) exploit code in DarCache eXploit.

  • Detailed Assessment Example 1: Non-Human Identity (NHI) Exposure Assessment: ThreatNG evaluates external exposure variables—including open non-standard ports, accessible environment variables, public cloud configurations, and unvetted webhook endpoints—to locate exposed programmatic machine identities. It identifies exposed API keys, service principal tokens, and cloud access credentials, computing an NHI Exposure Rating (A through F). If a public repository contains a valid AWS secret key tied to production infrastructure, ThreatNG calculates the blast radius across connected cloud storage buckets and administrative interfaces, showing how an attacker can bypass perimeter firewalls using valid programmatic access.

  • Detailed Assessment Example 2: BEC & Phishing Susceptibility Assessment (Credential Harvesting Infrastructure): ThreatNG’s Domain Intelligence module calculates a dedicated A through F BEC & Phishing Susceptibility score. The engine inspects taken permutation domains for newly configured MX records and evaluates whether threat actors have activated mail delivery capabilities. If a taken lookalike domain configures MX records pointing to high-volume mail services while lacking restrictive Sender Policy Framework (SPF) or DMARC authentication, ThreatNG flags the domain as an active pre-weaponization vector staged to harvest employee keys via AitM reverse proxies.

  • Detailed Assessment Example 3: Web Application Hijack Susceptibility on Authentication Gateways: ThreatNG evaluates web applications hosted across corporate subdomains for missing security controls and exposed administrative routes. It calculates an A through F Web Application Hijack Susceptibility score based on external web components, verifying whether exposed single sign-on (SSO) gateways or administrative panels lack multi-factor authentication enforcement or expose session management weaknesses that permit session hijacking.

  • Detailed Assessment Example 4: Data Leak Susceptibility on Exposed Cloud Buckets: ThreatNG evaluates public cloud storage instances across AWS S3, Azure Blob, and Google Cloud Storage for unauthenticated read and write permissions. It assigns an A through F Data Leak Susceptibility rating to identify open cloud buckets containing configuration files, database backups, or deployment scripts with database credentials and API keys, and flags where static keys are exposed directly to the internet.

  • Detailed Assessment Example 5: Cyber Risk Exposure and Infrastructure Hosting Verification: ThreatNG analyzes the IP infrastructure hosting external assets. It evaluates shared hosting blocks, ASNs, geolocation, and neighboring domains to determine whether exposed corporate portals reside on hosting infrastructure exhibiting high exposure to threat actor scanning networks, adjusting the Cyber Risk Exposure score accordingly.

Strategic Reporting

ThreatNG standardizes the communication of identity exposures and stolen key risks by converting raw outside-in telemetry, infrastructure graphs, and technical exposure metrics into structured, auditable records for technical practitioners, executive leadership, and compliance auditors.

  • Executive Security Ratings Reports: ThreatNG converts complex vulnerability metrics, exposed configurations, and digital risk indicators into standardized A through F security ratings across categories including Non-Human Identity (NHI) Exposure, Cyber Risk Exposure, Data Leak Susceptibility, and Supply Chain & Third Party Exposure. This enables Chief Information Security Officers (CISOs) to present empirical identity risk trends and secret reduction metrics directly to corporate boards.

  • Correlation Evidence Questionnaires (CEQs): ThreatNG dynamically generates Correlation Evidence Questionnaires based on confirmed external discovery and assessment results. The CEQ acts as an EASM-to-Audit Translation Layer, transforming unauthenticated outside-in discoveries—such as exposed API tokens and unmonitored authentication portals—into targeted, auditable inquiries mapped directly to regulatory frameworks across four functional pillars: Technical, Strategic, Operational, and Financial.

  • External Adversary View and Framework Mapping Reports: ThreatNG automatically correlates raw external discoveries—such as exposed APIs, unmanaged cloud storage, open database ports, and leaked secrets—directly into strategic narratives aligned with MITRE ATT&CK for enterprise IT and MITRE ATLAS for AI/ML systems. This contextualizes technical indicators into specific tactical stages (such as Credential Access, Initial Access, and Lateral Movement), giving CISOs the evidence-based business context needed to brief executive boards on how attackers use valid credentials rather than exploits.

  • U.S. SEC Cybersecurity Disclosures Report: The report aligns an organization's public regulatory filings (such as Form 10-K Item 106 and Form 8-K Item 1.05 disclosures) with the verifiable technical reality of its external attack surface. It connects compromised identity markers and material credential leaks directly to corporate filings, eliminating disclosure disconnects and protecting corporate officers from regulatory penalties.

  • Forensic Evidence Packages for Rapid Invalidation: When ThreatNG discovers an exposed machine secret, an open cloud database credential, or an active phishing domain harvesting keys, it generates a detailed forensic evidence package containing technical markers, commit timestamps, file paths, repository URLs, DNS resolution histories, and HTTP response headers to support immediate key revocation and administrative action.

Continuous Monitoring

Because developers push code continuously and infostealer malware extracts session cookies 24/7, identity exposures occur in seconds. ThreatNG delivers 24/7 continuous external surveillance across the extended digital footprint.

The platform tracks code repository commits, newly registered lookalike domains, modified DNS records, fresh certificate issuances, and dark web credential dumps in real time. If a developer inadvertently commits a configuration file containing an API token or an adversary deploys a lookalike login page, ThreatNG detects the event immediately. Furthermore, ThreatNG incorporates its Overwatch capability—a cross-entity vulnerability intelligence system that instantly evaluates exposure across an entire portfolio of subsidiaries, business units, and supply chain partners whenever it identifies an emerging credential dump or zero-day authentication flaw, alerting security operations within seconds.

Investigation Modules

ThreatNG features specialized investigation modules that allow security analysts to investigate discovered infrastructure, trace developer leaks, and evaluate the full intelligence context of exposed authentication keys.

  • Detailed Module Example 1: Sensitive Code Exposure Module: ThreatNG continuously monitors public code repositories (such as GitHub, GitLab, and Bitbucket) and paste sites for leaked corporate secrets. This module uncovers hardcoded API keys, private SSH keys, Jenkins credentials, AWS access tokens, and database connection strings committed by internal developers or third-party contractors. The module provides exact repository URLs, commit timestamps, and file paths, allowing security analysts to isolate the exact commit that introduced the exposed key and initiate revocation before threat actors exploit it.

  • Detailed Module Example 2: Dark Web Presence and Infostealer Intelligence: Operating through its dark web intelligence modules, ThreatNG continuously monitors underground marketplaces, paste sites, and infostealer malware logs for compromised corporate credentials, session cookies, and corporate mentions. This module discovers active authentication exposures—such as employee passwords and browser session tokens extracted by malware strains like RedLine or Lumma—enabling security teams to invalidate hijacked sessions before adversaries use them to bypass multi-factor authentication (MFA).

  • Detailed Module Example 3: The DarChain Exploit Path Mapping Engine: DarChain (Digital Attack Risk Contextual Hyper-Analysis Insights Narrative) chains isolated technical, credential, and environmental discoveries into predictive attack graphs. For example, DarChain maps how an attacker discovers an exposed cloud storage bucket, extracts an unencrypted configuration file containing a service account key, and uses that key to authenticate to an internal production database. DarChain pinpoints the critical Attack Path Choke Point—such as the exposed machine secret—proving that revoking that specific key collapses the entire adversarial narrative.

  • Detailed Module Example 4: Subdomain Infrastructure Exposure Module: Operating within Subdomain Intelligence, this module actively inspects discovered subdomains for exposed administrative interfaces, developmental pipelines, and automated tools. It detects exposed orchestration frameworks (including Langflow, self-hosted n8n, AnythingLLM, LM Studio, LiteLLM, Ollama, OpenAI Compatible APIs, and Clawdbot/Moltbot), vector databases (QDrant, Milvus, local Pinecone, and DuckDB), and Model Context Protocols (MCP), identifying administrative endpoints where attackers use default or stolen credentials to gain remote execution.

  • Detailed Module Example 5: Cybersecurity AI Prompts (DarcPrompt): DarcPrompt packages verified identity-exposure context and attack-path findings into structured prompt blueprints. Featuring specialized personas—such as External Attack Paths, Shadow IT and AI, and External GRC Assessment—DarcPrompt applies strict architectural constraints that bind the prompt to ThreatNG's proprietary ground truth. Through an Air-Gapped Handoff, security analysts safely copy these blueprints into their internal private enterprise AI systems to draft secret rotation playbooks, IAM policy updates, and executive summaries without exposing sensitive asset data to public AI services.

Intelligence Repositories

ThreatNG centralizes and structures threat intelligence through the DarCache intelligence engine, providing an interconnected dynamic ecosystem that grounds identity protection in empirical adversary reality:

  • DarCache Infostealer: Parses dark web logs for compromised corporate credentials and active browser session tokens, helping teams determine which enterprise portals, SaaS tools, or employee identities have suffered token theft and neutralizing MFA-bypass attempts.

  • DarCache Dark Web & Rupture: Scans underground forums, paste sites, and dark web sources for threats to brand assets and personnel, while tracking compromised corporate credentials, session cookies, and data leaks across all domain permutations.

  • DarCache Vulnerability & eXploit: Integrates NVD baselines, CISA KEV listings, 30-day EPSS probabilities, and verified PoC exploit pointers to evaluate whether servers hosting authentication portals or connected enterprise gateways have weaponizable software flaws.

  • DarCache Ransomware: Tracks active ransomware cartels and their tactics, techniques, and procedures (TTPs), monitoring whether threat actors use compromised credentials to target specific industry sectors or subsidiary brands.

  • DarCache Bug Bounty: Aggregates and analyzes historical bug bounty program disclosures, researcher activity trends, and crowdsourced exploit patterns to evaluate public perimeter assets under scrutiny by external researchers.

  • DarCache Mobile: Detects hardcoded access credentials, security keys, and platform-specific identifiers within public mobile applications, discovering embedded API keys that communicate with cloud backends.

  • DarCache 8-K & ESG: Tracks SEC Form 8-K filings, global ESG violations, and corporate regulatory disclosures, providing non-technical governance indicators that connect digital identity risks directly to financial materiality, board oversight, and legal exposure.

  • DarCache BIN: Monitors Bank Identification Numbers (BINs) to identify and prevent potential payment card fraud across digital transactional and e-commerce assets.

Cooperation with Complementary Solutions

ThreatNG functions as an external intelligence scout that cooperates seamlessly with complementary solutions across enterprise governance, risk, and security operations to neutralize stolen keys.

  • Cooperation with Identity and Access Management (IAM) and Secrets Vaults: ThreatNG passes verified leaked Non-Human Identities (NHIs), API tokens, and private keys discovered in public code repositories directly to complementary solutions (enterprise IAM platforms and secrets management vaults). The IAM platform immediately invalidates the affected credentials, revokes active session tokens, and triggers automated secret rotation, closing the access window before adversaries use the key.

  • Cooperation with Security Orchestration, Automation, and Response (SOAR): ThreatNG delivers pre-correlated Context Objects and DarChain attack paths to complementary solutions (enterprise SOAR platforms) via an API. When ThreatNG detects a corporate login credential or active session token in an infostealer log, the SOAR platform executes automated containment playbooks—forcing an immediate password reset, revoking all active OAuth session cookies across connected SaaS applications, and opening a high-priority incident ticket in Jira.

  • Cooperation with Secure Email Gateways (SEGs) and Protective DNS Resolvers: ThreatNG continuously discovers taken lookalike domains, typosquats, and homoglyphs with active MX records staged to harvest employee keys. It feeds these indicators directly into complementary solutions (SEGs, protective DNS resolvers, firewalls, and Secure Web Gateways) to block outbound employee resolution and quarantine incoming phishing emails before employees enter their credentials into AitM reverse proxies.

  • Cooperation with Security Information and Event Management (SIEM) and XDR: ThreatNG passes external identity exposures, leaked credentials, and targeting telemetry to complementary solutions (enterprise SIEM and XDR platforms). SOC analysts use this intelligence to correlate internal authentication logs with ThreatNG's external indicators, immediately flagging successful logins from known infostealer-compromised accounts or impossible geographical locations.

  • Cooperation with Cyber Asset Attack Surface Management (CAASM) and CMDBs: ThreatNG feeds external asset inventories, newly discovered subdomains, and shadow cloud infrastructure into complementary solutions (CAASM platforms and CMDBs). IT and asset management teams use this feed to reconcile external discoveries against internal records, ensuring that all deployed web assets, cloud buckets, and domain names have assigned owners and documented decommissioning procedures.

Examples of ThreatNG Helping Organizations

  • Revoking Leaked Production Cloud Keys Before Exploitation: An external software development contractor committed a deployment script to a public GitHub repository. The script contained a hardcoded AWS IAM secret key with administrative privileges over the organization's primary production cloud account. ThreatNG’s Sensitive Code Exposure module discovered the commit within minutes, identifying the exact repository URL, file path, and key string. ThreatNG assigned an F Non-Human Identity (NHI) Exposure score and generated an emergency alert. The security team invalidated the key in AWS IAM and rotated the credentials, preventing threat actors from using legitimate administrative keys to access production infrastructure.

  • Neutralizing AitM Phishing Infrastructure Harvesting SSO Keys: ThreatNG’s Domain Name Permutations capability discovered a newly registered combosquatted domain (company-sso-login.com) configured with active MX records and a freshly provisioned Let's Encrypt SSL/TLS certificate. ThreatNG’s assessment revealed an AitM reverse proxy cloning the corporate Okta portal designed to harvest usernames, passwords, and multi-factor authentication session cookies. ThreatNG assigned an F score for BEC & Phishing Susceptibility and generated a forensic evidence package. The security team blocked the domain across perimeter gateways and submitted an expedited registrar takedown request, neutralizing the harvesting infrastructure before it targeted employees.

Examples of ThreatNG Working with Complementary Solutions

  • Working with IAM and SOAR to Invalidate Compromised Infostealer Sessions: ThreatNG’s DarCache Infostealer repository identifies active browser session cookies and corporate VPN credentials belonging to a senior system administrator circulating in a recent dark web log archive. ThreatNG transmits a pre-correlated Context Object to complementary solutions (an enterprise SOAR platform). The SOAR system automatically triggers API commands to complementary solutions (the enterprise IAM platform and identity provider) to revoke all active browser sessions, terminate current VPN connections, and enforce a mandatory hardware-backed MFA re-authentication, preventing an adversary from bypassing MFA via session replay.

  • Working with SIEM and Protective DNS to Stop Credential Harvesting: ThreatNG discovers a taken homoglyph domain mimicking an internal payroll portal. ThreatNG passes the canonical Punycode domain to complementary solutions (protective DNS resolvers and an enterprise SIEM). The protective DNS resolver automatically blocks internal resolution to the domain, while the SIEM queries historical web proxy logs to identify whether any employees previously clicked the link, allowing the SOC to isolate two workstations and reset credentials before unauthorized transactions occurred.

Frequently Asked Questions

How does ThreatNG discover stolen credentials and leaked keys without internal network access?

ThreatNG operates entirely as an unauthenticated external scout. It continuously monitors public code repositories (GitHub, GitLab), paste sites, dark web marketplaces, infostealer botnet archives, and public cloud object storage across the open internet, discovering exposed credentials and machine secrets the same way an external threat actor does.

Why is monitoring Non-Human Identities (NHIs) critical to stopping the "Stolen Keys" Principle?

Non-Human Identities (such as API keys, service principal tokens, and cloud access secrets) rarely have multi-factor authentication enabled and frequently maintain elevated, cross-environment permissions. If an adversary obtains an exposed API key from a public repository, they can authenticate directly to cloud infrastructure, execute commands, and exfiltrate data while appearing as legitimate automated software traffic.

How does ThreatNG cooperate with complementary security platforms during an identity exposure event?

ThreatNG acts as an external intelligence scout, feeding pre-correlated Context Objects, verified secret exposures, and DarcPrompt blueprints directly into complementary solutions like IAM platforms, secrets vaults, SIEMs, SOAR engines, and protective DNS firewalls to drive automated credential revocation, session termination, and perimeter blocking.

Immediate Actionable Verification Checklist

  1. Conduct Continuous Code Repository Secret Surveillance: Deploy ThreatNG’s Sensitive Code Exposure module across all corporate brands, domains, and developer handles to discover exposed API keys, private SSH tokens, and database passwords.

  2. Review the Non-Human Identity (NHI) Exposure Rating: Inspect ThreatNG’s dedicated A through F NHI rating and technical penalty breakdown to identify exposed machine secrets across cloud environments.

  3. Audit Infostealer Intelligence Archives: Query ThreatNG’s DarCache Infostealer repository to determine whether employee session cookies, browser passwords, or VPN configurations appear in recent dark web botnet logs.

  4. Deploy Context Objects into Automated Revocation Workflows: Configure the delivery of pre-correlated external secret findings into complementary SOAR playbooks and IAM vaults to automate credential invalidation and session termination.

  5. Inspect Lookalike Permutations for AitM Reverse Proxies: Review taken, combosquatted, and typosquatted domains with active MX records and SSL certificates to neutralize credential-harvesting portals before phishing messages reach employees.

Previous
Previous

SLA Theater

Next
Next

The WAF Band-Aid