Means
Ability to Modify Cloud Resources
Access
Aiding and Abetting
Bluetooth
Bring Your Own Device (BYOD)
Clipboard
Corporate-Issued Device
Credential Access and Exposure
Delegated Access via Managed Service Providers
Enterprise-Integrated AI Platforms
FTP Servers
Installed Software
Media Capture
Network Attached Storage
Physical Disk Access
Placement
Printing
Privileged Access
Removable Media
Screenshots and Screen Recording
Sensitivity Label Leakage
SMB File Sharing
SSH Servers
System Startup Firmware Access
Unauthorized Access to Unassigned Hardware
Unmanaged Device Presence
Unrestricted Software Installation
Unrevoked Access
Web Access
- ID: ME027.005
- Created: 03rd August 2026
- Updated: 03rd August 2026
- Contributor: The ITM Team
Credentials in Documentation and Knowledge Bases
A subject can access credentials, tokens, keys, connection strings, or other authentication material recorded within internal documentation, runbooks, wikis, shared notes, or knowledge-management systems.
Credentials may have been added to support troubleshooting, maintenance, deployment, or operational handover, but remain available to a wider population than intended. Historical versions, attachments, comments, and exported copies may continue to expose the material after it has been removed from the visible document.
Access to these repositories may allow a subject to obtain authentication material without being formally granted access to the system or account it protects.