Insider Threat Matrix™Insider Threat Matrix™
  • ID: PR044.005
  • Created: 05th August 2026
  • Updated: 05th August 2026
  • Contributor: The ITM Team

Application, Service, and Shared Account Discovery

A subject identifies or enumerates accounts maintained within an individual application or accounts used by services, integrations, automation, scheduled processes, or multiple authorized individuals.

 

The subject may review application administration pages, account directories, configuration files, deployment definitions, service documentation, scripts, database records, secrets-management metadata, or account inventories to identify application users, service accounts, integration identities, shared accounts, account owners, or associated privileges.

 

These accounts may be attractive because they can hold broad access, operate without interactive oversight, or provide weaker attribution than a personally assigned identity. Discovery may support later credential collection, unauthorized application access, misuse of automation, persistence, or concealment through a non-personal identity.

 

Investigators should determine how the account information was obtained, whether the subject had an operational requirement to view it, which account types were targeted, and whether discovered identities were later used interactively or outside their documented purpose.