US 12,225,002 B2
Enriching exposed credential search results to make them actionable
Michael Christopher Fanning, Redmond, WA (US); Suvam Mukherjee, Allston, MA (US); Jacek Andrzej Czerwonka, Sammamish, WA (US); Christopher Michael Henry Faucon, Redmond, WA (US); Eddy Toshiyuki Okada Nakamura, Redmond, WA (US); Danielle Nicole Gonzalez, LeRoy, NY (US); Nicolas Yves Couraud, Westwood, MA (US); and Alison Lynne Maclellan, Renton, WA (US)
Assigned to Microsoft Technology Licensing, LLC, Redmond, WA (US)
Filed by Microsoft Technology Licensing, LLC, Redmond, WA (US)
Filed on Oct. 17, 2022, as Appl. No. 17/967,113.
Prior Publication US 2024/0129293 A1, Apr. 18, 2024
Int. Cl. G06F 21/00 (2013.01); H04L 9/40 (2022.01)
CPC H04L 63/083 (2013.01) 17 Claims
OG exemplary drawing
 
1. A method for (i) using contextual information associated with an exposed credential to identify a resource that could be accessed using the exposed credential, (ii) identifying a responsible entity of that resource, and (iii) alerting the responsible entity about the exposed credential, said method comprising:
identifying a credential that is located within an artifact;
determining that the credential is in an exposed state such that the credential is an exposed credential, wherein the exposed credential, if used, could potentially provide access to a resource;
analyzing one or more of the exposed credential or the artifact to determine a context that is associated with the exposed credential;
based on the context that is associated with the exposed credential, identifying the resource;
determining a responsible entity that is associated with the resource;
triggering transmission of an alert, wherein the alert includes information corresponding to the exposed credential;
periodically querying to determine whether the exposed credential has been invalidated;
in response to a determination that the exposed credential has not been invalidated, providing a subsequent alert; and
in response to a determination that the exposed credential has already been invalidated, finalizing actions related to remediation of the exposed credential.