Privileged Identity Management

Enterprises expect a privileged identity product to find their machines, find every credential on them, find everywhere each credential is used, and then take control: change the credential and update every place that uses it, without breaking the service. Analog Informatics Corporation (AIC) kits do that across operating systems, directories, databases, cloud accounts, network and hardware devices, applications, and web-managed devices.

Privileged Identity Management (PIM) is the credential side of privileged access: discovery, vaulting, rotation, and propagation of privileged and service credentials. Privileged Access Management (PAM) is the session side: Connect, Jump, and recording. See Capabilities.

Short answers

What does discovery find?

Systems on the network, the accounts on each system, membership in privileged groups such as local Administrators and Domain Admins, service accounts, SSH keys and the trusts they grant, cloud accounts and access keys, and credentials that match published vendor defaults.

Does it find old, abandoned, or unknown credentials?

Yes. Discovery records when each password was last set and when the account last signed in. Assessment rules flag stale administrator passwords, unreviewed members of privileged groups, credentials the kit does not manage, and known default passwords still in use.

Does it find where a credential is used?

Yes. For each credential the kit finds the Windows services, scheduled tasks, IIS application pools, and COM+ and DCOM applications that depend on it. When a change runs, it also updates SQL Server objects, ASP.NET connection strings, and the configuration files you add to the change plan.

What happens when it changes a credential?

The kit changes the password or key on the target, then updates every dependency in order: it stops the dependent services, writes the new credential into each one, and starts them again. A preview shows every step before anything changes.

What is a blast radius?

The set of systems and services affected if one credential is compromised. A domain account running services on 40 servers has a blast radius of 40 servers. The kit reports the blast radius of every shared credential, including group managed service accounts.

How is a blast radius reduced?

From the finding, rotate the shared credential and propagate it, or split it into one managed service account per host so a single compromise no longer reaches every server. Preview the plan, then apply it.

What about devices that only have a web page?

The browser automation engine signs in to the device's web management page and changes the credential the same way an administrator would. The kit ships ready-made automations, and you can build your own for any web-connected device.

What about a device or application with no built-in support?

Add it yourself, without waiting for a vendor connector. Use a browser automation for a web page, an SSH or Telnet script for a command line, or the REST API for anything that can call it. See Manage credentials on any platform.

How it works

  1. Discover - Find every system, account, and credential.
    Network scan, directory import, and cloud account discovery
    Local and domain accounts, privileged group members, service accounts
    SSH keys, cloud access keys, and known default passwords
    Password age and last sign-in, to expose abandoned and unknown credentials
  2. Map usage - Find where each credential is used.
    • Windows services, scheduled tasks, and IIS application pools
    • COM+ and DCOM applications
    • Add SQL Server, connection string, and configuration file dependencies to the change plan
  3. Assess blast radius - See what one compromised credential reaches.
    • Hosts and services per shared credential
    • Domain Admin used as a service, shared service accounts, stale passwords
    • Findings sorted by reach, with the owner shown
  4. Take control - Vault the credential and change it.
    • Operating systems, directories, databases, and cloud accounts
    • Network, hardware, and web-managed devices
    • Any other platform through a script, an automation, or the API
  5. Propagate - Push the new value everywhere it is used.
    • Services, tasks, IIS, COM+, DCOM, SQL Server, ASP.NET connection strings, and configuration files
    • Stop dependents, update each one, start them in order
    • Preview the full plan before anything changes
  6. Verify and record - Confirm the change and keep the evidence.
    • Sign-in verification on the target after the change
    • Every step written to the audit trail

Discover

What is foundHow
Live systems on IPv4 and IPv6 networksICMP, ARP, port scan, SMB, NetBIOS, SNMP, SSDP, HTTP, Redfish, and Telnet probes with device fingerprinting
Systems in the directoryActive Directory and LDAP
Windows accounts and privileged groupsNative Windows and WinRM
Linux, Unix, and macOS accounts and privileged groupsSSH
Password age and last sign-inAccount discovery records password last set and last logon
SSH keys and trust relationshipsSSH key discovery on Linux, Unix, and Windows, with rediscovery
Cloud accounts and access keysAmazon Web Services Identity and Access Management (IAM), Microsoft Entra ID, Salesforce, Rackspace, and IBM Cloud Classic
Database accountsMicrosoft SQL Server, MySQL, Oracle, and PostgreSQL
Known default credentialsSignature match against licensed public dictionaries. See Known default credentials
Network devices, servers, and hardware managementCisco, VMware ESXi, Redfish, Dell iDRAC, HPE iLO, IPMI baseboard management controllers, and Xerox devices
Database instances on a hostAutomatic discovery of SQL Server, MySQL, Oracle, and PostgreSQL instances running on a discovered system
CertificatesDiscovery and renewal of certificates across certificate authorities. See Capabilities

Find where each credential is used

Dependency

  • Windows services
  • Scheduled tasks
  • IIS application pools and IIS configuration files
  • COM+ applications and DCOM run-as identities
  • SQL Server objects that store the credential
  • ASP.NET connection strings
  • Any configuration file, by search and replace
  • A customer command or script run after a change
  • Hosts that use a group managed service account

Change and propagate

The kit changes the credential on the target and then pushes the new value to every dependency found above.

Target

  • Windows local and domain accounts
  • Linux, Unix, and macOS accounts
  • SSH key rotation
  • Active Directory and LDAP directories
  • SQL Server, MySQL, Oracle, and PostgreSQL
  • Amazon Web Services IAM, Microsoft Entra ID, Salesforce, Rackspace, and IBM Cloud Classic
  • Cisco network devices and VMware ESXi
  • Redfish, Dell iDRAC, HPE iLO, and IPMI baseboard management controllers
  • Any device or application with a web management page, through browser automation

Every change runs in order: stop dependents, change the credential, update each dependency, start dependents, then verify. A preview shows the full plan first. Each step is recorded in the audit trail.

Blast radius and remediation

Capability

  • Blast radius per credential: hosts and services that use it
  • Shared service account finding (one account on 5 or more hosts)
  • Domain Admin used as a service on a system that is not a domain controller
  • Service running as local Administrator
  • Unreviewed members of the local Administrators group
  • Stale administrator password
  • Known default credential in use
  • Rotate and propagate from the finding
  • Split a shared service account into one managed service account per host, with preview
  • Remediation plans generated for every auto-fixable finding at once

Some findings need IT action rather than a product change. The kit flags those so the owner can see them.

Manage credentials on any platform

Built-in support covers the platforms in the tables above. For everything else, three extension paths let you manage a device, application, or operating system as soon as you describe how to reach it. None of them needs a vendor software development kit or a product release.

PathUse it forHow it works
Browser automationDevices and services with a web management pageBuild a workflow in the console, test it on one device, publish it, and run it on the rest
SSH and Telnet scriptingSwitches, appliances, Unix variants, and applications with a command lineWrite a response file with send, expect, wait, set, log, and conditional steps. The kit fills in the account, the current password, and the new password at run time
Custom connection typesSystems reached through a jump host, a nonstandard port, or a tunnelDefine the connection once and assign it to systems or groups of systems
REST APIApplications, internal tools, and workflows that can call a web serviceEvery function is available through the REST API, described in OpenAPI

Browser automation for web-managed devices

Many devices and services are managed only through a web page: printers, storage arrays, hardware management controllers, network appliances, and software-as-a-service consoles. The kit drives a headless browser to sign in, find the credential field, change it, and confirm the result.

Capability

  • Ready-made automations: generic sign-in, generic password change, Dell iDRAC, HPE iLO, and Xerox
  • Ready-made automations to import accounts from other vault products
  • Visual workflow builder for customer-authored automations
  • JSON workflow editor, with draft and publish
  • Building blocks: navigate, click, type, sign in, read a value, take a screenshot, branch, and repeat
  • Execution history with the result of every step
  • Run one automation against as many web-connected devices as you manage

Customers start from a ready-made automation or build a new one in the console, test it against one device, publish it, and then run it on the rest.

How this compares

Competitors typically find dependencies from a fixed list of Windows services, scheduled tasks, and IIS application pools. Changing a credential on a web application or a non-standard device usually means writing a script or a plugin with a software development kit. Blast radius analysis is often a separate product.

AIC kits find and update a wider set of dependencies: they find COM+ and DCOM usage, and they also update SQL Server, ASP.NET connection strings, and configuration files. They change credentials on web-managed devices through automations built in the console, on command-line devices through SSH and Telnet scripts, and on anything else through the REST API. They report blast radius and offer the fix from the same finding.

See it on your use case

Request a demo