[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fc06vnxJnGLNAwSvPN5I_A751DtsEcIBSHIS0q0hY6LQ":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":44},"c6aaba06-7c44-4085-96aa-b7f913fdb2c3","ghost-credentials-dormant-non-human-identities-create-hidden-cloud-attack-paths","195c70e8-ec8b-47ec-add9-dba0eebd97c5","Ghost Credentials: Dormant Non-Human Identities Create Hidden Cloud Attack Paths","Organizations accumulate non-human identities (NHIs) — such as service accounts, API keys, and automation tokens — that are provisioned but never properly decommissioned, leaving 'ghost credentials' that remain valid and exploitable long after their intended use. Because these identities are rarely monitored or reviewed, attackers who discover them can leverage established trust relationships to move laterally or escalate privileges within cloud environments without triggering standard detection controls. The core failure is the absence of a systematic identity lifecycle management process that treats NHIs with the same rigor applied to human user accounts. This matters because cloud environments scale NHI proliferation rapidly, making manual tracking impractical and dramatically expanding the attack surface if no automated discovery tooling is in place.","**Immediate actions:**\n- Conduct an urgent audit of all non-human identities (service accounts, API keys, OAuth tokens) across every cloud environment to identify dormant or unmanaged credentials.\n- Deploy an open-source or commercial NHI discovery tool (e.g., NHI Hound) to surface ghost credentials that fall outside existing IAM visibility.\n- Revoke or rotate any NHI credential that cannot be attributed to an active, documented business purpose.\n\n**Long-term improvements:**\n- Implement a formal NHI lifecycle management policy that mandates provisioning approval, periodic re-certification, and automatic expiration for all non-human identities.\n- Enforce least-privilege principles for every NHI so that credentials carry only the minimum permissions required for their specific function.\n- Integrate NHI inventory into your CMDB or identity governance platform to ensure continuous visibility as environments scale.\n\n**Detection measures:**\n- Enable cloud-native audit logging (e.g., AWS CloudTrail, Azure Monitor, GCP Audit Logs) and alert on authentication events from NHIs that have not been active within a defined threshold (e.g., 90 days).\n- Establish behavioural baselines for NHI activity and trigger anomaly alerts when credentials are used from unexpected regions, services, or at unusual times.\n- Schedule quarterly automated scans to detect newly orphaned credentials introduced through infrastructure changes or developer activity.",[12,13,14,15,16,17,18,19,20,21,22,23],"CIS Control 5: Account Management","CIS Control 6: Access Control Management","CIS Control 8: Audit Log Management","NIST SP 800-53 AC-2: Account Management","NIST SP 800-53 AC-3: Access Enforcement","NIST SP 800-53 IA-4: Identifier Management","NIST SP 800-53 AU-6: Audit Record Review, Analysis, and Reporting","NIST CSF PR.AC-1: Identities and credentials are managed for authorized devices and users","NIST CSF DE.CM-3: Personnel activity is monitored to detect potential cybersecurity events","ISO\u002FIEC 27001:2022 A.5.16: Identity Management","ISO\u002FIEC 27001:2022 A.8.2: Privileged Access Rights","GDPR Article 32: Security of Processing (access control obligations)","published","2026-07-29T00:21:06.064236+00:00","2026-07-29T00:21:05.946+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fwww.darkreading.com\u002Fcloud-security\u002Fnon-human-identity-sprawl-creates-a-new-cloud-attack-path","ghost-credentials-expose-cloud-systems-to-hidden-identity-risks-331be8","Ghost Credentials Expose Cloud Systems to Hidden Identity Risks",[32,38],{"id":33,"name":34,"slug":35,"description":36,"color":37},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":39,"name":40,"slug":41,"description":42,"color":43},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",[]]