Qualys ETM Identity Accelerates Detection of Credential‑Based Attacks Across Enterprise Environments
What Happened — Qualys announced enhancements to its EnterpriseTruRisk Platform (ETM) Identity module that automatically surface risky identities, map AD trust relationships, and prioritize attack paths such as Pass‑the‑Hash, Kerberoasting, DCSync, and AS‑REP Roasting. The solution unifies identity posture, exploitability, and asset context into a single risk model to shorten detection and response times for identity‑based intrusions.
Why It Matters for Compliance & Audit Readiness
- Credential compromise is a core focus of SOC 2 CC6.1 (Logical Access); continuous identity‑risk scoring provides the audit evidence required to demonstrate effective access‑control monitoring.
- Mapping risky identities to business impact aligns with the SOC 2 “risk‑based” approach and supplies defensible documentation for control testing.
- Automated remediation workflows generate traceable tickets, satisfying the “monitoring and response” criteria of the SOC 2 Trust Services Criteria.
Who Is Affected – Enterprises that rely on Active Directory, Microsoft Entra ID, or hybrid cloud directories; sectors with high‑value data such as finance, healthcare, and SaaS providers.
Recommended Actions
- Align your logical‑access controls (SOC 2 CC6.1) with an identity‑risk scoring framework.
- Integrate continuous identity‑posture data into your audit‑ready evidence repository.
- Validate that privileged‑access reviews incorporate automated alerts from an ISPM solution.
Source: Qualys Blog – How Qualys ETM Identity Detects Identity‑Based Attacks Faster
Technical Notes – The blog references AD‑specific techniques (Pass‑the‑Hash, Kerberoasting, DCSync, AS‑REP Roasting) and highlights the prevalence of stale accounts, over‑permissive trusts, and unmanaged machine identities as attack enablers. No new CVEs are disclosed. Source: same as above