Skip to content

Default Threat Rules

This article provides an overview of the default threat detection rules available to all Hydden customers. Rules are organized by category, with each category contributing up to 10 points to the total threat score.

Hydden's threat rules page

Each rule can be specified to be shown in Reports or Posture. By default both options are checked on all default threat rules.

Privilege

NameDescriptionScoreDefault StateDetection OnlyFramework
Highly Privileged Group(s)Groups for which privileges have not been trimmed.5EnabledNo
Highly Privileged Role(s)Roles for which privileges have not been trimmed.5EnabledNo
All Privileged GroupsFlags all accounts that are members of any privileged group.10EnabledYes
Privileged Accounts Not VaultedPrivileged accounts that are not managed by a vault solution.10EnabledNo

Password & Security

NameDescriptionThresholdScoreDefault StateDetection OnlyFramework
Accounts with MFA Not EnabledAccounts for which MFA has not been enabled.8EnabledNo
Accounts with Password Never SetAccounts for which a password was never set up.10EnabledNo
Accounts with Password 90+ DaysAccounts with a password age of 90 or more days.90+5EnabledNo
Accounts with Password 180+ DaysAccounts with a password age of 180 or more days.180+4EnabledYes
Accounts with Password 365+ DaysAccounts with a password age of 365 or more days.365+4EnabledYes

Account Activity

NameDescriptionThresholdScoreDefault StateDetection OnlyFramework
Accounts not used in 90+ DaysFlags all accounts that have been stale for 90+ days.90+ days10EnabledNo
Accounts not used in 180+ DaysFlags all accounts that have been stale for 180+ days.180+ days3EnabledYes
Accounts not used in 275+ DaysFlags all accounts that have been stale for 275+ days.275+ days4DisabledNo
Accounts not used in 365+ DaysFlags all accounts that have been stale for 365+ days.365+ days5EnabledYes
Accounts with 10+ Failed Login Attempts in 1 HourFlags accounts with more than 10 failed login attempts in one hour.10+10EnabledNo
Accounts with 5+ Failed Login AttemptsFlags accounts with more than 5 failed login attempts.5+6DisabledNo
Accounts with 20+ Failed Login AttemptsFlags accounts with more than 20 failed login attempts.20+8DisabledNo
Accounts with 25+ Failed Login AttemptsFlags accounts with more than 25 failed login attempts.25+9DisabledNo

Breaches

NameDescriptionScoreDefault StateDetection OnlyFramework
Account Password Not Changed Since Public BreachFlags accounts identified in a breach where the password change date is unknown or older than the breach date.10EnabledNo
Breached Account(s)Flags accounts identified in a public data breach.10EnabledYes

Group Membership

NameDescriptionThresholdScoreDefault StateDetection OnlyFramework
Group(s) 500+Detects accounts with memberships in excessively large groups.500+2DisabledNo
Account Group Deviation (Z-Score)Identifies accounts with group membership outside the standard distribution. See Z-Score.5EnabledNoNIST CSF V2.0 / PR.AA-05

Owner Mapping

NameDescriptionScoreDefault StateDetection OnlyFramework
Accounts with No OwnerAlerts to accounts without owner designation.8EnabledNo
Shared AccountAlerts to an account that is shared with another user.5EnabledNo
Shared Account+Alerts to an account that is shared with more than one other user (3+ owners).10DisabledNo
Inactive Owners With Enabled AccountsFlags accounts mapped to inactive owners that remain enabled.10EnabledYes

Special Rules

NameDescriptionScoreDefault StateDetection OnlyAlertRepeatableFramework
CyberArk OnboardingDetects privileged accounts eligible for CyberArk vault onboarding.10DisabledYesYesYes

Default Aggregation Rules

Aggregation rules combine matched threat rules into category totals and a final account-level threat score.

CategoryNameDescriptionMax Score
Total CalculationAccount Activity (Total)Aggregates all Account Activity rule matches10
Total CalculationAccount Statistics (Total)Aggregates all Account Statistics rule matches10
Total CalculationBreach Data (Total)Aggregates all Breach rule matches10
Total CalculationExpired Accounts (Aggregated)Aggregates expired account data10
Total CalculationGroup Membership (Total)Aggregates all Group Membership rule matches10
Total CalculationOwner Mapping (Total)Aggregates all Owner Mapping rule matches10
Total CalculationPassword & Security (Total)Aggregates all Password & Security rule matches10
Total CalculationPrivilege (Total)Aggregates all Privilege rule matches10
Total CalculationTotal ThreatCombines all 8 category totals into a single score (0–100)100

NOTE

The Total Threat aggregation method defaults to Totals Average but can be configured as Maximum or Weighted Average. Contact Hydden Support to learn more about which setting to use for your specific needs.

Hydden Documentation and Training Hub