Skip to content

Global Search Default Table Columns

This reference provides a complete overview of the system columns available in the Global Search table. Each entity type (Owners, Accounts, Groups, Roles) has its own set of default columns optimized for that data type.

Overview

Global Search columns fall into three categories:

  1. System Columns: Core entity attributes collected from platforms (Platform, Name, Email, Status, etc.)
  2. Threat Rule Columns: Columns generated from default Threat Rules and custom threat rules
  3. Custom Columns: Organization-specific columns from custom threat rules or extended attributes

NOTE

Each row in the Global Search tables offers click-through to the entity details page for that specific entity, providing comprehensive information about relationships, threat analysis, and historical data.


Owners Tab Columns

The Owners tab displays individual identities with aggregated data from all mapped accounts.

Default Columns

ColumnDescriptionTypeNotes
Owner NameThe name under which the identity owner was establishedStringPrimary identifier; click to open Owner Details
Owner EmailPrimary email address associated with the ownerStringUsed for account mapping and contact
Mapped AccountsNumber of accounts mapped to this ownerIntegerExpandable chevron shows account list
Total ThreatAggregated risk level for this owner from all mapped accountsScoreHigher scores indicate greater risk

Accounts Tab Columns

The Accounts tab displays individual user accounts, service accounts, and federated identities discovered across all connected systems.

Default Columns

ColumnDescriptionTypeNotes
PlatformSystem platform from which the account was collectedStringE.g., Azure AD, Active Directory, Okta, AWS
Data SourceCollector module that retrieved the account dataStringData source name configured in Hydden
TypeAccount type classificationStringUser, Service, Federated, Discovered, or Vaulted
Display NameEstablished display name for the accountStringTypically FirstName LastName format
Account NameName under which the account was initially createdStringPrimary account identifier on the platform
EmailEmail address associated with the accountStringUsed for owner mapping
Total ThreatRisk level indicator for this accountScoreAggregate of all applicable threat rules
StatusAccount statusStringEnabled, Disabled, Locked, Expired, etc.

Groups Tab Columns

The Groups tab displays security groups, distribution lists, and role groups with membership information.

Default Columns

ColumnDescriptionTypeNotes
Group PlatformSystem platform on which this group was discoveredStringE.g., Azure AD, Active Directory, Okta, AWS
Data SourceCollector module that retrieved the group dataStringData source name configured in Hydden
Group NameGroup name as established in the directory serviceStringPrimary group identifier
Group Display NameGroup display nameStringFriendly name for the group
Direct Member CountNumber of direct members in the groupIntegerAccounts explicitly added to the group
Expanded Member CountNumber of expanded (nested) membersIntegerIncludes direct members plus members from nested groups

Roles Tab Columns

The Roles tab displays cloud roles, application roles, and permission sets with assignment counts.

Default Columns

ColumnDescriptionTypeNotes
Role PlatformSystem platform from which the role data was collectedStringE.g., Azure, AWS, GCP
Data Source NameCollector module that retrieved the role dataStringData source name configured in Hydden
DomainDomain associated with the roleStringCloud tenant or account identifier
ProviderRole providerStringAzure, AWS, GCP, etc.
NameRole name as used in the role providerStringPrimary role identifier
Direct Role CountNumber of accounts with this specific role assignmentIntegerExplicitly assigned accounts
Expanded Role CountNumber of accounts with this role due to inheritanceIntegerIncludes direct assignments plus inherited roles

Threat Rule Columns

Threat rule columns appear across all tabs based on default and custom threat detection rules. For a complete list, see Default Threat Rules.

Common Threat Rule Columns include:

  • Privileged Account(s) - Entity has elevated privileges
  • Password 90+ Days, Password 180+ Days - Password age exceeds thresholds
  • Password Never Set - No password set since account creation
  • MFA Not Enabled, MFA Status N/A - MFA configuration status
  • Stale Account 90+ Days, 180+ Days, 365+ Days - No login activity
  • More Than 5/10/20/25 Failed Login Attempts - Failed authentication attempts
  • Breached Account(s), Breached Account(s) High Risk - Found in breach databases
  • Group(s) 500+ - Member of 500+ groups
  • No Owner, Shared Account, Shared Account+ - Mapping status
  • Highly Privileged Group(s), Highly Privileged Role(s) - Elevated permissions

Custom threat rules created by your organization will automatically appear as additional columns.


Column Features

Sorting

  • Click column header once for ascending sort (A-Z, 0-9, oldest-newest)
  • Click again for descending sort (Z-A, 9-0, newest-oldest)
  • Click third time to remove sorting
  • Shift+Click additional columns for multi-column sorting

Filtering

Each column supports filtering based on data type:

  • Text Filter: Contains, Equals, Starts with, Ends with
  • Number Filter: Equals, Greater than, Less than, Between
  • Set Filter: Select multiple values (checkboxes)
  • Date Filter: Before, After, Between dates

Column Customization

Use the Columns panel to show/hide, reorder, pin, or search for columns. Preferences are saved per user in browser local storage.


Additional Columns

Beyond the default columns, many additional attributes are available via the Columns panel:

Common Additional Columns:

  • User Principal Name, Domain, Short Domain
  • Description, Classification
  • Created date, Last Logon, Last Logon Age
  • Password Changed, Password Age
  • MFA Count, Pending MFA Count
  • Is Privileged (0-10 scale)
  • Failed Logon Count
  • Object SID, Object GUID (Active Directory)
  • Employee ID, Job Title, Department, Manager
  • PAM Status, Vault/Safe (for vaulted accounts)

Platform-specific columns are also available for attributes unique to Azure AD, AWS, Okta, Linux, and other platforms.


Hydden Documentation and Training Hub