Identity

Service Account

A service account is a technical account used by applications and services to access systems and data.

A service account is a technical account that is used by applications, services or scripts and does not belong to any person. It allows systems to authenticate with each other.

How it works

Applications often require access to databases, file shares or interfaces. For this purpose, they receive a dedicated account with the necessary permissions. In Windows environments, these are service accounts in Active Directory. In the cloud, they are service principals, managed identities or API keys. These accounts typically log in automatically without MFA and with passwords that seldom change.

For example, a backup service runs using an account with domain admin rights. Its password was set eight years ago and is stored in a script. An attacker finds the script on a server. Using this account, they compromise the entire Active Directory. The SOC detects the service account's interactive login, which never occurs during normal operation.

What to look out for

  • Create an inventory of all service accounts, including their purpose and owners.
  • Grant only the permissions that the service requires.
  • Use managed service accounts with passwords that rotate automatically.
  • Prohibit interactive logins for service accounts.
  • Never store credentials in plain text in scripts or configuration files.

Why it matters

Service accounts often possess extensive permissions and are rarely reviewed. They are therefore popular targets for attackers. Many organisations have more technical accounts than employees.

Detection

Service accounts behave very regularly. Deviations are therefore easy to detect. A login from a new system or at an unusual time is a strong signal.

Typical mistakes

Often, nobody knows the purpose of an old service account anymore. It is not deactivated for fear of causing an outage. A second mistake is using cloud keys without an expiry date, which can end up in code repositories.

How we implement it

We monitor service accounts for deviations from normal behaviour, such as new source systems or interactive logins. We treat any anomalies as a high-priority Case.

How ANOMAL implements this