Digital Identity Explained
What session tokens, refresh tokens, cookies, API keys, and wallet keys actually are, why attackers target them, and how Cyber Crucible's kernel behavioral engine protects them without ever reading them.
Do you collect any of identity data?
The short answer is no, we do not.The longer answer, is, no we do not, but i...
How Is This Different Than Normal Identity Monitoring?
Cyber Crucible’s digital identity theft capability is proactive and preventa...
What identity data is protected?
Core Windows Operating SystemNTDS (Active Directory)Incubating feature that ...
How is identity data protected?
Short answer: Cyber Crucible identifies the locations where identity data is stored and protects ...
What cryptocurrency wallets are protected?
CoinomiArmory (“Bitcoin Armory”)ElectrumExodusGuarda ...
What happens when a program tries to access identity data it shouldn't?
Short answer: It depends on whether the program is trusted and whether it has been compromised. A...
What is a session token, and why is stealing one worse than stealing a password?
Short answer: A session token is the credential your browser or app holds after you log in, provi...
What is a refresh token, and why is losing one especially damaging?
Short answer: A refresh token is a long-lived credential used to silently obtain new access token...
What are browser cookies, and how do attackers abuse them?
Short answer: Cookies are small pieces of data a website stores in your browser, and some of them...
What is an API key, and what happens if one is stolen?
Short answer: An API key is a secret string that identifies and authorizes a program — rather tha...
Where does Windows store passwords and credentials?
Short answer: In several predictable places — the Windows Credential Manager, browser password st...
What are cryptocurrency wallet keys, and why is theft irreversible?
Short answer: A wallet key is the private cryptographic key that authorizes spending from a crypt...
What is key-based authentication, and why do stolen keys grant lasting access?
Short answer: Key-based authentication proves identity with a cryptographic private key instead o...
Why does protecting identity data require kernel-level access?
Short answer: Because the theft happens in the space between a program requesting credential data...