Access Revocation
Definition
The removal of permissions, accounts, or trust relationships that the attacker exploited or could exploit. Distinct from credential rotation in that it removes the account or permission entirely rather than changing the secret.
- Action
- Remove permissions, accounts or trust relationships
- Distinct from
- Credential rotation (changing a secret)
- Phase
- Incident containment and hardening
- Scope
- Access the attacker exploited or could exploit
Common questions
How is this different from simply resetting a password?+
A password reset changes a secret on an account that still exists, while access revocation removes the account, role, or trust relationship itself so it can no longer be used at all.
Why revoke access instead of only rotating credentials?+
An attacker who set up persistence, such as an added SSH key or a rogue OAuth grant, can survive a credential rotation, so the underlying access must be removed as well.
When during incident response does access revocation typically happen?+
Usually during containment and hardening, after compromised access has been identified but before full recovery, to prevent the attacker regaining a foothold.
Related terms
- Attack Surface Reduction
- The systematic elimination of pathways an attacker could use to enter or move within a system. In incident response this includes closing...
- Compensating Control
- A security measure that reduces risk when the ideal control cannot be applied immediately. For example, routing traffic through a monitored proxy...
- Credential Rotation
- The process of invalidating and replacing passwords, API keys, certificates, and other authentication tokens that may have been exposed during an incident....
- Long-Term Containment
- The incident response phase in which emergency stabilisation measures are replaced with durable controls, such as patches, credential rotation, and firewall changes,...
- System Hardening
- Configuration changes that reduce a system's attack surface by disabling unnecessary services, applying least-privilege access, enabling audit logging, and removing or restricting...