> Source: [sk183363](https://support.checkpoint.com/results/sk/sk183363)

# sk183363 - How to understand and Export Corporate Credentials Alerts on ERM

| Property | Value |
|----------|-------|
| Solution ID | sk183363 |
| Date Created | 2025-05-11 |
| Last Modified | 2025-05-11 |
| Technical Level | General |
| Products | External Risk Management |
| Versions | Cloud |

## Solution

This guide provides a concise overview of how to investigate credential exposure alerts, interpret associated metadata, and export relevant information for internal analysis or remediation workflows. It is structured to proactively address typical user concerns and investigative needs.  

**Understanding the Alert Structure**   

Each credential exposure alert represents a unique username and password combination that has been observed in a third-party source, typically from underground forums, stealer logs, or open-source breaches.  

**Deduplication Logic:**   

Alerts are deduplicated per username + password pair. If the same combination appears across different platforms or domains, the alert aggregates all relevant entities under a single entry.  

**Related Entities Field:** This field lists all platforms or services where the credentials were identified. These are not usage logs or login attempts, but exposure points where the credentials were observed in data dumps or logs.  

**Temporal Behavior:** Alerts are not grouped by date or time. If credentials reappear in future dumps or contexts, a new alert may be generated depending on visibility and matching thresholds.  

**Source-Specific Metadata:** Alerts from malware logs or stealer logs may include enriched metadata such as:  

* IP address
* Locale or keyboard configuration
* Operating system username
* Related emails (often corporate + personal)

**User Attribution \& Verification**   

The alert system does not tie exposed passwords directly to usage behavior on the related platforms. It reflects exposure --- not confirmed activity. Determining whether a password was actually used on a platform (or reused internally) requires internal investigation.  

Recommended Verification Workflow:  

* Leverage internal access logs, SIEM, or identity monitoring tools.
* Filter by exposed usernames or compare password hash patterns.
* Investigate potentially high-risk behavior such as reuse across personal and corporate services.

<br />

**Exporting Alert Data**   

Credential exposure data can be exported easily for bulk analysis or ticketing system integration.  

* Navigate to the alert dashboard.
* Select alerts individually or in bulk.
* Use the Export Data function to generate a CSV file.

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk183363/Image_2025-04-15_10-14-17 (1)202505091449263.png)  

**The exported file includes:**   

* Username
* Password (plain or masked, based on policy)
* URLs or platforms where the pair was observed

This enables rapid correlation and triage without parsing raw logs manually.  

**Alert Sources \& Coverage**   

Credential exposure alerts may originate from multiple modules:  

* **ASM (Attack Surface Monitoring):**

Surfaces exposures linked to domains and subdomains tied to your organization's attack surface.  

* **Threat Intelligence (TI):**

Highlights exposures observed in broader threat actor operations, breach collections, or credential marketplaces.  

ERM deduplicates alerts within each stream but may present similar exposures across modules if seen in different contexts or times.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
