Use case · Service accounts

AI agents reuse service accounts. Find the ones that open the domain.

Many agents do not get an identity of their own. They run on an existing service account, cloud role or API key, and inherit everything that identity could already do. The agent is new. The access is years old.

EXAMPLE PATHPath risk High
cron agentAI agent
ScheduleNightly
Own identityNo
backup-writerIdentity
Used by3 agents
Key age14 months
OwnerOffboarded
prod roleRole
BucketWrite, delete
CloudAWS
prod backupsProd
DeletableYes
VersioningOff
2 steps from a cron agent
cron agent can delete production backupsThrough backup-writer and the prod role · 2 stepsCriticalShow fix
THE PROBLEM

Why service accounts decide the impact

In the PaperCut campaign, hundreds of AI agents exploited print servers at 395 organisations. Where the software ran as a domain-admin service account, the attacker needed no further exploit to take the domain. In the retail campaign Gambit reconstructed, one database identity could read card data, create tables and drop backups. The exploit opened the door. The service account decided how far the attacker got.

395
organisationshit by AI agents in the PaperCut campaign. Where it ran as domain admin, the domain fell with it.
$25
a companyin the retail campaign Gambit reconstructed.
1
service accountdecided how far the attacker got. The exploit only opened the door.
WHAT ELMOZ SHOWS

What Elmoz shows for service accounts and roles

Five questions Elmoz answers for every service account, role and key an agent runs on.

01Which agents run on which identity

Including identities shared by several agents or services.

cron agent
backup-writer
Shared by 3 agents
02What each identity can reach

Roles, group memberships and data stores, traced as paths.

backup-writer
prod backups
Write, delete
03Who owns it

Service accounts whose owners have left are flagged.

Owner
Left the company
04Credential age and exposure

Keys that have not rotated in months and where they are stored.

Key age
Last rotated 14 months ago
05The smallest safe change

Scope a role, split a shared identity or rotate a key, with the impact shown first.

Remove delete
Backups keep running
THE FIX

The smallest safe change. Impact shown first.

Scope a role, split a shared identity or rotate a key, with the impact shown first.

Recommended actionsbackup-writer
Remove delete on the backup bucketCloses the path, backups keep runningSafe
Split the shared identityEach agent gets its own accountSafe
Rotate the keyThree agents need the new keyDisruptive
Apply fixCreate ticketPaths closed: 1
SHARED IDENTITIES

One identity, three agents.

When several agents or services use one identity, compromising any of them gives the attacker the combined access. The agent is new. The access is years old.

cron agentNightly
report agentFinance
sync agentCRM sync
backup-writerOne shared identity

An example path

The agent is new. The access is years old. Three agents share one service account whose role can delete the production backups. Elmoz shows the shared identity and the reach in one view.

Security GraphFocus: cron agentAll assetsIdentitiesData stores
ATTACK PATH3 agents on one identity · 2 access steps
cron agentAI agent · nightlyreport agentSame usersync agentSame user3!backup-writerService accountawsprod-accountAWS account!OwnerLeft the companyaws!prod-backup roleWrite and delete3Findings3 issuesProd backupsS3 bucketDatabase dumpsCustomer dataConfig exportsSecrets inside
FAQ

Questions, answered.

Short answers on agents that run on existing service accounts and roles.

Do AI agents need their own identity?

They should have one. When an agent reuses an existing service account or key, it inherits all of that identity's access and its actions cannot be told apart from the original service.

How do I find over-privileged service accounts?

Trace what each service account can reach, not only which roles it has. Look first at identities that reach production data, domain admin groups or backups, and at identities without a current owner.

What is a shared identity risk?

When several agents or services use one identity, compromising any of them gives the attacker the combined access. Splitting the identity limits the blast radius.

See what your agents can reach. Before someone else does.

Book a demo and we walk through the access paths in an environment like yours.