Findings
Generator
Configuration
Lucidum Reverse
Architecture
Statistics
← All Findings
Vendor:
CyberArk Endpoint Privilege Manager
FIN-783
Weight:
5
4
3
2
1
Confidence:
High
Medium
Low
Edited:
2026-03-27 16:18
Not Verified
What It Detects
A server-class endpoint has a disconnected CyberArk EPM agent. Servers present higher risk than workstations when EPM protection lapses: they run critical services, store sensitive data, are typically accessible from multiple network segments, and operate continuously. A disconnected agent on a server means privilege elevation policies, application control, and audit logging are not functioning on infrastructure that may host databases, file shares, or domain services.
MITRE ATT&CK Techniques
Comma-separated, e.g. T1078, T1190
Checks
read-only
Field
Operator
Value
Connectors
equals
CyberArk
Status
equals
Disconnected
Asset Type
equals
Server
Remediation
×
×
×
×
+ Add item
Why It Matters
+ Add item
Save Changes
Export Lucidum