Discovery using the Vault
Running Discovery using the Keeper Vault user interface
Overview
In this guide, you will learn how to discover resources within your target infrastructure using Discovery with the Keeper Vault and Desktop App.
Prerequisites
Prior to using Discovery, make sure to review the Discovery Basics documentation.
Discovery
From the Keeper Vault, click on the Discovery section. Click on "Create Discovery Job" to start a discovery process.

When discovery jobs are either running, failed, or completed states, the jobs will display on the Discovery screen.

Create a Discovery Job
To create a discovery job, select the Keeper Gateway which will perform the discovery. The Gateway is associated to a PAM Configuration, which tells the gateway what type of environment is being scanned.
If the PAM Configuration is lacking details about the environment such as CIDR or cloud secrets, the user is prompted to enter this information.

Discovery Rules
If prior discovery jobs have created discovery rules, the rules can be viewed and managed. A Discovery Rule saves time in the discovery process by ignoring certain findings. For example, if you want to ignore a certain resource.

Job Queue
Discovery jobs can be run in parallel across Keeper Gateways, but a single gateway can only run a single job at a time. If a job on a particular gateway is still running, you will receive an error message and you are giving the opportunity to cancel the job.

Process Results
After a discovery job is in a "Completed" state, clicking the Job will allow you to process the findings interactively. You can multi-select or iterate through the findings, and add the findings to a queue before it is finalized.

When iterating through the discovery results, you can either Ignore, Skip or Queue the result to the final batch of results.
Ignore: Skip the resource now and for future jobs, creating a Rule for this resource
Skip: Only skips the resource during this session, but will be found again in subsequent scans
Queue to Folder: Add the resource to the queue, and finalize all findings at the end
When iterating through the results, you can select the location in the vault where the resource will be stored, and you can immediately assign the Admin Credentials associated to the resource. The Admin Credentials which are linked to the resource server several purposes:
Finding user accounts: Subsequent discovery jobs will be able to use the Admin Credentials to remotely access the target resource and discover local user accounts.
Password Rotation: The Admin Credential is used for performing on-demand and scheduled password rotations on any found accounts.
Just-In-Time Access: Keeper JIT enables role and group elevation for the duration of privileged sessions.
Ephemeral Accounts: Keeper JIT capabilities include creation of temporary accounts under a certain role or group, for the duration of privileged sessions.
PAM Resources can have Connections and Tunneling activated to simplify the process of establishing access to the targets. PAM Users found during discovery can be enabled for automatic rotation.


Publish Found Resources
After processing through the findings, the queued resources can be published to the vault in the specified Shared Folder locations.

Next Steps
Now that the Discovery is complete, additional resources can be found by running another job against the same Gateway and PAM Configuration. If Admin Credentials have been linked to KeeperPAM Resources, these credentials will be used to discover local user accounts within each resource.
Last updated
Was this helpful?