Updated on 2026-09-10 GMT+08:00

Enabling and Viewing Credential Leakage Detection

DSC scans public repositories and blogs (such as GitHub) as well as authorized cloud storage (such as OBS buckets) for exposed Huawei Cloud credentials, including AKs (AccessKey IDs and AccessKey Secrets) and other credential information. It detects leaked credentials across OBS buckets, databases, big data platforms, and LTS, and reports alarms. View and handle credential leakage alarms in a timely manner.

Constraints

To use credential leakage detection, you must use a primary account or a user with the Security Administrator permission.

Prerequisites

You have purchased the DSC professional edition.

Enabling Credential Leakage Detection

  1. Log in to the DSC console.
  2. Click in the upper left corner and select a region or project.
  3. In the navigation pane on the left, choose Data Security Operations > Credential Leakage Detection.
  4. Click Enable Credential Leakage Detection. In addition, create a service agency with the Security Administrator role to query the user AK list and user list.
  5. If the switch under Enable Function is toggled on, the function has been enabled, as shown in Figure 1.

    Figure 1 Authorized credential leakage detection

Viewing Credential Leakage Alarms

  1. Log in to the DSC console.
  2. Click in the upper left corner and select a region or project.
  3. In the navigation pane on the left, choose Data Security Operations > Credential Leakage Detection.
  4. View the leaked credential information and risky credential list. Table 1 describes the parameters in the list.

    The system regularly monitors the leakage of three types of sensitive credentials: access keys (AKs), IAM accounts, and custom credentials. The monitoring covers four leakage channels: Internet, OBS, databases, and log storage. The monitoring data of the last 30 days is displayed.
    Figure 2 Credential leakage
    Table 1 Risky credential information

    Parameter

    Description

    Risky Credential

    Risky credential name.

    Credential Type

    Credential type, which can be:

    • IAM account
    • Access Key

    Credential Owner

    Credential owner username.

    Risk Source

    ID of the asset that contains files or data with leakage risks.

    Risk Object Path

    Path of the risky object.

    First Scan

    Time when the first scan is performed.

    Last Scan

    Time when the last scan is performed.