Updated on 2026-07-27 GMT+08:00

Enabling and Viewing Credential Leakage Detection

DSC scans public repositories and blogs (such as GitHub) as well as authorized cloud storage (such as OBS buckets) for exposed Huawei Cloud credentials, including AKs and other credential information. It detects leaked credentials across OBS buckets, databases, big data platforms, and LTS, triggers real-time alarms, and provides actionable remediation steps. View and handle credential leakage alarms in a timely manner.

Constraints

To use credential leakage detection, you must use a primary account or a user with the Security Administrator permission.

Prerequisites

You have purchased the DSC professional edition.

Enabling Credential Leakage Detection

  1. Log in to the DSC console.
  2. Click in the upper left corner and select a region or project.
  3. In the navigation pane on the left, choose Data Security Operations > Credential Leakage Detection.
  4. Click Enable Credential Leakage Detection. In addition, create a service agency with the Security Administrator role to query the user AK list and user list.
  5. If the switch under Enable Function is toggled on, the function has been enabled, as shown in Figure 1.

    Figure 1 Authorized credential leakage detection

Viewing Credential Leakage Alarms

  1. Log in to the DSC console.
  2. Click in the upper left corner and select a region or project.
  3. In the navigation pane on the left, choose Data Security Operations > Credential Leakage Detection.
  4. View the credential leakage information, as shown in Table 1.

    Table 1 Risky credential information

    Parameter

    Description

    Risky Credential

    Risky credential name.

    Credential Type

    Credential type, which can be:

    • IAM account
    • Access Key

    Credential Owner

    Credential owner username.

    Risk Source

    ID of the asset that contains files or data with leakage risks.

    Risk Object Path

    Path of the risky object.

    First Scan

    Time when the first scan is performed.

    Last Scan

    Time when the last scan is performed.