Sensitive credentials
Credentials belong to a specific endpoint inside an engagement. Use this feature only for access material authorized for the assessment.Do not enter real credentials until the release owner confirms the real-data pilot is open. Never
put secrets in reports, findings, notes, support tickets, or attachment filenames.
Before you add a credential
- Confirm the credential is in scope and approved for this engagement.
- Create or verify the endpoint that owns the credential; endpoint selection is required.
- Use the narrowest account available and follow your customer’s rotation requirements.
Add a credential
1
Open the engagement
From Engagements, open the engagement detail page and find the credentials section.
2
Select Add Credential
Enter the username and password, then select the endpoint the account belongs to.
3
Save once
Strikepoint encrypts the password before storing it. After the page refreshes, the password is
represented as
********; the table does not render stored plaintext by default.Reveal a password
1
Select Reveal
Open the prompt for the one credential you need. Opening another prompt clears any secret that
was already displayed.
2
Enter your current Strikepoint password
The server verifies your identity again, checks permission and engagement scope, and applies the
login-attempt throttle before decrypting the selected secret.
3
Use the 30-second window
On success, only that password appears for 30 seconds. Select Hide sooner when finished. The
value is cleared and focus returns to the reveal control when the window closes.
If reveal fails
- Strikepoint returns the same Unable to reveal credential message for invalid passwords, missing permission, wrong engagement scope, unavailable records, or decryption/audit failure.
- Repeated wrong-password attempts use the login-attempt lockout. Stop retrying and wait for the lock period if you may be throttled.
- Confirm you are in the correct engagement and that your own login password works. Contact an Organization Manager or Owner if your permission is wrong.
- Do not ask support to send the secret or include it in a ticket.
Audit and handling
Successful reveals require an audit record before the password is returned. Denied reveals are also recorded on a best-effort basis. Audit metadata identifies the action and result; it must not contain your current password or the revealed secret. Treat a displayed password as sensitive even after Strikepoint re-masks it. Do not copy it into unapproved storage, screen captures, chat, or exported reports. Follow the customer’s rotation and incident process if exposure is suspected.Related routes covered by this guide
/dashboard/engagements/[engagementId]