We recently had an incident whereby a system was compromised. The SQL service on the system was running under our domain administrator account credentials. We are not sure if that account has it's password leaked but we want to be proactive and change the password.
The domain administrator account is used across many different servers in our organization for this purpose. If we change the password we will obviously cause all those services to fail their authentication.
My question is: Is there a tool that I can use that can scan a server or multiple servers to let me know exactly what accounts are used by services to authenticate?
Needless to say we will be using another account going forward.