Cortex XDR - Windows Event per collect tool

Cortex XDR - Windows Event per collect tool

9994
Created On 01/19/21 08:28 AM - Last Modified 04/23/24 00:17 AM


Question


Which events are been collected by each tool?

Environment


  • XDR agent - Utilizing Endpoint Detection and Response (EDR) data collection
  • Broker VM (BVM) - Windows Event Collector applet (WEC)
  • Windows Active Directory


Answer


Broker VM WEC applet - event IDs list:
Event categoryEvent DescriptionEvent ID
SecurityKerberos authentication protocol4768
SecurityKerberos service ticket request4769
SecurityKerberos service ticket renew4770
SecurityKerberos pre- authentication failed4771
SecurityThe computer attempted to validate the credentials for an account4776
SecurityAn account was successfully logged on4624
SecurityAn account was successfully logged off4634
SecurityA logon was attempted using explicit credentials4648
SecuritySpecial privileges assigned to new logon4672
SecurityA user account was created4720
SecurityA user account was enabled4722
SecurityAn attempt was made to change an account's password4723
SecurityAn attempt was made to reset an account's password4724
SecurityA user account was disabled4725
SecurityA user account was deleted4726
SecurityA user account was changed4738
SecurityA user account was locked out4740
SecurityA user account was unlocked4767
SecurityThe ACL was set on accounts which are members of administrators groups4780
SecurityThe name of an account was changed4781
SecurityAn attempt was made to set the Directory Services Restore Mode administrator password4794


Important Notes:

  • By default the WEC applet collects the above event IDs. To collect all the events, navigate to the Configuration > Data Broker > BrokerVM > WEC config page and select all the sources.
  • WEC configuration on Cortex XDR should be aligned with the DC configuration
EDR data - event IDs list is available by official document Endpoint Data Collected by Cortex XDR Endpoint Data Collection.


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HCQHCA4&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language