<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alert for each time a usb device is plugged in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-for-each-time-a-usb-device-is-plugged/m-p/476889#M1796</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Multiple analytics alerts track USB activities that do not require BrokerVM&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/content/techdocs/en_US/cortex/cortex-xdr/cortex-xdr-analytics-alert-reference/cortex-xdr-analytics-alert-reference/a-user-connected-a-usb-storage-device-to-a-host-for-the-first-time.html#a-user-connected-a-usb-storage-device-to-a-host-for-the-first-time" target="_self"&gt;&lt;SPAN&gt;A user connected a USB storage device to a host for the first time&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/content/techdocs/en_US/cortex/cortex-xdr/cortex-xdr-analytics-alert-reference/cortex-xdr-analytics-alert-reference/a-user-connected-a-new-usb-storage-device-to-a-host.html#a-user-connected-a-new-usb-storage-device-to-a-host" target="_self"&gt;&lt;SPAN&gt;A user connected a new USB storage device to a host&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/content/techdocs/en_US/cortex/cortex-xdr/cortex-xdr-analytics-alert-reference/cortex-xdr-analytics-alert-reference/a-user-connected-a-new-usb-storage-device-to-multiple-hosts.html#a-user-connected-a-new-usb-storage-device-to-multiple-hosts" target="_self"&gt;&lt;SPAN&gt;A user connected a new USB storage device to multiple hosts&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;But you are correct, configuring the BrokerVM &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/broker-vm/set-up-broker-vm/activate-the-windows-event-collector.html" target="_self"&gt;Windows Event Collector&lt;/A&gt; would allow you to specify collection for event IDs 6416 &amp;amp; 4719&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 30 Mar 2022 13:26:34 GMT</pubDate>
    <dc:creator>jtalton</dc:creator>
    <dc:date>2022-03-30T13:26:34Z</dc:date>
    <item>
      <title>Alert for each time a usb device is plugged</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-for-each-time-a-usb-device-is-plugged/m-p/476304#M1770</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;Is there any way to set up an alert for each time a USB device is plugged into a host?&lt;BR /&gt;Even if it's not malicious.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Mar 2022 13:42:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-for-each-time-a-usb-device-is-plugged/m-p/476304#M1770</guid>
      <dc:creator>JoaoSantos20</dc:creator>
      <dc:date>2022-03-28T13:42:05Z</dc:date>
    </item>
    <item>
      <title>Re: Alert for each time a usb device is plugged</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-for-each-time-a-usb-device-is-plugged/m-p/476469#M1772</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you looking for USB device plugin alert or alert on activity such as File operation, execution operation via removable media?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;USB Device plugin alert may not be possible but definitely you should be able to create a BIOC rule for USB/RemovableMedia file operation, process operation activity with a low severity priority which will only trigger an alert in Alerts Table but not create an Incident.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Will be keen to know if someone has other idea.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Mar 2022 21:10:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-for-each-time-a-usb-device-is-plugged/m-p/476469#M1772</guid>
      <dc:creator>KanwarSingh01</dc:creator>
      <dc:date>2022-03-28T21:10:51Z</dc:date>
    </item>
    <item>
      <title>Re: Alert for each time a usb device is plugged</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-for-each-time-a-usb-device-is-plugged/m-p/476686#M1779</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi JoaoSantos20,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In the Restrictions Profile you have the option to configure notifications for Removable Media for file executions launched from external drives attached to endpoints in your network. To configure:&lt;/SPAN&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;SPAN&gt;From Cortex XDR, select &lt;/SPAN&gt;&lt;STRONG&gt;Endpoints &amp;gt; Policy Management &amp;gt; Prevention Profiles &amp;gt; + New Profile&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Select the OS to which the profile applies and &lt;STRONG&gt;Restrictions&lt;/STRONG&gt; as the profile type.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Click &lt;/SPAN&gt;&lt;STRONG&gt;Next&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Enter a &lt;/SPAN&gt;&lt;STRONG&gt;Profile Name&lt;/STRONG&gt;&lt;SPAN&gt; to identify the profile and &lt;STRONG&gt;Description&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Uncheck &lt;/SPAN&gt;&lt;STRONG&gt;Use Default&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Select which option best fits your use case&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;STRONG&gt;Notify&lt;/STRONG&gt;&lt;SPAN&gt;—Allow the file to execute but notify the user that the file is attempting to run from a suspicious location. The Cortex XDR agent also reports the event to Cortex XDR.&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;STRONG&gt;Report&lt;/STRONG&gt;&lt;SPAN&gt;—Allow the file to execute but report it to Cortex XDR.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;**You may add files or folders to an allow list or block list as well.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jtalton_4-1648588304362.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39881iD3DEA4BCC8737C90/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="jtalton_4-1648588304362.png" alt="jtalton_4-1648588304362.png" /&gt;&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Save&lt;/STRONG&gt;&lt;SPAN&gt; and then apply the Restrictions profile to the Security Profiles to Endpoints.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If you already have a Restrictions Profile configured, you may edit and follow steps 5 - 8&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You may also create an alert via a BIOC rule from an XQL Query for event logs for Windows and Linux system. For example, an XQL query for the Windows event ID 6416: &lt;EM&gt;A new external device was recognized by the system&lt;/EM&gt;. To build the BIOC rule query through a specific entity:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Navigate to Detection &lt;/SPAN&gt;&lt;STRONG&gt;Rules &amp;gt; BIOC &amp;gt; + Add BIOC&lt;/STRONG&gt;&lt;SPAN&gt; &amp;gt; Select the&amp;nbsp; &lt;/SPAN&gt;&lt;STRONG&gt;Event Log&lt;/STRONG&gt;&lt;SPAN&gt; Icon&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Enter&amp;nbsp;&lt;STRONG&gt;EVENT_ID&lt;/STRONG&gt; &lt;STRONG&gt;= 6416&lt;/STRONG&gt; (optional to enter other parameters),&amp;nbsp;&lt;STRONG&gt;Save&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jtalton_3-1648588232947.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39880i8635A7872EC1DEE2/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="jtalton_3-1648588232947.png" alt="jtalton_3-1648588232947.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Select the &lt;STRONG&gt;Type&lt;/STRONG&gt;, &lt;STRONG&gt;Severity&lt;/STRONG&gt;, &lt;STRONG&gt;Optional&lt;/STRONG&gt; select a MITRE Technique or Tactic to associate with the event, such as Technique - T1092 Removal Media and Tactic - TA0010 - Exfiltration. Enter a comment for tracking, then &lt;STRONG&gt;OK&lt;/STRONG&gt;.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jtalton_2-1648588193698.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39879i783F634AF307C1E3/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="jtalton_2-1648588193698.png" alt="jtalton_2-1648588193698.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The rule will be displayed in the BIOC Rules table. &lt;STRONG&gt;Right-Click&lt;/STRONG&gt; on the Rule to add it to the appropriate Restrictions Profile shown in the sub menu for the endpoints you would like monitored.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jtalton_1-1648588139581.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39878iFFCBE8B1AE217D63/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="jtalton_1-1648588139581.png" alt="jtalton_1-1648588139581.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jtalton_0-1648588087333.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39877i4F29C327A71306CC/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="jtalton_0-1648588087333.png" alt="jtalton_0-1648588087333.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Reference&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/endpoint-security-profiles/add-restrictions-profile" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Add a New Restrictions Security Profile (paloaltonetworks.com)&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/investigation-and-response/cortex-xdr-indicators/working-with-biocs/create-a-bioc-rule" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Create a BIOC Rule (paloaltonetworks.com)&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 21:19:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-for-each-time-a-usb-device-is-plugged/m-p/476686#M1779</guid>
      <dc:creator>jtalton</dc:creator>
      <dc:date>2022-03-29T21:19:04Z</dc:date>
    </item>
    <item>
      <title>Re: Alert for each time a usb device is plugged</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-for-each-time-a-usb-device-is-plugged/m-p/476696#M1780</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/203673"&gt;@jtalton&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pretty cool way of monitoring of removable media activity, i think the only thing which will be required from the endpoint side will be enable event logging for Removable media?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 21:42:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-for-each-time-a-usb-device-is-plugged/m-p/476696#M1780</guid>
      <dc:creator>KanwarSingh01</dc:creator>
      <dc:date>2022-03-29T21:42:29Z</dc:date>
    </item>
    <item>
      <title>Re: Alert for each time a usb device is plugged</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-for-each-time-a-usb-device-is-plugged/m-p/476697#M1781</link>
      <description>&lt;P&gt;Isnt it enabled in windows by default ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Really good and creative solution from Jtalton.&amp;nbsp;&lt;/P&gt;&lt;P&gt;That deserves likes, isnt it ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 21:44:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-for-each-time-a-usb-device-is-plugged/m-p/476697#M1781</guid>
      <dc:creator>eluis</dc:creator>
      <dc:date>2022-03-29T21:44:27Z</dc:date>
    </item>
    <item>
      <title>Re: Alert for each time a usb device is plugged</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-for-each-time-a-usb-device-is-plugged/m-p/476698#M1782</link>
      <description>&lt;P&gt;Thanks... Microsoft TechDoc doesn't specify if its enabled by default&amp;nbsp;&lt;A href="https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/monitor-the-use-of-removable-storage-devices" target="_blank"&gt;Monitor the use of removable storage devices (Windows 10) - Windows security | Microsoft Docs&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 21:50:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-for-each-time-a-usb-device-is-plugged/m-p/476698#M1782</guid>
      <dc:creator>jtalton</dc:creator>
      <dc:date>2022-03-29T21:50:30Z</dc:date>
    </item>
    <item>
      <title>Re: Alert for each time a usb device is plugged</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-for-each-time-a-usb-device-is-plugged/m-p/476702#M1783</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Open windows event viewer and go to&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Applications and Service Logs &amp;gt; Microsoft &amp;gt; Windows &amp;gt;&amp;nbsp;DriverFrameworks-UserMode&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;as shown in the pic1&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="eluis_0-1648591476794.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39882i1F2EB516E55617FF/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="eluis_0-1648591476794.png" alt="eluis_0-1648591476794.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Double click there and you will see the value is 0&amp;nbsp;&lt;/P&gt;&lt;P&gt;Right click on it and select properties. You will find enable logging check box empty. See pic2&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="eluis_1-1648591666091.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39883i15C26B63A8D2E16C/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="eluis_1-1648591666091.png" alt="eluis_1-1648591666091.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I believe it should be possible to propagate this setting through all your endpoints using GPO instead of manually configuring each endpoint.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;KR,&lt;/P&gt;&lt;P&gt;Luis&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 08:10:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-for-each-time-a-usb-device-is-plugged/m-p/476702#M1783</guid>
      <dc:creator>eluis</dc:creator>
      <dc:date>2022-03-30T08:10:48Z</dc:date>
    </item>
    <item>
      <title>Re: Alert for each time a usb device is plugged</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-for-each-time-a-usb-device-is-plugged/m-p/476707#M1784</link>
      <description>&lt;P&gt;Additionally in the registry we see that the enable value is 0 for the registry key&amp;nbsp;&lt;/P&gt;&lt;P&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-DriverFrameworks-UserMode/Operational&lt;/P&gt;&lt;P&gt;Changing the value to 1 should also work&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;KR,&lt;/P&gt;&lt;P&gt;Luis&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="eluis_0-1648592297033.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39886i0932CA10EF6909C3/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="eluis_0-1648592297033.png" alt="eluis_0-1648592297033.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 22:19:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-for-each-time-a-usb-device-is-plugged/m-p/476707#M1784</guid>
      <dc:creator>eluis</dc:creator>
      <dc:date>2022-03-29T22:19:13Z</dc:date>
    </item>
    <item>
      <title>Re: Alert for each time a usb device is plugged</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-for-each-time-a-usb-device-is-plugged/m-p/476728#M1788</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190764"&gt;@eluis&lt;/a&gt; and &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/203673"&gt;@jtalton&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For monitoring any new USB device it will be Event-ID 6416 but for monitoring removable media which is already registered by the system it will be 4719. So i guess a BIOC with a combination of 6416 and 4719 Event ID will help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="KanwarSingh01_0-1648594685226.png" style="width: 698px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39890iC0AC068B69CC58C9/image-dimensions/698x37/is-moderation-mode/true?v=v2" width="698" height="37" role="button" title="KanwarSingh01_0-1648594685226.png" alt="KanwarSingh01_0-1648594685226.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 23:20:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-for-each-time-a-usb-device-is-plugged/m-p/476728#M1788</guid>
      <dc:creator>KanwarSingh01</dc:creator>
      <dc:date>2022-03-29T23:20:54Z</dc:date>
    </item>
    <item>
      <title>Re: Alert for each time a usb device is plugged</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-for-each-time-a-usb-device-is-plugged/m-p/476778#M1792</link>
      <description>&lt;P&gt;Very interesting solution&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190764"&gt;@eluis&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/203673"&gt;@jtalton&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm referencing this Cortex XDR documentation:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/customizable-agent-settings/endpoint-data-collected-by-cortex-xdr.html" target="_blank"&gt;https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/endpoint-security/customizable-agent-settings/endpoint-data-collected-by-cortex-xdr.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Will those Events (6416 &amp;amp; 4719) be collected automatically or would it be necessary to use the Broker VM to collect this additional IDs?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 06:15:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-for-each-time-a-usb-device-is-plugged/m-p/476778#M1792</guid>
      <dc:creator>micomi</dc:creator>
      <dc:date>2022-03-30T06:15:02Z</dc:date>
    </item>
    <item>
      <title>Re: Alert for each time a usb device is plugged</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-for-each-time-a-usb-device-is-plugged/m-p/476889#M1796</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Multiple analytics alerts track USB activities that do not require BrokerVM&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/content/techdocs/en_US/cortex/cortex-xdr/cortex-xdr-analytics-alert-reference/cortex-xdr-analytics-alert-reference/a-user-connected-a-usb-storage-device-to-a-host-for-the-first-time.html#a-user-connected-a-usb-storage-device-to-a-host-for-the-first-time" target="_self"&gt;&lt;SPAN&gt;A user connected a USB storage device to a host for the first time&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/content/techdocs/en_US/cortex/cortex-xdr/cortex-xdr-analytics-alert-reference/cortex-xdr-analytics-alert-reference/a-user-connected-a-new-usb-storage-device-to-a-host.html#a-user-connected-a-new-usb-storage-device-to-a-host" target="_self"&gt;&lt;SPAN&gt;A user connected a new USB storage device to a host&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/content/techdocs/en_US/cortex/cortex-xdr/cortex-xdr-analytics-alert-reference/cortex-xdr-analytics-alert-reference/a-user-connected-a-new-usb-storage-device-to-multiple-hosts.html#a-user-connected-a-new-usb-storage-device-to-multiple-hosts" target="_self"&gt;&lt;SPAN&gt;A user connected a new USB storage device to multiple hosts&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;But you are correct, configuring the BrokerVM &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-pro-admin/broker-vm/set-up-broker-vm/activate-the-windows-event-collector.html" target="_self"&gt;Windows Event Collector&lt;/A&gt; would allow you to specify collection for event IDs 6416 &amp;amp; 4719&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 13:26:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-for-each-time-a-usb-device-is-plugged/m-p/476889#M1796</guid>
      <dc:creator>jtalton</dc:creator>
      <dc:date>2022-03-30T13:26:34Z</dc:date>
    </item>
    <item>
      <title>Re: Alert for each time a usb device is plugged</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-for-each-time-a-usb-device-is-plugged/m-p/477732#M1819</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/41187"&gt;@micomi&lt;/a&gt;&amp;nbsp;Don't see Cortex XDR looking for those EVIDs (6416&amp;amp;4719) in default collection, I think Broker VM would be required in this case.&lt;/P&gt;&lt;P&gt;Probably&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190764"&gt;@eluis&lt;/a&gt;&amp;nbsp;or&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/203673"&gt;@jtalton&lt;/a&gt;&amp;nbsp;can let us know?&lt;/P&gt;</description>
      <pubDate>Sat, 02 Apr 2022 19:30:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-for-each-time-a-usb-device-is-plugged/m-p/477732#M1819</guid>
      <dc:creator>KanwarSingh01</dc:creator>
      <dc:date>2022-04-02T19:30:30Z</dc:date>
    </item>
    <item>
      <title>Re: Alert for each time a usb device is plugged</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-for-each-time-a-usb-device-is-plugged/m-p/486801#M1983</link>
      <description>&lt;P&gt;We created a bioc using a reg key&lt;/P&gt;&lt;P&gt;Seems to work&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;preset = xdr_registry&lt;BR /&gt;| filter (action_registry_key_name contains "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\USBSTOR\Enum" and event_sub_type = REGISTRY_CREATE_KEY)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NathanBradley_0-1652365387945.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/40978i22F9050BB2E6BE58/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="NathanBradley_0-1652365387945.png" alt="NathanBradley_0-1652365387945.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2022 14:25:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-for-each-time-a-usb-device-is-plugged/m-p/486801#M1983</guid>
      <dc:creator>NathanBradley</dc:creator>
      <dc:date>2022-05-12T14:25:47Z</dc:date>
    </item>
    <item>
      <title>Re: Alert for each time a usb device is plugged</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-for-each-time-a-usb-device-is-plugged/m-p/486959#M1989</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;You can also consider using the following BIOC to raise alerts when a USB device is plugged in.&lt;/P&gt;&lt;P&gt;You can play around with the filters to whitelist allowed device IDs/vendors.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bbarmanroy_2-1652408436992.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/40987i7E551AB9BB847034/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="bbarmanroy_2-1652408436992.png" alt="bbarmanroy_2-1652408436992.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 May 2022 02:21:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-for-each-time-a-usb-device-is-plugged/m-p/486959#M1989</guid>
      <dc:creator>bbarmanroy</dc:creator>
      <dc:date>2022-05-13T02:21:08Z</dc:date>
    </item>
    <item>
      <title>Re: Alert for each time a usb device is plugged</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-for-each-time-a-usb-device-is-plugged/m-p/1235540#M8629</link>
      <description>&lt;P&gt;Hey Bb,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tried the XQL query as it looked super easy but there are no results. Is something else required to make this work?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Aug 2025 17:43:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/alert-for-each-time-a-usb-device-is-plugged/m-p/1235540#M8629</guid>
      <dc:creator>eumbach</dc:creator>
      <dc:date>2025-08-06T17:43:14Z</dc:date>
    </item>
  </channel>
</rss>

