<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Deactivating UAC should be alerted in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/deactivating-uac-should-be-alerted/m-p/513247#M2742</link>
    <description>&lt;P&gt;Hey Neelrohit,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you, I will tweak the BIOCs as you mentioned.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;</description>
    <pubDate>Mon, 29 Aug 2022 13:01:43 GMT</pubDate>
    <dc:creator>RFeyertag</dc:creator>
    <dc:date>2022-08-29T13:01:43Z</dc:date>
    <item>
      <title>Deactivating UAC should be alerted</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/deactivating-uac-should-be-alerted/m-p/513182#M2732</link>
      <description>&lt;P&gt;Hello dear community,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tested to deactivate my UAC, which was possible without any alert.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In my opinion there should be an alert triggerd. What do you think?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://twitter.com/Computeus7/status/1562497080048119808" target="_blank"&gt;https://twitter.com/Computeus7/status/1562497080048119808&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Reg Add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v "EnableLUA" /t "REG_DWORD" /d "0" /f&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 27 Aug 2022 21:57:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/deactivating-uac-should-be-alerted/m-p/513182#M2732</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2022-08-27T21:57:51Z</dc:date>
    </item>
    <item>
      <title>Re: Deactivating UAC should be alerted</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/deactivating-uac-should-be-alerted/m-p/513190#M2734</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190671"&gt;@RFeyertag&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cortex XDR has many Out of the Box BIOC rules created for UAC bypass events and it generates the alerts on the same. However these rules are detection rules. In the case of the command line posted, XDR collected the event log, however, the BIOC rules designed are not in this manner and you can create a copy of the already existing BIOC rule "T&lt;STRONG&gt;ampering with the Windows User Account Controls (UAC) configuration&lt;/STRONG&gt;" and tweak the rule within it with the below:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Registry [ action type = all AND registry key name = *SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA* ] AND Host [ host os = windows ]&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The above rule can generate an alert for you now.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2022-08-28 at 9.51.08 AM.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43397iF01D9E46B7AE42C7/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screenshot 2022-08-28 at 9.51.08 AM.png" alt="Screenshot 2022-08-28 at 9.51.08 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Sun, 28 Aug 2022 01:51:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/deactivating-uac-should-be-alerted/m-p/513190#M2734</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2022-08-28T01:51:31Z</dc:date>
    </item>
    <item>
      <title>Re: Deactivating UAC should be alerted</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/deactivating-uac-should-be-alerted/m-p/513247#M2742</link>
      <description>&lt;P&gt;Hey Neelrohit,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you, I will tweak the BIOCs as you mentioned.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Mon, 29 Aug 2022 13:01:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/deactivating-uac-should-be-alerted/m-p/513247#M2742</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2022-08-29T13:01:43Z</dc:date>
    </item>
  </channel>
</rss>

