<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Confirmed issues with some identity threat modules and risk management dashboard in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/confirmed-issues-with-some-identity-threat-modules-and-risk/m-p/543855#M4452</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/276269"&gt;@PiyushKohli&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks for the information.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I'm trying to star some users, but not every starred user appears on my watchlist. May I ask why some of the starred users cannot appear on the watchlist?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Furthermore, I understand that selecting ＂Gained＂ as the sorting method shows the score gained within a custom timeframe.&amp;nbsp;Therefore, selecting ＂Total＂ as the sorting method should show the total score after enabling ITDR, right? However, I not sure why some user scores become negative when I switch to ＂Total＂, I want to understand the reason behind this result.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best wishes.&lt;/P&gt;</description>
    <pubDate>Tue, 30 May 2023 03:50:22 GMT</pubDate>
    <dc:creator>Chilla</dc:creator>
    <dc:date>2023-05-30T03:50:22Z</dc:date>
    <item>
      <title>Confirmed issues with some identity threat modules and risk management dashboard</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/confirmed-issues-with-some-identity-threat-modules-and-risk/m-p/543474#M4444</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello everyone!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Recently, I have been learning about the Identity Analytics feature in Cortex XDR.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; After enabling Identity Analytics, I found that not every tenant presents the same interface. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I found that the following UI features are not identical:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;absence of a Risk Management Dashboard&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;&lt;SPAN&gt;less information displayed in User Risk View (e.g.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;Regular Activity Hours&lt;SPAN class="xdr-sr-only ng-star-inserted"&gt;&lt;SPAN class="xdr-sr-only ng-star-inserted"&gt;artifact info,&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;Actual activity...)
&lt;DIV class="widget-body"&gt;
&lt;DIV class="widget-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;no Asset Roles Configuration(Asset → Asset Roles Configuration). &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;no Host Risk View&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;I checked some official documents, it seems to be caused by the &lt;FONT style="--darkreader-inline-color: #fffdfa;" color="#000000" data-darkreader-inline-color=""&gt;&lt;STRONG&gt;Identity Threat Module not being enabled&lt;/STRONG&gt;.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I’m a little confused about a few points：&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;So enabled Identity Analytic does not represent the Identity Threat Module is enabled?&lt;/LI&gt;
&lt;LI&gt;To fully enable the Identity Threat Module, we not only need to enable Identity Analytics in Cortex XDR but also need to activate the Cloud Identity Engine, right?&lt;/LI&gt;
&lt;LI&gt;About Risk Management Dash Board, I check the document about&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Pej0m_jlN3h9P0ekcdDDeg/NTsicyGdBuUA95xvxdHiUw?section=UUID-f6f1adde-585e-e3f7-5b03-c7dc795d01f0_UUID-d1a11cd7-71bd-99f8-96fd-63f3d9eab894" target="_self"&gt;Metrics Widgets&lt;/A&gt;.&lt;BR /&gt;Regarding the description of ＂Top 5 Users at Risk＂ and ＂Watchlist＂ in Widgets, both are about users who are most vulnerable to potential security threats. I would like to know more about the differences between them.&lt;/LI&gt;
&lt;LI&gt;In User Risk Card,&amp;nbsp; ＂Login Attempts＂ and ＂&lt;SPAN&gt;Latest Authentication Attempts＂, i&lt;/SPAN&gt;&lt;SPAN&gt;t seems that both display login information, including src_ip, dst_ip, and vendor. I would like to ask for more information about the differences between the two.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Perhaps someone can help me clarify the above questions. Thank you all.&lt;span class="lia-unicode-emoji" title=":folded_hands:"&gt;🙏&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 May 2023 08:52:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/confirmed-issues-with-some-identity-threat-modules-and-risk/m-p/543474#M4444</guid>
      <dc:creator>Chilla</dc:creator>
      <dc:date>2023-05-26T08:52:09Z</dc:date>
    </item>
    <item>
      <title>Re: Confirmed issues with some identity threat modules and risk management dashboard</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/confirmed-issues-with-some-identity-threat-modules-and-risk/m-p/543775#M4448</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/251009"&gt;@Chilla&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for writing to live community! Please find response to your above queries inline.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;OL&gt;
&lt;LI&gt;So enabled Identity Analytic does not represent the Identity Threat Module is enabled?&amp;nbsp;&lt;STRONG&gt;Yes. ITDR is a new separate module. This module is an Add-On Premium that provides analytical and risk-based detections that correlates with User &amp;amp; Entity behavior analytics (UEBA) and is available for a free trial through July 31st, 2023.&amp;nbsp;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;To fully enable the Identity Threat Module, we not only need to enable Identity Analytics in Cortex XDR but also need to activate the Cloud Identity Engine, right? &lt;STRONG&gt;Yes,&amp;nbsp;for ITDR full analytics capabilities and in order to improve precision in terms of detection CIE is highly recommended.&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;About Risk Management Dash Board, I check the document about&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Pej0m_jlN3h9P0ekcdDDeg/NTsicyGdBuUA95xvxdHiUw?section=UUID-f6f1adde-585e-e3f7-5b03-c7dc795d01f0_UUID-d1a11cd7-71bd-99f8-96fd-63f3d9eab894" target="_self"&gt;Metrics Widgets&lt;/A&gt;.&lt;BR /&gt;Regarding the description of ＂Top 5 Users at Risk＂ and ＂Watchlist＂ in Widgets, both are about users who are most vulnerable to potential security threats. I would like to know more about the differences between them.&amp;nbsp; &lt;STRONG&gt;Main difference is Watchlist Widget is custom like widget which can show upto 10 users that are selected as starred. i.e. You may star a user which you would like to monitor even if its not under Top 5 users at Risk you may monitor or see under Watchlist. Hope this helps.&lt;/STRONG&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;In User Risk Card,&amp;nbsp; ＂Login Attempts＂ and ＂&lt;SPAN&gt;Latest Authentication Attempts＂, i&lt;/SPAN&gt;&lt;SPAN&gt;t seems that both display login information, including src_ip, dst_ip, and vendor. I would like to ask for more information about the differences between the two. &lt;STRONG&gt;Let me get back to you on this!&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;You may also check more about this module &lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-how-to-videos/cortex-xdr-3-6-feature-review-identity-threat-detection-and/ta-p/538650" target="_self"&gt;here&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Mon, 29 May 2023 06:08:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/confirmed-issues-with-some-identity-threat-modules-and-risk/m-p/543775#M4448</guid>
      <dc:creator>PiyushKohli</dc:creator>
      <dc:date>2023-05-29T06:08:11Z</dc:date>
    </item>
    <item>
      <title>Re: Confirmed issues with some identity threat modules and risk management dashboard</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/confirmed-issues-with-some-identity-threat-modules-and-risk/m-p/543855#M4452</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/276269"&gt;@PiyushKohli&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks for the information.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I'm trying to star some users, but not every starred user appears on my watchlist. May I ask why some of the starred users cannot appear on the watchlist?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Furthermore, I understand that selecting ＂Gained＂ as the sorting method shows the score gained within a custom timeframe.&amp;nbsp;Therefore, selecting ＂Total＂ as the sorting method should show the total score after enabling ITDR, right? However, I not sure why some user scores become negative when I switch to ＂Total＂, I want to understand the reason behind this result.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best wishes.&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2023 03:50:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/confirmed-issues-with-some-identity-threat-modules-and-risk/m-p/543855#M4452</guid>
      <dc:creator>Chilla</dc:creator>
      <dc:date>2023-05-30T03:50:22Z</dc:date>
    </item>
    <item>
      <title>Re: Confirmed issues with some identity threat modules and risk management dashboard</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/confirmed-issues-with-some-identity-threat-modules-and-risk/m-p/544136#M4460</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/251009"&gt;@Chilla&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In case you are seeing any issues where you have star users but those are not appearing on the watchlist , you may open Support Case for their investigation.&amp;nbsp;&lt;BR /&gt;For user scores which are being seen as negative after you select "Total" could you share some additional info or screenshot by redacting any user/org info.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 10:31:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/confirmed-issues-with-some-identity-threat-modules-and-risk/m-p/544136#M4460</guid>
      <dc:creator>PiyushKohli</dc:creator>
      <dc:date>2023-05-31T10:31:36Z</dc:date>
    </item>
  </channel>
</rss>

