<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Required Windows Event IDs for the best Cortex XDR detection performance in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/required-windows-event-ids-for-the-best-cortex-xdr-detection/m-p/590170#M6840</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1292845191"&gt;@agsaqqal&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for writing to live community.&lt;BR /&gt;&lt;BR /&gt;Yes, you are right.&lt;BR /&gt;First the event has to be generated and present on the machine in order for XDR Agent to be able to collect it and forward to XDR cloud servers.&lt;BR /&gt;For more details on what data XDR collect, you may refer&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Endpoint-Data-Collection" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Endpoint-Data-Collection&lt;/A&gt;&lt;BR /&gt;I hope that answers your question.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please mark this as answer if you found it helpful.&lt;/P&gt;</description>
    <pubDate>Mon, 24 Jun 2024 06:02:27 GMT</pubDate>
    <dc:creator>aspatil</dc:creator>
    <dc:date>2024-06-24T06:02:27Z</dc:date>
    <item>
      <title>Required Windows Event IDs for the best Cortex XDR detection performance</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/required-windows-event-ids-for-the-best-cortex-xdr-detection/m-p/590110#M6838</link>
      <description>&lt;P&gt;Hello, dear Community,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I need a list of Windows event IDs required for BIOC and other Cortex XDR rules to work effectively.&lt;/P&gt;
&lt;P&gt;For example, when we performed a Kerberos user enumeration attack using Kerbrute, it was not detected initially. Cortex XDR requires event ID 4768 to be enabled to detect such an attack. After enabling this event ID and testing the attack simulation again, it was successfully detected.&lt;/P&gt;
&lt;P&gt;I am now wondering which event IDs are crucial to enable in order to maximize detection opportunities for Cortex XDR. It would be great to get a list of these event IDs.&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2024 19:18:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/required-windows-event-ids-for-the-best-cortex-xdr-detection/m-p/590110#M6838</guid>
      <dc:creator>agsaqqal</dc:creator>
      <dc:date>2024-06-21T19:18:42Z</dc:date>
    </item>
    <item>
      <title>Re: Required Windows Event IDs for the best Cortex XDR detection performance</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/required-windows-event-ids-for-the-best-cortex-xdr-detection/m-p/590170#M6840</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1292845191"&gt;@agsaqqal&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for writing to live community.&lt;BR /&gt;&lt;BR /&gt;Yes, you are right.&lt;BR /&gt;First the event has to be generated and present on the machine in order for XDR Agent to be able to collect it and forward to XDR cloud servers.&lt;BR /&gt;For more details on what data XDR collect, you may refer&amp;nbsp;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Endpoint-Data-Collection" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Endpoint-Data-Collection&lt;/A&gt;&lt;BR /&gt;I hope that answers your question.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please mark this as answer if you found it helpful.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2024 06:02:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/required-windows-event-ids-for-the-best-cortex-xdr-detection/m-p/590170#M6840</guid>
      <dc:creator>aspatil</dc:creator>
      <dc:date>2024-06-24T06:02:27Z</dc:date>
    </item>
  </channel>
</rss>

