<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cortex XDR XQL query to check which user is elevating access in linux in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-xql-query-to-check-which-user-is-elevating-access-in/m-p/598637#M7218</link>
    <description>&lt;P&gt;Hello Team ,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am trying to write a XQL query to check&amp;nbsp;which user is elevating access in Linux.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;can someone please help to write this query ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;BR /&gt;&lt;BR /&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp; #XQL&lt;/P&gt;</description>
    <pubDate>Tue, 24 Sep 2024 11:47:55 GMT</pubDate>
    <dc:creator>tejaspatil12</dc:creator>
    <dc:date>2024-09-24T11:47:55Z</dc:date>
    <item>
      <title>Cortex XDR XQL query to check which user is elevating access in linux</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-xql-query-to-check-which-user-is-elevating-access-in/m-p/598637#M7218</link>
      <description>&lt;P&gt;Hello Team ,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am trying to write a XQL query to check&amp;nbsp;which user is elevating access in Linux.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;can someone please help to write this query ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;BR /&gt;&lt;BR /&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp; #XQL&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2024 11:47:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-xql-query-to-check-which-user-is-elevating-access-in/m-p/598637#M7218</guid>
      <dc:creator>tejaspatil12</dc:creator>
      <dc:date>2024-09-24T11:47:55Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR XQL query to check which user is elevating access in linux</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-xql-query-to-check-which-user-is-elevating-access-in/m-p/598671#M7219</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/326396"&gt;@tejaspatil12&lt;/a&gt;, thanks for reaching us using the Live Community.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is a simple example that can help you with your inquiry:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;dataset = xdr_data &lt;BR /&gt;| filter agent_hostname = "HostName" // If you need to filter one endpoint&lt;BR /&gt;| filter actor_process_command_line contains "sudo"&lt;BR /&gt;| fields agent_hostname, agent_ip_addresses, actor_process_command_line // Add fields as needed&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this post answers your question, please mark it as the solution.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2024 17:46:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-xql-query-to-check-which-user-is-elevating-access-in/m-p/598671#M7219</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2024-09-24T17:46:30Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR XQL query to check which user is elevating access in linux</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-xql-query-to-check-which-user-is-elevating-access-in/m-p/598742#M7220</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/310428"&gt;@jmazzeo&lt;/a&gt;&amp;nbsp; this is giving the list for all command lines.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can we add the field which user executed it ? so we can get the idea about which user elevated the access&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2024 10:38:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-xql-query-to-check-which-user-is-elevating-access-in/m-p/598742#M7220</guid>
      <dc:creator>tejaspatil12</dc:creator>
      <dc:date>2024-09-25T10:38:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR XQL query to check which user is elevating access in linux</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-xql-query-to-check-which-user-is-elevating-access-in/m-p/598785#M7224</link>
      <description>&lt;P&gt;You can add any fields you need, look at the "field" stage line in the query and keep adding all the required fields.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2024 18:59:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-xql-query-to-check-which-user-is-elevating-access-in/m-p/598785#M7224</guid>
      <dc:creator>jmazzeo</dc:creator>
      <dc:date>2024-09-25T18:59:02Z</dc:date>
    </item>
  </channel>
</rss>

