<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: File Integrity Monitoring FIM using Auditbeat module in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-integrity-monitoring-fim-using-auditbeat-module/m-p/1220398#M7882</link>
    <description>&lt;P&gt;The XDR agent doesn't have full FIM coverage. It doesn't calculate the hash after every change, certain paths aren't monitored, and if the host is too active then that can cause file events to not be reported to the tenant's backend database. &lt;BR /&gt;You can monitor for processes touching certain directories and can set BIOCs or correlation rules to trigger on file events on certain directories, but it's not 100% coverage. If you have a scrupulous auditor, or an application team that tracks every change made during a change window on a host, there's a good chance it'll end up being a finding on your auditor's report.&lt;BR /&gt;&lt;BR /&gt;If you want full FIM monitoring on linux and use XDR Pro per GB/TB, look into using AuditBeats, specify the directories to monitor, and send that data in via HTTP Collectors. Prisma Cloud's Defender may provide better FIM coverage but I haven't personally tested.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.elastic.co/guide/en/beats/auditbeat/current/auditbeat-module-file_integrity.html" target="_blank" rel="noopener"&gt;https://www.elastic.co/guide/en/beats/auditbeat/current/auditbeat-module-file_integrity.html&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://docs.prismacloud.io/en/compute-edition/31/admin-guide/install/deploy-defender/app-embedded/config-app-embedded-fs-mon" target="_blank" rel="noopener"&gt;https://docs.prismacloud.io/en/compute-edition/31/admin-guide/install/deploy-defender/app-embedded/config-app-embedded-fs-mon&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Osquery &amp;amp; Fleet are other viable option for FIM as well.&amp;nbsp;&lt;BR /&gt;&lt;A href="https://osquery.readthedocs.io/en/stable/deployment/file-integrity-monitoring/" target="_blank" rel="noopener"&gt;https://osquery.readthedocs.io/en/stable/deployment/file-integrity-monitoring/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://fleetdm.com/" target="_blank" rel="noopener"&gt;https://fleetdm.com/&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 13 Feb 2025 21:59:54 GMT</pubDate>
    <dc:creator>p.Dugan005079</dc:creator>
    <dc:date>2025-02-13T21:59:54Z</dc:date>
    <item>
      <title>File Integrity Monitoring FIM using Auditbeat module</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-integrity-monitoring-fim-using-auditbeat-module/m-p/521279#M3143</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Looking to set up FIM using the Cortex XDR agent and from what I have found so far, it seems unsupported. Has anyone set up FIM using any method?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The only possible option I have found so far is maybe using an auditbeat with the FIM module:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.elastic.co/guide/en/beats/auditbeat/current/auditbeat-module-file_integrity.html#_how_it_works_2" target="_blank"&gt;https://www.elastic.co/guide/en/beats/auditbeat/current/auditbeat-module-file_integrity.html#_how_it_works_2&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Nov 2022 15:03:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-integrity-monitoring-fim-using-auditbeat-module/m-p/521279#M3143</guid>
      <dc:creator>Optimizer</dc:creator>
      <dc:date>2022-11-15T15:03:20Z</dc:date>
    </item>
    <item>
      <title>Re: File Integrity Monitoring FIM using Auditbeat module</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-integrity-monitoring-fim-using-auditbeat-module/m-p/521293#M3144</link>
      <description>&lt;P&gt;Looking into this further. BIOC rules seem to be what I'm looking for, but I am not certain how to set my specific file paths I want to be monitored.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I test creating my own BIOC rule, I cannot find the files I am looking for in the provided list&lt;/P&gt;</description>
      <pubDate>Tue, 15 Nov 2022 16:34:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-integrity-monitoring-fim-using-auditbeat-module/m-p/521293#M3144</guid>
      <dc:creator>Optimizer</dc:creator>
      <dc:date>2022-11-15T16:34:44Z</dc:date>
    </item>
    <item>
      <title>Re: File Integrity Monitoring FIM using Auditbeat module</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-integrity-monitoring-fim-using-auditbeat-module/m-p/521303#M3145</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/255006"&gt;@Optimizer&lt;/a&gt;&amp;nbsp;,&amp;nbsp;thanks for writing to Live Community.&lt;BR /&gt;&lt;BR /&gt;You are correct, the way to use File Integrity Monitoring with XDR is through BIOC rules, correlations and&amp;nbsp;&lt;SPAN&gt;reports based on XQL.&amp;nbsp;&lt;BR /&gt;Please see a few examples below:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;1. XQL Based Correlation Rule :&lt;SPAN&gt;&amp;nbsp;Monitor /etc/, usr/local/share/, /usr/share/ for any conf file modifications:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV class=""&gt;
&lt;DIV class="" role="presentation" data-qa="message_content"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="" data-qa="message-text"&gt;
&lt;DIV class="" data-qa="block-kit-renderer"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="" dir="auto"&gt;
&lt;DIV class=""&gt;&lt;EM&gt;&lt;EM&gt;dataset = xdr_data&lt;BR /&gt;&lt;EM&gt;|filter event_type = FILE and (event_sub_type = FILE_CREATE_NEW or event_sub_type = FILE_WRITE or event_sub_type = FILE_REMOVE or event_sub_type = FILE_RENAME )&lt;BR /&gt;&lt;EM&gt;|filter lowercase(action_file_path) in ("/etc/*","/usr/local/share/*","/usr/share/*") and action_file_extension in ("conf","txt")&lt;BR /&gt;&lt;EM&gt;| fields action_file_name , action_file_path , action_file_type , agent_ip_addresses , agent_hostname, action_file_path&lt;/EM&gt;&lt;/EM&gt;&lt;/EM&gt;&lt;/EM&gt;&lt;/EM&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class=""&gt;&lt;SPAN&gt;&lt;STRONG&gt;2. BIOC rule to monitor Apache2 configuration file (please see attached screenshot below).&lt;/STRONG&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class=""&gt;You should of course make changes to the file paths based on the files you are looking to monitor.&lt;BR /&gt;&lt;BR /&gt;Let me know if the provided examples helped you in your case!
&lt;DIV class="" role="group"&gt;
&lt;DIV class="" role="group" aria-label="Message actions" data-qa="message-actions"&gt;&amp;nbsp;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mavraham_0-1668532826398.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/45357i38F6E05E49BC92E3/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="mavraham_0-1668532826398.png" alt="mavraham_0-1668532826398.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Nov 2022 17:28:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-integrity-monitoring-fim-using-auditbeat-module/m-p/521303#M3145</guid>
      <dc:creator>mavraham</dc:creator>
      <dc:date>2022-11-15T17:28:38Z</dc:date>
    </item>
    <item>
      <title>Re: File Integrity Monitoring FIM using Auditbeat module</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-integrity-monitoring-fim-using-auditbeat-module/m-p/521306#M3146</link>
      <description>&lt;P&gt;Thank you, this helped a lot!&lt;/P&gt;</description>
      <pubDate>Tue, 15 Nov 2022 18:09:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-integrity-monitoring-fim-using-auditbeat-module/m-p/521306#M3146</guid>
      <dc:creator>Optimizer</dc:creator>
      <dc:date>2022-11-15T18:09:13Z</dc:date>
    </item>
    <item>
      <title>Re: File Integrity Monitoring FIM using Auditbeat module</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-integrity-monitoring-fim-using-auditbeat-module/m-p/551121#M4829</link>
      <description>&lt;P&gt;I finally got around to working on this, and... still need to configure some more, but it works.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;dataset = xdr_data |filter event_type = FILE and (event_sub_type = FILE_CREATE_NEW or event_sub_type = FILE_WRITE or event_sub_type = FILE_REMOVE or event_sub_type = FILE_RENAME )&lt;BR /&gt;|filter action_file_path in ("C:\Program Files (x86)\*","C:\Program Files\*","C:\ProgramData\*") and action_file_name contains ".exe"&lt;BR /&gt;|fields agent_hostname, agent_ip_addresses , action_file_name, action_file_path, action_file_type&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 15:46:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-integrity-monitoring-fim-using-auditbeat-module/m-p/551121#M4829</guid>
      <dc:creator>PC-TomS</dc:creator>
      <dc:date>2023-07-26T15:46:05Z</dc:date>
    </item>
    <item>
      <title>Re: File Integrity Monitoring FIM using Auditbeat module</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-integrity-monitoring-fim-using-auditbeat-module/m-p/565901#M5553</link>
      <description>&lt;P&gt;Hi Optimizer,&lt;/P&gt;
&lt;P&gt;I'm looking for a solution to meet the 11.5 (FIM) requirement of PCI. &lt;SPAN&gt;Did Cortex XDR BIOC meet your FIM requirements&lt;/SPAN&gt;?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 00:09:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-integrity-monitoring-fim-using-auditbeat-module/m-p/565901#M5553</guid>
      <dc:creator>danlav</dc:creator>
      <dc:date>2023-11-16T00:09:50Z</dc:date>
    </item>
    <item>
      <title>Re: File Integrity Monitoring FIM using Auditbeat module</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-integrity-monitoring-fim-using-auditbeat-module/m-p/580993#M6358</link>
      <description>&lt;P&gt;Dear all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm looking for FIM on Linux (etc/shadow), for the examples are the difference (object before and after) and then the process name like "&lt;SPAN&gt;/usr/sbin/sshd&lt;/SPAN&gt;" or "/&lt;SPAN&gt;usr/sbin/userdel&lt;/SPAN&gt;". How to show it on XQL Query? Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2024 06:42:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-integrity-monitoring-fim-using-auditbeat-module/m-p/580993#M6358</guid>
      <dc:creator>T.Andriawan</dc:creator>
      <dc:date>2024-03-20T06:42:59Z</dc:date>
    </item>
    <item>
      <title>Re: File Integrity Monitoring FIM using Auditbeat module</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-integrity-monitoring-fim-using-auditbeat-module/m-p/581001#M6359</link>
      <description>&lt;P&gt;Any solution of that? Thankyou&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2024 08:24:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-integrity-monitoring-fim-using-auditbeat-module/m-p/581001#M6359</guid>
      <dc:creator>T.Andriawan</dc:creator>
      <dc:date>2024-03-20T08:24:50Z</dc:date>
    </item>
    <item>
      <title>Re: File Integrity Monitoring FIM using Auditbeat module</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-integrity-monitoring-fim-using-auditbeat-module/m-p/1220398#M7882</link>
      <description>&lt;P&gt;The XDR agent doesn't have full FIM coverage. It doesn't calculate the hash after every change, certain paths aren't monitored, and if the host is too active then that can cause file events to not be reported to the tenant's backend database. &lt;BR /&gt;You can monitor for processes touching certain directories and can set BIOCs or correlation rules to trigger on file events on certain directories, but it's not 100% coverage. If you have a scrupulous auditor, or an application team that tracks every change made during a change window on a host, there's a good chance it'll end up being a finding on your auditor's report.&lt;BR /&gt;&lt;BR /&gt;If you want full FIM monitoring on linux and use XDR Pro per GB/TB, look into using AuditBeats, specify the directories to monitor, and send that data in via HTTP Collectors. Prisma Cloud's Defender may provide better FIM coverage but I haven't personally tested.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.elastic.co/guide/en/beats/auditbeat/current/auditbeat-module-file_integrity.html" target="_blank" rel="noopener"&gt;https://www.elastic.co/guide/en/beats/auditbeat/current/auditbeat-module-file_integrity.html&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://docs.prismacloud.io/en/compute-edition/31/admin-guide/install/deploy-defender/app-embedded/config-app-embedded-fs-mon" target="_blank" rel="noopener"&gt;https://docs.prismacloud.io/en/compute-edition/31/admin-guide/install/deploy-defender/app-embedded/config-app-embedded-fs-mon&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Osquery &amp;amp; Fleet are other viable option for FIM as well.&amp;nbsp;&lt;BR /&gt;&lt;A href="https://osquery.readthedocs.io/en/stable/deployment/file-integrity-monitoring/" target="_blank" rel="noopener"&gt;https://osquery.readthedocs.io/en/stable/deployment/file-integrity-monitoring/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://fleetdm.com/" target="_blank" rel="noopener"&gt;https://fleetdm.com/&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2025 21:59:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-integrity-monitoring-fim-using-auditbeat-module/m-p/1220398#M7882</guid>
      <dc:creator>p.Dugan005079</dc:creator>
      <dc:date>2025-02-13T21:59:54Z</dc:date>
    </item>
    <item>
      <title>Re: File Integrity Monitoring FIM using Auditbeat module</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-integrity-monitoring-fim-using-auditbeat-module/m-p/1220400#M7883</link>
      <description>&lt;P&gt;Isn't possible with XQL directly, as it doesn't read the file contents.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2025 22:10:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/file-integrity-monitoring-fim-using-auditbeat-module/m-p/1220400#M7883</guid>
      <dc:creator>p.Dugan005079</dc:creator>
      <dc:date>2025-02-13T22:10:07Z</dc:date>
    </item>
  </channel>
</rss>

