<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User Added to Local Administrators Group  XQL Query in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/user-added-to-local-administrators-group-xql-query/m-p/1228917#M8299</link>
    <description>&lt;P&gt;Thanks ,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;CODE data-start="176" data-end="183"&gt;&lt;BR /&gt;&lt;BR /&gt;I want to show all local users who are members of the Administrators group, excluding users named test1 and test2.&amp;nbsp;&lt;BR /&gt;note :&amp;nbsp; The users test1 and test2 were previously added to the Administrators group. so, i want to exclude.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thank you&amp;nbsp;&lt;BR /&gt;&lt;/CODE&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 13 May 2025 07:50:06 GMT</pubDate>
    <dc:creator>Prashanta</dc:creator>
    <dc:date>2025-05-13T07:50:06Z</dc:date>
    <item>
      <title>User Added to Local Administrators Group  XQL Query</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/user-added-to-local-administrators-group-xql-query/m-p/1228905#M8294</link>
      <description>&lt;P&gt;Hi Family ,&amp;nbsp;&lt;BR /&gt;I want to create a Cortex XDR query that generates an &lt;STRONG&gt;alert&lt;/STRONG&gt; when a user creates a local account and adds it to the administrators group.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;dataset = xdr_data &lt;BR /&gt;|filter event_type = ENUM.EVENT_LOG and action_evtlog_event_id in (4732, 4728)&lt;BR /&gt;&lt;BR /&gt;here i attached an reference link&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;A href="https://github.com/ItamarSafri/CortexXDR-XQL" target="_blank"&gt;GitHub - ItamarSafri/CortexXDR-XQL: Cortex XDR XQL Queries&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Thank You.&amp;nbsp;&lt;BR /&gt;&lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;LI-PRODUCT title="Endpoint Protection" id="Endpoint_Protection"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 May 2025 05:46:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/user-added-to-local-administrators-group-xql-query/m-p/1228905#M8294</guid>
      <dc:creator>Prashanta</dc:creator>
      <dc:date>2025-05-13T05:46:14Z</dc:date>
    </item>
    <item>
      <title>Re: User Added to Local Administrators Group  XQL Query</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/user-added-to-local-administrators-group-xql-query/m-p/1228911#M8295</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/593283889"&gt;@Prashanta&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;You can refer to below query which gives more details and reduces noise. Create correlation rule to generate an alert.&lt;/P&gt;
&lt;P&gt;// Use the XDR Event Log preset&lt;BR /&gt;preset = xdr_event_log&lt;/P&gt;
&lt;P&gt;// Filter for Event ID 4732: Member added to security-enabled local group&lt;BR /&gt;| filter action_evtlog_event_id = 4732&lt;BR /&gt;| filter action_evtlog_data_fields contains "Administrators"&lt;/P&gt;
&lt;P&gt;// Extract and rename useful fields&lt;BR /&gt;| alter &lt;BR /&gt;ProvisionerSid = action_evtlog_data_fields -&amp;gt; SubjectUserSid,&lt;BR /&gt;ProvisionerUserName = action_evtlog_data_fields -&amp;gt; SubjectUserName,&lt;BR /&gt;ProvisionerDomain = action_evtlog_data_fields -&amp;gt; SubjectDomainName,&lt;BR /&gt;SidOfUser = action_evtlog_data_fields -&amp;gt; MemberSid,&lt;BR /&gt;LocalGroupName = action_evtlog_data_fields -&amp;gt; TargetUserName,&lt;BR /&gt;LocalDomainName = action_evtlog_data_fields -&amp;gt; TargetDomainName,&lt;BR /&gt;LocalGroupSid = action_evtlog_data_fields -&amp;gt; TargetSid&lt;/P&gt;
&lt;P&gt;// Filter out system-generated events (e.g., SYSTEM account)&lt;BR /&gt;// Comment this out if you want to inspect all activity&lt;BR /&gt;| filter ProvisionerSid != "S-1-5-18"&lt;/P&gt;
&lt;P&gt;// Keep only relevant fields for clarity&lt;BR /&gt;| fields agent_hostname, ProvisionerSid, ProvisionerUserName, ProvisionerDomain,&lt;BR /&gt;LocalGroupName, LocalDomainName, LocalGroupSid, SidOfUser, &lt;BR /&gt;_time as UserAddedToAdmin_Timestamp&lt;/P&gt;
&lt;P&gt;// Join with host inventory for resolving SID-to-username outside retention&lt;BR /&gt;| join type = left conflict_strategy = left (&lt;BR /&gt;preset = host_inventory_users&lt;BR /&gt;| fields name, sid&lt;BR /&gt;) as host_inv SidOfUser = host_inv.sid&lt;/P&gt;
&lt;P&gt;// Optional: Join with Event ID 4720 (user created) within the last 24h&lt;BR /&gt;| join type = left conflict_strategy = left (&lt;BR /&gt;preset = xdr_event_log&lt;BR /&gt;| filter action_evtlog_event_id = 4720&lt;BR /&gt;| alter &lt;BR /&gt;NewUserSid = action_evtlog_data_fields -&amp;gt; TargetSid,&lt;BR /&gt;NewUserName = action_evtlog_data_fields -&amp;gt; SamAccountName,&lt;BR /&gt;UserAdded_Timestamp = _time&lt;BR /&gt;| fields NewUserSid, NewUserName, UserAdded_Timestamp&lt;BR /&gt;) as NewUser_Added SidOfUser = NewUser_Added.NewUserSid&lt;/P&gt;
&lt;P&gt;// Deduplicate on key fields to avoid repeated entries&lt;BR /&gt;| dedup agent_hostname, ProvisionerSid, ProvisionerUserName, ProvisionerDomain, &lt;BR /&gt;LocalGroupName, LocalDomainName, LocalGroupSid, SidOfUser&lt;/P&gt;
&lt;P&gt;// Final tidy fields&lt;BR /&gt;| fields _time, agent_hostname, ProvisionerSid, ProvisionerDomain, ProvisionerUserName, &lt;BR /&gt;UserAdded_Timestamp, UserAddedToAdmin_Timestamp, SidOfUser, LocalGroupSid, &lt;BR /&gt;LocalDomainName, LocalGroupName, NewUserName, name&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you feel this has answered your query, please let us know by clicking like and&amp;nbsp; on "mark this as a Solution". Thank you.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 May 2025 06:14:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/user-added-to-local-administrators-group-xql-query/m-p/1228911#M8295</guid>
      <dc:creator>aspatil</dc:creator>
      <dc:date>2025-05-13T06:14:24Z</dc:date>
    </item>
    <item>
      <title>Re: User Added to Local Administrators Group  XQL Query</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/user-added-to-local-administrators-group-xql-query/m-p/1228917#M8299</link>
      <description>&lt;P&gt;Thanks ,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;CODE data-start="176" data-end="183"&gt;&lt;BR /&gt;&lt;BR /&gt;I want to show all local users who are members of the Administrators group, excluding users named test1 and test2.&amp;nbsp;&lt;BR /&gt;note :&amp;nbsp; The users test1 and test2 were previously added to the Administrators group. so, i want to exclude.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thank you&amp;nbsp;&lt;BR /&gt;&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 May 2025 07:50:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/user-added-to-local-administrators-group-xql-query/m-p/1228917#M8299</guid>
      <dc:creator>Prashanta</dc:creator>
      <dc:date>2025-05-13T07:50:06Z</dc:date>
    </item>
  </channel>
</rss>

