<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic XQL help  AD in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-help-ad/m-p/1235782#M8642</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="886" data-end="1078"&gt;Hi everyone,&lt;BR /&gt;&lt;BR /&gt;Anyone know how to query what types of AD queries users run?&lt;BR /&gt;I want to (1) find users/computers doing AD enumeration and (2) see what kind of enumeration they ran.&lt;/P&gt;
&lt;P data-start="1080" data-end="1125"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Aug 2025 13:48:30 GMT</pubDate>
    <dc:creator>tlmarques</dc:creator>
    <dc:date>2025-08-11T13:48:30Z</dc:date>
    <item>
      <title>XQL help  AD</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-help-ad/m-p/1235782#M8642</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="886" data-end="1078"&gt;Hi everyone,&lt;BR /&gt;&lt;BR /&gt;Anyone know how to query what types of AD queries users run?&lt;BR /&gt;I want to (1) find users/computers doing AD enumeration and (2) see what kind of enumeration they ran.&lt;/P&gt;
&lt;P data-start="1080" data-end="1125"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Aug 2025 13:48:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-help-ad/m-p/1235782#M8642</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2025-08-11T13:48:30Z</dc:date>
    </item>
    <item>
      <title>Re: XQL help  AD</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-help-ad/m-p/1235792#M8643</link>
      <description>&lt;P&gt;Hi Tlmarques,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First you should enable the security auditing logs:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-3.x-Documentation/Enable-security-auditing-event-IDs-with-GPO" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-3.x-Documentation/Enable-security-auditing-event-IDs-with-GPO&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can search on the security events that show that AD enumeration has been done.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on "mark this as a Solution". Thank you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;KR,&lt;/P&gt;
&lt;P&gt;Luis&lt;/P&gt;</description>
      <pubDate>Mon, 11 Aug 2025 15:05:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xql-help-ad/m-p/1235792#M8643</guid>
      <dc:creator>eluis</dc:creator>
      <dc:date>2025-08-11T15:05:23Z</dc:date>
    </item>
  </channel>
</rss>

