Help creating a Cortex XDR alert when a user is added to a privileged group in Active Directory

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Help creating a Cortex XDR alert when a user is added to a privileged group in Active Directory

L0 Member



I am looking to create a Cortex XDR alert when a user is added to a privileged group in Active Director. I can get the alerts when a user is added to any group, but I am looking for only privileged groups.




L5 Sessionator

HI @michaelpageHFE ,


Thank you for writing to live community!


Cortex XDR agent is capable of collection of event IDs for Group member additions (4728, 4732, 4756) with Pro capabilities enabled. As a result, you can try to create a BIOC and correlation rule for the same. We can create BIOC rules on the event IDs and/or XQL queries for the same.


For BIOC, you can get through the BIOC rules with native parameters to create alerts for "4728", "4732", "4756" and fine tune as per your choice.


You can also use XQL queries for the same as a BIOC rule or correlation rules on the same metric with the query below and choose to fine tune as per your choice.



dataset = xdr_data 
| filter event_type = ENUM.EVENT_LOG and action_evtlog_event_id in (4728,4732,4756)
| fields <enter the fields of your choice>




Hope this helps! Please mark the response as "Accept as Solution" if it answers your query.






I went through all the fields and I cannot find a field to filter down the dataset to an active directory group. I see all the data in the XQL queries. Is there a field that can filter the data to the active directory privileged group by Cn, Active Group Name, or objectSid?

Hi @michaelpageHFE ,


The xdr_dataset is the dataset for logs collected from agent only. In case if you are ingesting and syncing data from your active directory using Cloud Identity Engine( using your on-prem or Azure/any other AD), the data from the CIE is stitched under the dataset pan_dss_raw.

Please join the latter dataset to the fields in the former to get an output for the same and you should be able to get the columns of your choice.


Hope this helps

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!