Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Monitor bitlocker

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Monitor bitlocker

L1 Bithead

Hello,

 

I am checking if it is possible, to monitor from cortex when BitLocker is enabled on the computer, via a BIOC?

 

Best regards.

4 REPLIES 4

L5 Sessionator

Hello @J.PrezHidalgo ,

 

Thank you for reaching out on Live community.

 

Behavioral indicators of compromise (BIOCs) enable you to alert and respond to behaviors—tactics, techniques, and procedures. Instead of hashes and other traditional indicators of compromise, BIOC rules detect behavior such as is related to processes, registry, files, and network activity.

 

If you want to monitor the encryption status on the machines, you can refer to below query:
dataset = endpoints
|fields endpoint_name , endpoint_id , operating_system , encryption_status

 

You can create Dashboard or use correlation rule as per your need. 

 

If you feel this has answered your query, please let us know by clicking on "mark this as a Solution".

Ashutosh Patil

L1 Bithead

In this case, we do not need to see the encryption status (if applied by Cortex XDR), but to see when the bitlocker goes from inactive to active.

L5 Sessionator

Hello @J.PrezHidalgo ,

 

The idle way is to run manage-bde -status. However, if you want to be notified, I have found two ways here.

 

1. To look for the event id's when encryption starts and completes and create a correlation rule and get alerted.

2. Check with Microsoft which registries can be verified to ensure that encryption status changes and create the BIOC.

 

Or you can get the report in every specific time frame and ingest back into XDR and create the correlation rule. Please ensure you have pro per GB license for it.

Ashutosh Patil

Hello,

 

Thank you very much for the answer, you are helping me enormously. The question is that the idea I had was to do what you said in point number 1.

 

But I can not identify in the telemetry the event that allows me to perform the correlation rule to warn us.

 

Thank you very much for your help.

 

Best regards.

  • 1200 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!