CyberArk
Telemetry Evidence
These values show how indexed rules identify CyberArk telemetry.Elastic
logs-cyberarkpas.audit* cyberarkpas Kusto
CyberArk_AuditEvents_CL CyberArkEPM
Detection Rules
Elastic #
- CyberArk Privileged Access Security Error source high: Identifies the occurrence of a CyberArk Privileged Access Security (PAS) error level audit event. The event.code correlates to the CyberArk Vault Audit Action Code.
T1078
Kusto #
- CyberArkEPM - Attack attempt not blocked source high: 'This rule triggers on attack attempt which was not blocked by CyberArkEPM.'
T1204 - CyberArkEPM - MSBuild usage as LOLBin source medium: 'Detects usage of msbuild tool as LOLBin.'
T1127 - CyberArkEPM - Multiple attack types source high: 'This rule triggers on multiple attack attemts triggered by same user.'
T1204 - CyberArkEPM - Possible execution of Powershell Empire source high: 'Detects possible execution of Powershell Empire.'
T1204 - CyberArkEPM - Process started from different locations source medium: 'Detects when process started from different locations on a host.'
T1036,T1204 - CyberArkEPM - Renamed Windows binary source high: 'Detects renamed windows binaries.'
T1036,T1204 - CyberArkEPM - Uncommon process Internet access source high: 'Detects access to the Internet by uncommon processes.'
T1036,T1095,T1204 - CyberArkEPM - Uncommon Windows process started from System folder source medium: 'Detects when uncommon windows proccess is started from System folder.'
T1036,T1204 - CyberArkEPM - Unexpected executable extension source medium: 'Detects Windows executable with unexpected extension.'
T1036,T1204 - CyberArkEPM - Unexpected executable location source medium: 'Detects program run from unexpected location.'
T1036,T1204
Show 3 more
- Idira - High-Risk Actions Outside Business Hours source high: Detects privileged or destructive actions (delete/disable/rotate/elevate/etc.) occurring outside standard business hours. Useful for insider misuse or compromised admin detection.
- Idira - Multiple Failed Actions Followed by Success (15m) source medium: Detects 3+ failed actions against an account followed by a success in a short window, indicating brute-force or credential guessing.
- Idira - Sensitive Safe/Permission/Entitlement Changes (with customData) source low: Alerts on control-plane modifications: safes, permissions, roles, entitlements, policy changes. Leverages customData fields such as changeType/role/permission/policy/entitlement to reduce misses.