Microsoft ATA
ArchivedThe Microsoft ATA application enables you to monitor and identify threats in your organization using data from Microsoft ATA. You can further analyze the data using alerts and pre-set dashboard views.
Release Details
Package Details
- Component
- LP_Microsoft ATA_Pass the ticket
- LP_Microsoft ATA_Suspicious replication of directory services
- LP_Microsoft ATA_Database used by a Center is Down
- LP_Microsoft ATA_Identity theft using Pass-the-Ticket attack
- LP_Microsoft ATA_Malicious Data Protection Private Information Request
- LP_Microsoft ATA_Pass-the-hash
- LP_Microsoft ATA
- MicrosoftATANormalizer
Installation
Follow these steps to install the Microsoft ATA v5.1.0 application:
- Download the Microsoft ATA package from the Download section above.
- Add Microsoft ATA as the required device in LogPoint.
- Create a collection policy with the Syslog collector and an appropriate processing policy.
- Assign the policy to the device.
- Add the dashboard.
Log Format
Microsoft ATA v1.x
Expected Log Format
CEF
Log Sample
CEF:0|Microsoft|ATA|1.9.0.0|AbnormalSensitiveGroupMembershipChangeSuspiciousActivity|Abnormal modification of sensitive groups|5|start=2020-1-12T18:52:58.0000000Z app=GroupMembershipChangeEvent suser=abc msg=abc has uncharacteristically modified sensitive group memberships. externalId=1234 cs1Label=url cs1=https://1.1.1.1/suspiciousActivity/xxxxxxxxxxxxx
To export data to LogPoint, use the Syslog collector on port 514 of the LogPoint server.
Microsoft ATA v1.x
Expected Log Format
CEF
Log Sample
CEF:0|Microsoft|ATA|1.9.0.0|AbnormalSensitiveGroupMembershipChangeSuspiciousActivity|Abnormal modification of sensitive groups|5|start=2020-1-12T18:52:58.0000000Z app=GroupMembershipChangeEvent suser=abc msg=abc has uncharacteristically modified sensitive group memberships. externalId=1234 cs1Label=url cs1=https://1.1.1.1/suspiciousActivity/xxxxxxxxxxxxx
To export data to LogPoint, use the Syslog collector on port 514 of the LogPoint server.
Support
If you have any questions or require assistance, create a support ticket.
Comments
Article is closed for comments.