Logo
Resources
Documentation Portal Ideas Portal Guardsix Academy License Portal
Resources
Documentation Portal Ideas Portal Guardsix Academy License Portal
Sign in
  1. Guardsix Servicedesk
  2. Products Hub
  3. Marketplace

Microsoft ATA

Archived

The Microsoft ATA application enables you to monitor and identify threats in your organization using data from Microsoft ATA. You can further analyze the data using alerts and pre-set dashboard views. 

Release Details

Version: 5.1.0
Release date: 2021-01-11
Supported On: LogPoint v6.7.4 or later
SHA 256: bf030346c67e5811d424dec7cb64c0ecbb0a6bb5b391e8b85e2eed0a749e3f28
Download

Package Details

  1. Component
    • LP_Microsoft ATA_Pass the ticket
    • LP_Microsoft ATA_Suspicious replication of directory services
    • LP_Microsoft ATA_Database used by a Center is Down
    • LP_Microsoft ATA_Identity theft using Pass-the-Ticket attack
    • LP_Microsoft ATA_Malicious Data Protection Private Information Request
    • LP_Microsoft ATA_Pass-the-hash
    • LP_Microsoft ATA
    • MicrosoftATANormalizer

Installation

Follow these steps to install the Microsoft ATA v5.1.0 application:

  1. Download the Microsoft ATA package from the Download section above.
  2. Add Microsoft ATA as the required device in LogPoint.
  3. Create a collection policy with the Syslog collector and an appropriate processing policy.
  4. Assign the policy to the device.
  5. Add the dashboard.

Log Format

Microsoft ATA v1.x

Expected Log Format

CEF

Log Sample

CEF:0|Microsoft|ATA|1.9.0.0|AbnormalSensitiveGroupMembershipChangeSuspiciousActivity|Abnormal modification of sensitive groups|5|start=2020-1-12T18:52:58.0000000Z app=GroupMembershipChangeEvent suser=abc msg=abc has uncharacteristically modified sensitive group memberships. externalId=1234 cs1Label=url cs1=https://1.1.1.1/suspiciousActivity/xxxxxxxxxxxxx

To export data to LogPoint, use the Syslog collector on port 514 of the LogPoint server.

Microsoft ATA v1.x

Expected Log Format

CEF

Log Sample

CEF:0|Microsoft|ATA|1.9.0.0|AbnormalSensitiveGroupMembershipChangeSuspiciousActivity|Abnormal modification of sensitive groups|5|start=2020-1-12T18:52:58.0000000Z app=GroupMembershipChangeEvent suser=abc msg=abc has uncharacteristically modified sensitive group memberships. externalId=1234 cs1Label=url cs1=https://1.1.1.1/suspiciousActivity/xxxxxxxxxxxxx

To export data to LogPoint, use the Syslog collector on port 514 of the LogPoint server.

Support

If you have any questions or require assistance, create a support ticket.

Comments

Article is closed for comments.

Follow

Related articles

  • Microsoft Defender ATP
  • Lookup
  • Genua Firewall
  • GoogleCloudPlatform
  • Crowdstrike
Consent Required To Proceed
By clicking “I Agree & Download”, you confirm that you are authorized to act on behalf of your organization and you give explicit consent for Guardsix to share your organization’s customer name and log source count with NXLog for the sole purposes of entitlement management, compliance verification, and support delivery related to the embedded NXLog technology in the Guardsix SIEM solution.

This data will not be used for sales or marketing and will not be shared with other third parties. You may withdraw your consent at any time by contacting Guardsix Support; withdrawal will not affect processing already performed.
Cancel I Agree & Download
Privacy policy    EULA    Terms of service   
Copyright © , Guardsix. All rights reserved.

Note: We use cookies that are essential for the smooth functioning of our website.