Skip to content

CyberArk Privileged Threat Analytics

You can integrate CyberArk Privileged Threat Analytics (PTA) with Sophos XDR so that it sends data to Sophos for analysis.

This page gives you an overview of the integration.

CyberArk PTA product overview

CyberArk Privileged Threat Analytics (PTA) continuously monitors the use of privileged accounts managed by the CyberArk Privileged Access Manager platform, as well as unmanaged accounts, detecting indications of privileged-account abuse, misuse, and attacks such as Golden Ticket. This integration also ingests events from the CyberArk Digital Vault, the secure, isolated store that holds privileged credentials and controls authenticated access to them, capturing its authentication and audit activity.

What we ingest

Sophos XDR collects CyberArk syslog data by listening for CEF messages your CyberArk deployment forwards to a Sophos XDR data collector. The following log categories are collected:

  • Privileged threat detections: CyberArk PTA alerts for privileged account abuse and misuse.
  • Vault authentication: CyberArk Vault logon events.
  • Vault audit: CyberArk Vault administrative and audit activity.

Event and data types

We ingest the following event and data types from CyberArk PTA:

  • Privileged threat detections: CyberArk Privileged Threat Analytics (PTA) alerts for privileged account abuse, misuse, and attacks, with the detection and risk. Normalized to third-party security alert telemetry.
  • Vault authentication: CyberArk Vault logon events, with the user and result. Normalized to authentication telemetry.
  • Vault audit: CyberArk Vault administrative and configuration audit activity, with the user, object, and action. Normalized to cloud audit telemetry.

Data provided by this integration

Data provided by CyberArk PTA gets normalized to the following schemas:

  • auth
  • cloudaudit
  • thirdpartyalert

For more information about using schemas in Data Lake Search, see Schemas and logical types.

Vendor documentation