CyberArk Privileged Threat Analytics
You can integrate CyberArk Privileged Threat Analytics (PTA) with Sophos XDR so that it sends data to Sophos for analysis.
This page gives you an overview of the integration.
CyberArk PTA product overview
CyberArk Privileged Threat Analytics (PTA) continuously monitors the use of privileged accounts managed by the CyberArk Privileged Access Manager platform, as well as unmanaged accounts, detecting indications of privileged-account abuse, misuse, and attacks such as Golden Ticket. This integration also ingests events from the CyberArk Digital Vault, the secure, isolated store that holds privileged credentials and controls authenticated access to them, capturing its authentication and audit activity.
What we ingest
Sophos XDR collects CyberArk syslog data by listening for CEF messages your CyberArk deployment forwards to a Sophos XDR data collector. The following log categories are collected:
- Privileged threat detections: CyberArk PTA alerts for privileged account abuse and misuse.
- Vault authentication: CyberArk Vault logon events.
- Vault audit: CyberArk Vault administrative and audit activity.
Event and data types
We ingest the following event and data types from CyberArk PTA:
- Privileged threat detections: CyberArk Privileged Threat Analytics (PTA) alerts for privileged account abuse, misuse, and attacks, with the detection and risk. Normalized to third-party security alert telemetry.
- Vault authentication: CyberArk Vault logon events, with the user and result. Normalized to authentication telemetry.
- Vault audit: CyberArk Vault administrative and configuration audit activity, with the user, object, and action. Normalized to cloud audit telemetry.
Data provided by this integration
Data provided by CyberArk PTA gets normalized to the following schemas:
authcloudauditthirdpartyalert
For more information about using schemas in Data Lake Search, see Schemas and logical types.