CyberArkEPMEventCollector

Collects policy audits, admin audits, and detailed (raw) events from CyberArk Endpoint Privilege Manager (EPM).

Analytics & SIEM · CyberArk Endpoint Privilege Manager

Details

IDCyberArkEPMEventCollector
ProviderCyberArk
CategoryAnalytics & SIEM
From Version8.2.0
Docker Imagedemisto/btfl-soup:1.0.1.10120494
Supported ModulesAgentix XSIAM EDR

README

Collects policy audits, admin audits, and detailed (raw) events from CyberArk Endpoint Privilege Manager (EPM).
This integration was integrated and tested with version 23.12.0 of CyberArk EPM.

Configure CyberArk EPM Event Collector in Cortex

Parameter Description Required
Authentication Method The authentication method to use when connecting to CyberArk EPM. Options: Idira OAuth, EPM, SAML. True
SAML/EPM Logon URL Required for EPM and SAML authentication methods only. SAML example: https://login.epm.cyberark.com/SAML/Logon. False
Identity URL Required for Idira OAuth authentication only. The CyberArk Identity FQDN, e.g. https://<sub-domain>.id.cyberark.cloud. Used only to obtain the OAuth token; must not include a /oauth2/token suffix. False
Web App ID Required for Idira OAuth authentication only. The registered OAuth2 web-app identifier in CyberArk Identity Administration, used as a URL path segment on the token endpoint (/oauth2/token/<web_app_id>). False
Server URL (only for Idira OAuth) Required for OAuth 2.0 only. For example: https://example.epm.cyberark.com/ False
Username   True
Password   True
Set name A comma-separated list of set names. True
Application ID Required for local(EPM) authentication only. False
Authentication URL Required for SAML authentication only, Example for PAN OKTA: https://paloaltonetworks.okta.com/api/v1/authn. False
Application URL Required for SAML authentication only, Example for PAN OKTA: https://paloaltonetworks.okta.com/home/[APP_NAME]/[APP_ID]. False
Trust any certificate (not secure)   False
Use system proxy settings   False
Maximum number of events per fetch   False

Commands

You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.

cyberarkepm-get-admin-audits


Gets admin audits from Cyber Ark EPM.

Base Command

cyberarkepm-get-admin-audits

Input

Argument Name Description Required
should_push_events If true, the command will create events, otherwise it will only display them. Possible values are: true, false. Default is false. Required
limit Maximum number of results to return. Optional
from_date Date to return results from. (in ISO format ‘01-01-24T00:00:00.123Z’). Optional

Human Readable Output

Admin Audits

Administrator Description EventTime Feature InternalSessionId LoggedAt LoggedFrom PermissionDescription Role SetName _time eventTypeXsiam
admin@paloaltonetworks.com API Get Admin audit data /API/Sets/47f5830e-383a-4db1-9e5f-b38ed0448a92/AdminAudit?dateFrom=2023-12-17T12:17:35.384Z&limit=250 GET DateFrom: 2023-12-17T12:17:35.384Z, DateTo: , offset: 0, limit: 250 2023-12-17T12:38:26.53Z Public API 239076 2023-12-14T13:09:49.81Z 1.1.1.1 None SetUser PANW Production(palo alto networks inc.) 2023-12-17T12:38:26.53Z set admin audit data
admin@paloaltonetworks.com API Get Admin audit data /API/Sets/47f5830e-383a-4db1-9e5f-b38ed0448a92/AdminAudit?dateFrom=2023-12-17T12:38:01.454Z&limit=250 GET DateFrom: 2023-12-17T12:38:01.454Z, DateTo: , offset: 0, limit: 250 2023-12-17T12:39:26.703Z Public API 239076 2023-12-14T13:09:49.81Z 1.1.1.1 None SetUser PANW Production(palo alto networks inc.) 2023-12-17T12:39:26.703Z set admin audit data

Context Output

There is no context output for this command.

cyberarkepm-get-policy-audits


Gets policy audits from Cyber Ark EPM.

Base Command

cyberarkepm-get-policy-audits

Input

Argument Name Description Required
should_push_events If true, the command will create events, otherwise it will only display them. Possible values are: true, false. Default is false. Required
limit Maximum number of results to return. Optional
from_date Date to return results from. (in ISO format ‘01-01-24T00:00:00.123Z’). Optional

Human Readable Output

Policy Audits

_time accessTargetName accessTargetType agentEventCount agentId applicationSubType arguments arrivalTime authorizationRights bundleName bundleVersion codeURL commandInfo company computerName displayName eventType eventTypeXsiam fileAccessPermission fileDescription fileName filePath fileQualifier fileSize fileVersion firstEventDate hash interpreter justification justificationEmail lastEventDate mimeType modificationTime operatingSystemType originUserUID originalFileName owner packageName policyAction policyName productCode productName productVersion publisher runAsUsername skippedCount sourceName sourceType symLink upgradeCode userIsAdmin userName workingDirectory
2023-12-17T12:43:54.659Z   Internet 363 6ebc011f-bdbd-4e0c-84ac-8ea7611c4019     2023-12-17T12:43:54.659Z   Google Chrome Helper (Renderer) 6045.199       M-VKY33Q227Q Google Chrome Helper (Renderer) (Google Chrome Helper (Renderer)) Launch policy audit raw event details     Google Chrome Helper (Renderer) /Applications/Google Chrome.app/Contents/Frameworks/Google Chrome Framework.framework/Versions/119.0.6045.199/Helpers/Google Chrome Helper (Renderer).app/Contents/MacOS/Google Chrome Helper (Renderer) 6843642769839712425 518832   2023-12-17T04:44:50Z 537ce868dd185f032e7ae18900eb3ec100ed35ef       2023-12-17T12:43:37Z   2023-11-27T22:43:23Z MacOS     root Google Chrome Helper (Renderer) (Google Chrome Helper (Renderer)) Run Normally panw-macos-prod-all-users-allow       Google LLC (EQHXZ8M8AV)   0 /Applications/Google Chrome.app/Contents/Frameworks/Google Chrome Framework.framework/Versions/119.0.6045.199/Helpers/Google Chrome Helper (Renderer).app/Contents/MacOS/Google Chrome Helper (Renderer) LocalDisk     true .\csvensson  
2023-12-17T12:43:54.658Z   Internet 16 6ebc011f-bdbd-4e0c-84ac-8ea7611c4019     2023-12-17T12:43:54.658Z   WeatherWidget 484       M-VKY33Q227Q WeatherWidget (WeatherWidget) Launch policy audit raw event details     WeatherWidget /System/Applications/Weather.app/Contents/PlugIns/WeatherWidget.appex/Contents/MacOS/WeatherWidget 2810527046663450530 3733952   2023-12-17T04:52:33Z 951815b591c7255b6de67adac3931549892c2fee       2023-12-17T12:43:30Z   2023-11-02T22:44:56Z MacOS     root WeatherWidget (WeatherWidget) Run Normally panw-macos-prod-all-users-allow       Software Signing   0 /System/Applications/Weather.app/Contents/PlugIns/WeatherWidget.appex/Contents/MacOS/WeatherWidget LocalDisk     true .\csvensson  

Context Output

There is no context output for this command.

cyberarkepm-get-events


Gets events from Cyber Ark EPM.

Base Command

cyberarkepm-get-events

Input

Argument Name Description Required
should_push_events If true, the command will create events, otherwise it will only display them. Possible values are: true, false. Default is false. Required
limit Maximum number of results to return. Optional
from_date Date to return results from. (in ISO format ‘01-01-24T00:00:00.123Z’). Optional

Human Readable Output

Detailed Evens

_time accessAction accessTargetName accessTargetType agentEventCount agentId applicationSubType arrivalTime authorizationRights bundleId bundleName bundleVersion company computerName deceptionType displayName eventCount eventType eventTypeXsiam evidences exposedUsers fatherProcess fileAccessPermission fileDescription fileName filePath filePathWithoutFilename fileQualifier fileSize fileVersion firstEventDate hash interpreter justification justificationEmail lastEventDate logonAttemptTypeId logonStatusId lureUser modificationTime operatingSystemType originUserUID originalFileName owner packageName policyCategory policyName processCertificateIssuer processCommandLine productCode productName productVersion publisher runAsUsername skippedCount sourceName sourceProcessCertificateIssuer sourceProcessCommandLine sourceProcessHash sourceProcessPublisher sourceProcessSigner sourceProcessUsername sourceType sourceWSIp sourceWSName symLink threatProtectionAction threatProtectionActionId upgradeCode userIsAdmin userName winEventRecordId winEventType workingDirectory
2023-12-17T12:37:11.855Z false   Internet 1 f8443d50-4e35-442e-a886-d543080d5def   2023-12-17T12:37:11.855Z         Microsoft Corporation W-5CG3423Q0T 0 Settings (SystemSettingsAdminFlows.exe) 1 Trust detailed raw         Settings SystemSettingsAdminFlows.exe C:\WINDOWS\system32\SystemSettingsAdminFlows.exe C:\WINDOWS\system32\ 4965081445568567330 683304 10.0.22621.2792 2023-12-17T12:37:06.555Z 6F15BDE5240C45B44449A82B0F7F834D7993AE8C       2023-12-17T12:37:06.555Z 0 0   2023-12-15T02:32:22.31Z Windows   SystemSettingsAdminFlows.EXE NT SERVICE\TrustedInstaller Microsoft® Windows® Operating System (TiWorker.exe)       ChangeStartupTaskStatus 9223372036854775808 "Logitech Download Assistant" 0   Microsoft® Windows® Operating System 10.0.22621.2792 Microsoft Windows   0 Microsoft® Windows® Operating System (TiWorker.exe)             LocalDisk       ALL 0   true PALOALTONETWORK\cbartuvia 0 0  
2023-12-17T12:36:16.408Z false   Internet 1 f8443d50-4e35-442e-a886-d543080d5def   2023-12-17T12:36:16.408Z         Microsoft Corporation W-5CG3423Q0T 0 Settings (SystemSettingsAdminFlows.exe) 1 Trust detailed raw         Settings SystemSettingsAdminFlows.exe C:\WINDOWS\system32\SystemSettingsAdminFlows.exe C:\WINDOWS\system32\ 4965081445568567330 683304 10.0.22621.2792 2023-12-17T12:36:10.435Z 6F15BDE5240C45B44449A82B0F7F834D7993AE8C       2023-12-17T12:36:10.435Z 0 0   2023-12-15T02:32:22.31Z Windows   SystemSettingsAdminFlows.EXE NT SERVICE\TrustedInstaller Microsoft® Windows® Operating System (TiWorker.exe)       ChangeStartupTaskStatus 9223372036854775808 "RTKUGUI" 0   Microsoft® Windows® Operating System 10.0.22621.2792 Microsoft Windows   0 Microsoft® Windows® Operating System (TiWorker.exe)             LocalDisk       ALL 0   true PALOALTONETWORK\cbartuvia 0 0  

Context Output

There is no context output for this command.

Configuration parameters

  • authentication_method — Authentication Method (required)
  • server_url — Server URL (only for Idira Oauth)
  • url — SAML/EPM Logon URL
  • identity_url — Identity URL
  • web_app_id — Web App ID
  • credentials — Username (required)
  • set_name — Set name (required)
  • application_id — Application ID
  • authentication_url — Authentication URL
  • application_url — Application URL
  • insecure — Trust any certificate (not secure)
  • proxy — Use system proxy settings
  • max_fetch — Maximum number of events per fetch
  • enable_admin_audits — Enable admin audits events
  • policy_audits_event_type — Policy Audit Events
  • raw_events_event_type — Detailed Events
  • isFetchEvents — Fetch events
  • eventFetchInterval — Events Fetch Interval

Commands (3)

  • cyberarkepm-get-admin-audits

    Gets admin audits from Cyber Ark EPM.

  • cyberarkepm-get-events

    Gets events from Cyber Ark EPM. Use this command for development and debugging only, as it may produce duplicate events, exceed API rate limits, or disrupt the fetch mechanism.

  • cyberarkepm-get-policy-audits

    Gets policy audits from Cyber Ark EPM.

## CyberArk EPM Help

### Authentication
There are three methods to authenticate: EPM, SAML (currently only via Okta), and Idira OAuth (CyberArk Identity / ISPSS).
Every method needs different parameters as show in the following:

* EPM authentication
    - **url**: `https://<EPM_server>` (for example: https://login.epm.cyberark.com/login)
    - **username**
    - **password**
    - [**application ID**](https://docs.cyberark.com/Idaptive/Latest/en/Content/Applications/AppsOvw/SpecifyAppID.htm#%23SpecifytheApplicationID)
    - **set name** (comma separated value)


* SAML authentication (advanced settings) currently supported only via Okta.
    - **url**: `https://login.epm.cyberark.com/SAML/Logon`
    - **username**
    - **password**
    - **authentication URL** [Okta example](https://developer.okta.com/docs/reference/api/authn/#authentication-operations): `https://[COMPANY_NAME].okta.com/api/v1/authn`
    - **Application URL**: `https://[COMPANY_NAME].okta.com/home/[APP_NAME]/[APP_ID]`
    - **Set name** (comma separated value)


* Idira OAuth authentication (CyberArk Identity / ISPSS).
    - **Server URL**: the EPM server address, for example: `https://example.epm.cyberark.com/`
    - **Identity URL**: The CyberArk Identity FQDN, for example: `https://<sub-domain>.id.cyberark.cloud` (used only to obtain the OAuth token)
    - **Web App ID**: The web app's application ID / alias (see the vendor-side setup below)
    - **Username** (the service-user login, used as the Client ID)
    - **Password** (the service-user password, used as the Client Secret)
    - **Set name** (comma separated value)

#### Vendor-side setup for the Idira OAuth (CyberArk Identity / ISPSS) method

1. **Create a service user for API requests** — In Identity Administration go to **Core Services > Users > Add User**. Set a **Login name**, **Display name**, and **Password**. Select **Is OAuth confidential client**, **Is Service User**, and **Password never expires**. Click **Create User**.
   > The service-user login becomes the Client ID; its password becomes the Client Secret.

2. **Create the custom permission group (EPM Management Console)** — Log in to the EPM Management Console as an Account Administrator. In the navigation pane, under **Administration**, select **Permission groups**, then click **Create custom permission group**. Enter a name (e.g. `API_Audit_Viewer`) and an optional description. From the **Based on** dropdown, select **View Only Set Admin** as the starting point. In the permissions matrix, fine-tune access so the API user can query the needed endpoints:
   - **Sets**: Ensure **Set visibility** is enabled.
   - **Policy Audit**: Ensure **View Audit** (or the top-level Policy Audit permission) is enabled.
   - Turn off any other permissions the API service user does not need. Click **Create**.

3. **Create an EPM role using the custom group (EPM Management Console)** — Permission groups cannot be assigned to users directly; they must be bundled with specific Sets into a Role. Still in the EPM Management Console, go to **Administration > Roles** and click **Create role**. Enter a name (e.g. `API_Set_Auditor_Role`), select the custom permission group you just created (`API_Audit_Viewer`), select the specific Set(s) the API is allowed to query, and click **Create**.

4. **Assign the role to your API service user (Identity Administration)** — Once created in EPM, the role automatically syncs to CyberArk Identity Administration with an `EPM_` prefix. Switch to the Identity Administration console, go to **Core Services > Roles**, and search for the role using the `EPM_` prefix (e.g. `EPM_API_Set_Auditor_Role`). Open the role, go to the **Members** tab, click **Add**, search for your OAuth API service user, select it, and click **Add**.
   > Sync between EPM and Identity Administration can take a few moments. If the new `EPM_` role does not appear in Identity Administration immediately, wait a minute or two and refresh.

5. **Create a custom EPM API web app** — In **Apps & Widgets > Web Apps > Add Web Apps**, search for `EPM`, add **Idira EPM API Client**, confirm, and save the required Settings.
   > The web app's application ID / alias becomes the **Web App ID**.

6. **Configure token expiration and bind the service user** — In the web app's **Tokens** tab, set the token expiration period and save. In the **Permissions** tab, add the service user and save. The web app status should become **Deployed**.

7. **Identify the Identity URL** — The CyberArk Identity FQDN, e.g. `https://<sub-domain>.id.cyberark.cloud` (used only to obtain the OAuth token).

### Fetch Information

- There are three event types that are fetched for the Event Collector:
    * Policy audits.
    * Admin audits.
    * Events.

* The **Set name** parameter contains a list of names to which the events are related.
* The **Maximum number of events per fetch** parameter applies to each event type and each name in the **Set name** parameter. For example, if **Maximum number of events per fetch** is set to 1000, the total maximum events fetched is equal to 3000 multiplied by the total number of names specified in the **Set name** parameter.
* The **Maximum number of events per fetch** parameter applies to each event type and each name in the **Set name** parameter. For example, if **Maximum number of events per fetch** is set to 1000, the total maximum events fetched is equal to 3000 multiplied by the total number of names specified in the **Set name** parameter.