CyberArkEPMEventCollector
Collects policy audits, admin audits, and detailed (raw) events from CyberArk Endpoint Privilege Manager (EPM).
Analytics & SIEM · CyberArk Endpoint Privilege Manager
Details
| ID | CyberArkEPMEventCollector |
|---|---|
| Provider | CyberArk |
| Category | Analytics & SIEM |
| From Version | 8.2.0 |
| Docker Image | demisto/btfl-soup:1.0.1.10120494 |
| Supported Modules | Agentix XSIAM EDR |
README
Collects policy audits, admin audits, and detailed (raw) events from CyberArk Endpoint Privilege Manager (EPM).
This integration was integrated and tested with version 23.12.0 of CyberArk EPM.
Configure CyberArk EPM Event Collector in Cortex
| Parameter | Description | Required |
|---|---|---|
| Authentication Method | The authentication method to use when connecting to CyberArk EPM. Options: Idira OAuth, EPM, SAML. |
True |
| SAML/EPM Logon URL | Required for EPM and SAML authentication methods only. SAML example: https://login.epm.cyberark.com/SAML/Logon. |
False |
| Identity URL | Required for Idira OAuth authentication only. The CyberArk Identity FQDN, e.g. https://<sub-domain>.id.cyberark.cloud. Used only to obtain the OAuth token; must not include a /oauth2/token suffix. |
False |
| Web App ID | Required for Idira OAuth authentication only. The registered OAuth2 web-app identifier in CyberArk Identity Administration, used as a URL path segment on the token endpoint (/oauth2/token/<web_app_id>). |
False |
| Server URL (only for Idira OAuth) | Required for OAuth 2.0 only. For example: https://example.epm.cyberark.com/ |
False |
| Username | True | |
| Password | True | |
| Set name | A comma-separated list of set names. | True |
| Application ID | Required for local(EPM) authentication only. | False |
| Authentication URL | Required for SAML authentication only, Example for PAN OKTA: https://paloaltonetworks.okta.com/api/v1/authn. |
False |
| Application URL | Required for SAML authentication only, Example for PAN OKTA: https://paloaltonetworks.okta.com/home/[APP_NAME]/[APP_ID]. |
False |
| Trust any certificate (not secure) | False | |
| Use system proxy settings | False | |
| Maximum number of events per fetch | False |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
cyberarkepm-get-admin-audits
Gets admin audits from Cyber Ark EPM.
Base Command
cyberarkepm-get-admin-audits
Input
| Argument Name | Description | Required |
|---|---|---|
| should_push_events | If true, the command will create events, otherwise it will only display them. Possible values are: true, false. Default is false. | Required |
| limit | Maximum number of results to return. | Optional |
| from_date | Date to return results from. (in ISO format ‘01-01-24T00:00:00.123Z’). | Optional |
Human Readable Output
Admin Audits
| Administrator | Description | EventTime | Feature | InternalSessionId | LoggedAt | LoggedFrom | PermissionDescription | Role | SetName | _time | eventTypeXsiam |
|---|---|---|---|---|---|---|---|---|---|---|---|
| admin@paloaltonetworks.com | API Get Admin audit data /API/Sets/47f5830e-383a-4db1-9e5f-b38ed0448a92/AdminAudit?dateFrom=2023-12-17T12:17:35.384Z&limit=250 GET DateFrom: 2023-12-17T12:17:35.384Z, DateTo: , offset: 0, limit: 250 | 2023-12-17T12:38:26.53Z | Public API | 239076 | 2023-12-14T13:09:49.81Z | 1.1.1.1 | None | SetUser | PANW Production(palo alto networks inc.) | 2023-12-17T12:38:26.53Z | set admin audit data |
| admin@paloaltonetworks.com | API Get Admin audit data /API/Sets/47f5830e-383a-4db1-9e5f-b38ed0448a92/AdminAudit?dateFrom=2023-12-17T12:38:01.454Z&limit=250 GET DateFrom: 2023-12-17T12:38:01.454Z, DateTo: , offset: 0, limit: 250 | 2023-12-17T12:39:26.703Z | Public API | 239076 | 2023-12-14T13:09:49.81Z | 1.1.1.1 | None | SetUser | PANW Production(palo alto networks inc.) | 2023-12-17T12:39:26.703Z | set admin audit data |
Context Output
There is no context output for this command.
cyberarkepm-get-policy-audits
Gets policy audits from Cyber Ark EPM.
Base Command
cyberarkepm-get-policy-audits
Input
| Argument Name | Description | Required |
|---|---|---|
| should_push_events | If true, the command will create events, otherwise it will only display them. Possible values are: true, false. Default is false. | Required |
| limit | Maximum number of results to return. | Optional |
| from_date | Date to return results from. (in ISO format ‘01-01-24T00:00:00.123Z’). | Optional |
Human Readable Output
Policy Audits
| _time | accessTargetName | accessTargetType | agentEventCount | agentId | applicationSubType | arguments | arrivalTime | authorizationRights | bundleName | bundleVersion | codeURL | commandInfo | company | computerName | displayName | eventType | eventTypeXsiam | fileAccessPermission | fileDescription | fileName | filePath | fileQualifier | fileSize | fileVersion | firstEventDate | hash | interpreter | justification | justificationEmail | lastEventDate | mimeType | modificationTime | operatingSystemType | originUserUID | originalFileName | owner | packageName | policyAction | policyName | productCode | productName | productVersion | publisher | runAsUsername | skippedCount | sourceName | sourceType | symLink | upgradeCode | userIsAdmin | userName | workingDirectory |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2023-12-17T12:43:54.659Z | Internet | 363 | 6ebc011f-bdbd-4e0c-84ac-8ea7611c4019 | 2023-12-17T12:43:54.659Z | Google Chrome Helper (Renderer) | 6045.199 | M-VKY33Q227Q | Google Chrome Helper (Renderer) (Google Chrome Helper (Renderer)) | Launch | policy audit raw event details | Google Chrome Helper (Renderer) | /Applications/Google Chrome.app/Contents/Frameworks/Google Chrome Framework.framework/Versions/119.0.6045.199/Helpers/Google Chrome Helper (Renderer).app/Contents/MacOS/Google Chrome Helper (Renderer) | 6843642769839712425 | 518832 | 2023-12-17T04:44:50Z | 537ce868dd185f032e7ae18900eb3ec100ed35ef | 2023-12-17T12:43:37Z | 2023-11-27T22:43:23Z | MacOS | root | Google Chrome Helper (Renderer) (Google Chrome Helper (Renderer)) | Run Normally | panw-macos-prod-all-users-allow | Google LLC (EQHXZ8M8AV) | 0 | /Applications/Google Chrome.app/Contents/Frameworks/Google Chrome Framework.framework/Versions/119.0.6045.199/Helpers/Google Chrome Helper (Renderer).app/Contents/MacOS/Google Chrome Helper (Renderer) | LocalDisk | true | .\csvensson | |||||||||||||||||||||||
| 2023-12-17T12:43:54.658Z | Internet | 16 | 6ebc011f-bdbd-4e0c-84ac-8ea7611c4019 | 2023-12-17T12:43:54.658Z | WeatherWidget | 484 | M-VKY33Q227Q | WeatherWidget (WeatherWidget) | Launch | policy audit raw event details | WeatherWidget | /System/Applications/Weather.app/Contents/PlugIns/WeatherWidget.appex/Contents/MacOS/WeatherWidget | 2810527046663450530 | 3733952 | 2023-12-17T04:52:33Z | 951815b591c7255b6de67adac3931549892c2fee | 2023-12-17T12:43:30Z | 2023-11-02T22:44:56Z | MacOS | root | WeatherWidget (WeatherWidget) | Run Normally | panw-macos-prod-all-users-allow | Software Signing | 0 | /System/Applications/Weather.app/Contents/PlugIns/WeatherWidget.appex/Contents/MacOS/WeatherWidget | LocalDisk | true | .\csvensson |
Context Output
There is no context output for this command.
cyberarkepm-get-events
Gets events from Cyber Ark EPM.
Base Command
cyberarkepm-get-events
Input
| Argument Name | Description | Required |
|---|---|---|
| should_push_events | If true, the command will create events, otherwise it will only display them. Possible values are: true, false. Default is false. | Required |
| limit | Maximum number of results to return. | Optional |
| from_date | Date to return results from. (in ISO format ‘01-01-24T00:00:00.123Z’). | Optional |
Human Readable Output
Detailed Evens
| _time | accessAction | accessTargetName | accessTargetType | agentEventCount | agentId | applicationSubType | arrivalTime | authorizationRights | bundleId | bundleName | bundleVersion | company | computerName | deceptionType | displayName | eventCount | eventType | eventTypeXsiam | evidences | exposedUsers | fatherProcess | fileAccessPermission | fileDescription | fileName | filePath | filePathWithoutFilename | fileQualifier | fileSize | fileVersion | firstEventDate | hash | interpreter | justification | justificationEmail | lastEventDate | logonAttemptTypeId | logonStatusId | lureUser | modificationTime | operatingSystemType | originUserUID | originalFileName | owner | packageName | policyCategory | policyName | processCertificateIssuer | processCommandLine | productCode | productName | productVersion | publisher | runAsUsername | skippedCount | sourceName | sourceProcessCertificateIssuer | sourceProcessCommandLine | sourceProcessHash | sourceProcessPublisher | sourceProcessSigner | sourceProcessUsername | sourceType | sourceWSIp | sourceWSName | symLink | threatProtectionAction | threatProtectionActionId | upgradeCode | userIsAdmin | userName | winEventRecordId | winEventType | workingDirectory |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2023-12-17T12:37:11.855Z | false | Internet | 1 | f8443d50-4e35-442e-a886-d543080d5def | 2023-12-17T12:37:11.855Z | Microsoft Corporation | W-5CG3423Q0T | 0 | Settings (SystemSettingsAdminFlows.exe) | 1 | Trust | detailed raw | Settings | SystemSettingsAdminFlows.exe | C:\WINDOWS\system32\SystemSettingsAdminFlows.exe | C:\WINDOWS\system32\ | 4965081445568567330 | 683304 | 10.0.22621.2792 | 2023-12-17T12:37:06.555Z | 6F15BDE5240C45B44449A82B0F7F834D7993AE8C | 2023-12-17T12:37:06.555Z | 0 | 0 | 2023-12-15T02:32:22.31Z | Windows | SystemSettingsAdminFlows.EXE | NT SERVICE\TrustedInstaller | Microsoft® Windows® Operating System (TiWorker.exe) | ChangeStartupTaskStatus 9223372036854775808 "Logitech Download Assistant" 0 | Microsoft® Windows® Operating System | 10.0.22621.2792 | Microsoft Windows | 0 | Microsoft® Windows® Operating System (TiWorker.exe) | LocalDisk | ALL | 0 | true | PALOALTONETWORK\cbartuvia | 0 | 0 | |||||||||||||||||||||||||||||||
| 2023-12-17T12:36:16.408Z | false | Internet | 1 | f8443d50-4e35-442e-a886-d543080d5def | 2023-12-17T12:36:16.408Z | Microsoft Corporation | W-5CG3423Q0T | 0 | Settings (SystemSettingsAdminFlows.exe) | 1 | Trust | detailed raw | Settings | SystemSettingsAdminFlows.exe | C:\WINDOWS\system32\SystemSettingsAdminFlows.exe | C:\WINDOWS\system32\ | 4965081445568567330 | 683304 | 10.0.22621.2792 | 2023-12-17T12:36:10.435Z | 6F15BDE5240C45B44449A82B0F7F834D7993AE8C | 2023-12-17T12:36:10.435Z | 0 | 0 | 2023-12-15T02:32:22.31Z | Windows | SystemSettingsAdminFlows.EXE | NT SERVICE\TrustedInstaller | Microsoft® Windows® Operating System (TiWorker.exe) | ChangeStartupTaskStatus 9223372036854775808 "RTKUGUI" 0 | Microsoft® Windows® Operating System | 10.0.22621.2792 | Microsoft Windows | 0 | Microsoft® Windows® Operating System (TiWorker.exe) | LocalDisk | ALL | 0 | true | PALOALTONETWORK\cbartuvia | 0 | 0 |
Context Output
There is no context output for this command.
Configuration parameters
authentication_method— Authentication Method (required)server_url— Server URL (only for Idira Oauth)url— SAML/EPM Logon URLidentity_url— Identity URLweb_app_id— Web App IDcredentials— Username (required)set_name— Set name (required)application_id— Application IDauthentication_url— Authentication URLapplication_url— Application URLinsecure— Trust any certificate (not secure)proxy— Use system proxy settingsmax_fetch— Maximum number of events per fetchenable_admin_audits— Enable admin audits eventspolicy_audits_event_type— Policy Audit Eventsraw_events_event_type— Detailed EventsisFetchEvents— Fetch eventseventFetchInterval— Events Fetch Interval
Commands (3)
-
cyberarkepm-get-admin-auditsGets admin audits from Cyber Ark EPM.
-
cyberarkepm-get-eventsGets events from Cyber Ark EPM. Use this command for development and debugging only, as it may produce duplicate events, exceed API rate limits, or disrupt the fetch mechanism.
-
cyberarkepm-get-policy-auditsGets policy audits from Cyber Ark EPM.
## CyberArk EPM Help ### Authentication There are three methods to authenticate: EPM, SAML (currently only via Okta), and Idira OAuth (CyberArk Identity / ISPSS). Every method needs different parameters as show in the following: * EPM authentication - **url**: `https://<EPM_server>` (for example: https://login.epm.cyberark.com/login) - **username** - **password** - [**application ID**](https://docs.cyberark.com/Idaptive/Latest/en/Content/Applications/AppsOvw/SpecifyAppID.htm#%23SpecifytheApplicationID) - **set name** (comma separated value) * SAML authentication (advanced settings) currently supported only via Okta. - **url**: `https://login.epm.cyberark.com/SAML/Logon` - **username** - **password** - **authentication URL** [Okta example](https://developer.okta.com/docs/reference/api/authn/#authentication-operations): `https://[COMPANY_NAME].okta.com/api/v1/authn` - **Application URL**: `https://[COMPANY_NAME].okta.com/home/[APP_NAME]/[APP_ID]` - **Set name** (comma separated value) * Idira OAuth authentication (CyberArk Identity / ISPSS). - **Server URL**: the EPM server address, for example: `https://example.epm.cyberark.com/` - **Identity URL**: The CyberArk Identity FQDN, for example: `https://<sub-domain>.id.cyberark.cloud` (used only to obtain the OAuth token) - **Web App ID**: The web app's application ID / alias (see the vendor-side setup below) - **Username** (the service-user login, used as the Client ID) - **Password** (the service-user password, used as the Client Secret) - **Set name** (comma separated value) #### Vendor-side setup for the Idira OAuth (CyberArk Identity / ISPSS) method 1. **Create a service user for API requests** — In Identity Administration go to **Core Services > Users > Add User**. Set a **Login name**, **Display name**, and **Password**. Select **Is OAuth confidential client**, **Is Service User**, and **Password never expires**. Click **Create User**. > The service-user login becomes the Client ID; its password becomes the Client Secret. 2. **Create the custom permission group (EPM Management Console)** — Log in to the EPM Management Console as an Account Administrator. In the navigation pane, under **Administration**, select **Permission groups**, then click **Create custom permission group**. Enter a name (e.g. `API_Audit_Viewer`) and an optional description. From the **Based on** dropdown, select **View Only Set Admin** as the starting point. In the permissions matrix, fine-tune access so the API user can query the needed endpoints: - **Sets**: Ensure **Set visibility** is enabled. - **Policy Audit**: Ensure **View Audit** (or the top-level Policy Audit permission) is enabled. - Turn off any other permissions the API service user does not need. Click **Create**. 3. **Create an EPM role using the custom group (EPM Management Console)** — Permission groups cannot be assigned to users directly; they must be bundled with specific Sets into a Role. Still in the EPM Management Console, go to **Administration > Roles** and click **Create role**. Enter a name (e.g. `API_Set_Auditor_Role`), select the custom permission group you just created (`API_Audit_Viewer`), select the specific Set(s) the API is allowed to query, and click **Create**. 4. **Assign the role to your API service user (Identity Administration)** — Once created in EPM, the role automatically syncs to CyberArk Identity Administration with an `EPM_` prefix. Switch to the Identity Administration console, go to **Core Services > Roles**, and search for the role using the `EPM_` prefix (e.g. `EPM_API_Set_Auditor_Role`). Open the role, go to the **Members** tab, click **Add**, search for your OAuth API service user, select it, and click **Add**. > Sync between EPM and Identity Administration can take a few moments. If the new `EPM_` role does not appear in Identity Administration immediately, wait a minute or two and refresh. 5. **Create a custom EPM API web app** — In **Apps & Widgets > Web Apps > Add Web Apps**, search for `EPM`, add **Idira EPM API Client**, confirm, and save the required Settings. > The web app's application ID / alias becomes the **Web App ID**. 6. **Configure token expiration and bind the service user** — In the web app's **Tokens** tab, set the token expiration period and save. In the **Permissions** tab, add the service user and save. The web app status should become **Deployed**. 7. **Identify the Identity URL** — The CyberArk Identity FQDN, e.g. `https://<sub-domain>.id.cyberark.cloud` (used only to obtain the OAuth token). ### Fetch Information - There are three event types that are fetched for the Event Collector: * Policy audits. * Admin audits. * Events. * The **Set name** parameter contains a list of names to which the events are related. * The **Maximum number of events per fetch** parameter applies to each event type and each name in the **Set name** parameter. For example, if **Maximum number of events per fetch** is set to 1000, the total maximum events fetched is equal to 3000 multiplied by the total number of names specified in the **Set name** parameter. * The **Maximum number of events per fetch** parameter applies to each event type and each name in the **Set name** parameter. For example, if **Maximum number of events per fetch** is set to 1000, the total maximum events fetched is equal to 3000 multiplied by the total number of names specified in the **Set name** parameter.