D-21
User Guide for Cisco Security MARS Local Controller
78-17020-01
Appendix D System Rules and Reports
List of System Reports
•
Activity: Host Privilege Escalation - Top Hosts.
This report records ranks the hosts by access privilege escalation attempts attempted against them.
Such attempts can happen remotely or from the local console and can be reported by Network or
Host IDS devices or the hosts themselves
•
Activity: Host Privilege Escalation - Top Hosts.
Activity: Host Privilege Escalation - Top Hosts
•
Activity: Host Privileged Access - All Events.
This report records all Microsoft Windows Host Privileged Access events from Windows Event
Logs.
•
Activity: Host Privileged Access - All Events.
Activity: Host Privileged Access - All Events
•
Activity: Host Process Tracking - All Events.
This report records all Microsoft Windows Detailed Process Tracking events from Windows Event
Logs.
•
Activity: Host Process Tracking - All Events.
Activity: Host Process Tracking - All Events
•
Activity: Host Registry Changes - All Events.
This report records the events signalling Microsoft Windows registry changes.
•
Activity: Host Registry Changes - All Events.
Activity: Host Registry Changes - All Events
•
Activity: Host Registry Changes - Top Host.
This report ranks hosts by the number of Microsoft Windows registry changes reported.
•
Activity: Host Registry Changes - Top Host.
Activity: Host Registry Changes - Top Host
•
Activity: Host Security Policy Changes - All Events.
This report lists all policy changes on a host affecting host security. These events are typically
reported by Host IDS and host agents.
•
Activity: Host Security Policy Changes - All Events.
This report lists all policy changes on a host affecting host security. These events are typically
reported by Host IDS and host agents.
•
Activity: Host Security Policy Changes - Top Host.
This report ranks hosts by the number of security policy changes on that host.
•
Activity: Host Security Policy Changes - Top Host.
Activity: Host Security Policy Changes - Top Host
•
Activity: Host System Events - All Events.
This report records the Microsoft Windows system events, e.g. startup, shutdown, LSA registration,
audit event discards, etc.
•
Activity: Host System Events - All Events.
Activity: Host System Events - All Events
•
Activity: Host User/Group Management - All Events.