<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security Endpoint associated user to computers in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/security-endpoint-associated-user-to-computers/m-p/4614162#M6879</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1356192"&gt;@ggadaleta&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I do have Device Insights enabled with the sources from Cisco Secure Endpoint and Cisco Orbital enabled.&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I am seeing is that the Associated User field is populated from the deduplicated results of the following two Orbital queries:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;SELECT username as localUsername FROM users where type == "local";&lt;/PRE&gt;&lt;PRE&gt;SELECT user as loggedInUser FROM logged_in_users where user != "";&lt;/PRE&gt;&lt;P&gt;The Associated User field is not carried over into the Cisco Secure Endpoint console and there is not a quick link between Device Trajectory page and the Device Insights page. There is neither a pivot menu option nor Ribbon option to move to the Device Insights information for that hostname or IP address.&lt;/P&gt;&lt;P&gt;Assuming that the host is online, it would be easier to just hit the "Orbital Query" button from the Device Trajectory page and enter a query for gathering user information or using Orbital in the Ribbon (clicking "Get Endpoints" and select a query for user information) than to jump out to SecureX, select "Insights" and then search for the hostname.&lt;BR /&gt;Hopefully future release of the Cisco Secure Endpoint console will include some better options for utilizing the Device Insights Information.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 20 May 2022 14:50:34 GMT</pubDate>
    <dc:creator>johnosn</dc:creator>
    <dc:date>2022-05-20T14:50:34Z</dc:date>
    <item>
      <title>Security Endpoint associated user to computers</title>
      <link>https://community.cisco.com/t5/endpoint-security/security-endpoint-associated-user-to-computers/m-p/4612897#M6871</link>
      <description>&lt;P&gt;hi there,&lt;/P&gt;
&lt;P&gt;I've enrolled some computers in AMP and now want to "link" computers to users. I've checked the documentation and I haven't found any possible solution.&lt;/P&gt;
&lt;P&gt;When I go in Insight in SecureX and see the device, I see a field "Associated user" which is empty. So it seem there must be a way to "Associate" the computer to a user.&lt;/P&gt;
&lt;P&gt;thanks in advance&lt;/P&gt;
&lt;P&gt;rgds&lt;/P&gt;
&lt;P&gt;Giovanni&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2022 09:31:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/security-endpoint-associated-user-to-computers/m-p/4612897#M6871</guid>
      <dc:creator>ggadaleta</dc:creator>
      <dc:date>2022-05-19T09:31:38Z</dc:date>
    </item>
    <item>
      <title>Re: Security Endpoint associated user to computers</title>
      <link>https://community.cisco.com/t5/endpoint-security/security-endpoint-associated-user-to-computers/m-p/4612935#M6872</link>
      <description>&lt;P&gt;Endpoint security is the practice of securing endpoints or entry points of end-user devices such as desktops, laptops, and mobile devices from being exploited by malicious actors and campaigns. Endpoint security systems protect these endpoints on a network or in the cloud from cybersecurity threats.&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FFFFFF"&gt;&lt;A href="https://www.prepaidgiftbalance.bid/" target="_self"&gt;&lt;FONT color="#FFFFFF"&gt;prepaidgiftbalance.com&lt;/FONT&gt;&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 20 May 2022 05:14:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/security-endpoint-associated-user-to-computers/m-p/4612935#M6872</guid>
      <dc:creator>Perez69</dc:creator>
      <dc:date>2022-05-20T05:14:30Z</dc:date>
    </item>
    <item>
      <title>Re: Security Endpoint associated user to computers</title>
      <link>https://community.cisco.com/t5/endpoint-security/security-endpoint-associated-user-to-computers/m-p/4612986#M6873</link>
      <description>What sources do you have available in Insights?  If I remember correctly, user comes from Orbital, so if you don't have Secure Endpoint Advantage, you won't have this data.&lt;BR /&gt;&lt;BR /&gt;You can also add a custom feed in Insights to tie users to machine.&lt;BR /&gt;&lt;BR /&gt;I'm not sure about the MDM feeds (Intune, Jamf,  etc.)&lt;BR /&gt;</description>
      <pubDate>Thu, 19 May 2022 11:44:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/security-endpoint-associated-user-to-computers/m-p/4612986#M6873</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2022-05-19T11:44:42Z</dc:date>
    </item>
    <item>
      <title>Re: Security Endpoint associated user to computers</title>
      <link>https://community.cisco.com/t5/endpoint-security/security-endpoint-associated-user-to-computers/m-p/4613007#M6875</link>
      <description>&lt;P&gt;I do have Secure Endpoint Advantage.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Would you please give some more hints on how to get this info from orbital ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;txs&lt;/P&gt;
&lt;P&gt;ciao&lt;/P&gt;
&lt;P&gt;Giovanni&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2022 12:30:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/security-endpoint-associated-user-to-computers/m-p/4613007#M6875</guid>
      <dc:creator>ggadaleta</dc:creator>
      <dc:date>2022-05-19T12:30:10Z</dc:date>
    </item>
    <item>
      <title>Re: Security Endpoint associated user to computers</title>
      <link>https://community.cisco.com/t5/endpoint-security/security-endpoint-associated-user-to-computers/m-p/4613049#M6877</link>
      <description>In Insights, in the column on the left, click on Sources&lt;BR /&gt;At the top right, click on "Add More Sources"&lt;BR /&gt;Find Orbital in the list of Integrations, and click the "+Add button"&lt;BR /&gt;Make sure the Integration with Device Insights button is checked, click Save.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 19 May 2022 13:09:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/security-endpoint-associated-user-to-computers/m-p/4613049#M6877</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2022-05-19T13:09:42Z</dc:date>
    </item>
    <item>
      <title>Re: Security Endpoint associated user to computers</title>
      <link>https://community.cisco.com/t5/endpoint-security/security-endpoint-associated-user-to-computers/m-p/4614162#M6879</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1356192"&gt;@ggadaleta&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I do have Device Insights enabled with the sources from Cisco Secure Endpoint and Cisco Orbital enabled.&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I am seeing is that the Associated User field is populated from the deduplicated results of the following two Orbital queries:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;SELECT username as localUsername FROM users where type == "local";&lt;/PRE&gt;&lt;PRE&gt;SELECT user as loggedInUser FROM logged_in_users where user != "";&lt;/PRE&gt;&lt;P&gt;The Associated User field is not carried over into the Cisco Secure Endpoint console and there is not a quick link between Device Trajectory page and the Device Insights page. There is neither a pivot menu option nor Ribbon option to move to the Device Insights information for that hostname or IP address.&lt;/P&gt;&lt;P&gt;Assuming that the host is online, it would be easier to just hit the "Orbital Query" button from the Device Trajectory page and enter a query for gathering user information or using Orbital in the Ribbon (clicking "Get Endpoints" and select a query for user information) than to jump out to SecureX, select "Insights" and then search for the hostname.&lt;BR /&gt;Hopefully future release of the Cisco Secure Endpoint console will include some better options for utilizing the Device Insights Information.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 May 2022 14:50:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/security-endpoint-associated-user-to-computers/m-p/4614162#M6879</guid>
      <dc:creator>johnosn</dc:creator>
      <dc:date>2022-05-20T14:50:34Z</dc:date>
    </item>
    <item>
      <title>Re: Security Endpoint associated user to computers</title>
      <link>https://community.cisco.com/t5/endpoint-security/security-endpoint-associated-user-to-computers/m-p/4614169#M6880</link>
      <description>&lt;P&gt;Here is the current list of Orbital queries that Device Insights uses for reference.&lt;/P&gt;&lt;PRE&gt;-- users
SELECT username AS localUsername 
FROM users 
WHERE type == "local";

-- logged_in_users
SELECT user AS loggedInUser 
FROM logged_in_users 
WHERE user != "";

-- time
SELECT 
	timezone, 
	local_timezone 
FROM time;

-- certificates
SELECT 
	common_name, 
	subject, 
	issuer, 
	ca 
FROM certificates;

-- registry
SELECT 
	firewall AS "firewall", 
	autoupdate AS "autoupdate", 
	antivirus AS "antivirus", 
	antispyware AS "antispyware", 
	internet_settings AS "internet_settings", 
	windows_security_center_service AS "windows_security_center_service", 
	(SELECT 
		CASE 
			WHEN DATA = 1 THEN "Good" ELSE "Poor" 
		END AS user_account_control
		FROM registry
		WHERE PATH = "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA" 
	) AS "user_account_control" 
FROM windows_security_center;

-- windows_security_products
SELECT * 
FROM windows_security_products;

-- bitlocker_info
SELECT * 
FROM bitlocker_info

-- Win32_DeviceGuard
SELECT 
	AvailableSecurityProperties, 
	CodeIntegrityPolicyEnforcementStatus, 
	RequiredSecurityProperties, 
	SecurityServicesConfigured, 
	SecurityServicesRunning, 
	UsermodeCodeIntegrityPolicyEnforcementStatus, 
	VirtualizationBasedSecurityStatus 
FROM Win32_DeviceGuard;

-- drivers
SELECT 
	device_id, 
	device_name, 
	description, 
	provider, 
	signed 
FROM drivers;

-- registry
SELECT 
	key AS reg_key, 
	path, 
	name, 
	data, 
	DATETIME(mtime, "unixepoch", "UTC") 
FROM registry 
WHERE (
	key LIKE "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sharedaccess\parameters\firewallpolicy\%profile" OR 
	key LIKE "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sharedaccess\parameters\firewallpolicy\%profile" OR 
	key LIKE "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sharedaccess\parameters\firewallpolicy\%profile" OR 
	key LIKE "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\%profile"
	) AND 
	name LIKE "EnableFirewall";

-- system_info
SELECT 
	uuid, 
	hostname, 
	hardware_vendor, 
	hardware_model, 
	hardware_version, 
	hardware_serial, 
	computer_name, 
	local_hostname 
FROM system_info

-- registry
SELECT 
	name, 
	key, 
	data 
FROM registry 
WHERE 
	key LIKE "HKEY_CLASSES_ROOT\Installer\Products\%%" AND 
	(
		data LIKE "%%DUO%%" OR 
		data LIKE "%%AMP%%" OR 
		data LIKE "%%AnyConnect%%"
	);

-- registry
SELECT SUBSTR(data, -24, 24) AS sid 
FROM registry 
WHERE 
	key = "HKEY_LOCAL_MACHINE\SECURITY\SAM\Domains\Account" AND 
	name == "V";&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 May 2022 15:07:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/security-endpoint-associated-user-to-computers/m-p/4614169#M6880</guid>
      <dc:creator>johnosn</dc:creator>
      <dc:date>2022-05-20T15:07:29Z</dc:date>
    </item>
    <item>
      <title>Re: Security Endpoint associated user to computers</title>
      <link>https://community.cisco.com/t5/endpoint-security/security-endpoint-associated-user-to-computers/m-p/4614197#M6882</link>
      <description>I was in the Device Insights Design Program and Beta, and asked for this... so they know it's a thing people want.&lt;BR /&gt;I was also using it before Orbital was included as a source, so I used a custom import from our asset tracker app to associate user and machine.&lt;BR /&gt;NOW... if you're using Cisco Threat Response, DI data does show up there.&lt;BR /&gt;</description>
      <pubDate>Fri, 20 May 2022 15:46:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/security-endpoint-associated-user-to-computers/m-p/4614197#M6882</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2022-05-20T15:46:17Z</dc:date>
    </item>
  </channel>
</rss>

