Skip to main content
Skip table of contents

QCF – Investigations

The Intelligent Indexing settings are recommendations. The default configuration is No.

NameDescriptionInvestigation IDControl SupportData SourceClassificationsLog Sources
CCF: Account Modification InvThis investigation provides details around account modifications across the environment.709

2.01, 2.03, 2.09, 4.06, 4.15, 4.16, 4.17, 4.21, 4.22, 4.26, 4.31, 4.32, 4.33, 4.41, 4.42, 4.43, 5.06, 5.07, 5.09, 7.01, 7.03, 7.05, 7.08, 7.09, 7.11, 7.12, 7.14, 7.16, 7.17, 8.03, 8.04, 8.09, 8.12, 8.16, 8.17, 9.07, 9.08, 9.1, 9.11, 9.13, 9.16, 9.17, 10.12, 10.16, 11.1, 11.11, 11.13, 12.01, 12.02, 12.03, 12.05, 12.06, 12.07, 12.08, 12.09, 12.1, 12.11, 12.14, 12.15, 12.17, 12.18, 12.19, 12.2, 12.21, 12.22, 12.25, 12.26, 13.07, 13.08, 13.11, 13.12, 13.14, 13.15, 14.02

Platform Manager(s)AuditAll Available Log Sources
CCF: Applications Accessed By User InvThis investigation provides information about user accessed applications.689

2.01, 2.03, 2.09, 4.06, 4.15, 4.16, 4.17, 4.2, 4.21, 4.22, 4.26, 4.31, 4.32, 4.33, 4.41, 4.42, 4.43, 5.06, 5.07, 5.09, 7.01, 7.03, 7.05, 7.08, 7.09, 7.11, 7.12, 7.14, 7.16, 7.17, 8.03, 8.04, 8.09, 8.12, 8.16, 8.17, 9.07, 9.08, 9.1, 9.11, 9.13, 9.16, 9.17, 10.12, 10.16, 11.1, 11.11, 11.13, 13.07, 13.08, 13.11, 13.12, 13.14, 13.15, 14.02

Data Processor(s)AuditAll Available Log Sources
CCF: Audit Log InvThis investigation provides details around potential control failures around auditing systems.  This requires the configuration and enablement of the CCF: Audit Logging Stopped Alarm, CCF: Audit Log Cleared Alarm, CCF: Failed Audit Log Write Alarms.701

2.01, 2.03, 2.04, 2.05, 2.06, 2.09, 2.1, 3.04, 3.05, 4.03, 4.05, 4.06, 4.07, 4.08, 4.09, 4.15, 4.16, 4.17, 4.18, 4.19, 4.21, 4.22, 4.25, 4.26, 4.31, 4.32, 4.33, 4.35, 4.41, 4.42, 4.43, 4.44, 5.06, 5.07, 5.08, 5.09, 6.08, 6.11, 6.15, 6.18, 6.23, 6.24, 7.01, 7.03, 7.05, 7.06, 7.07, 7.08, 7.09, 7.11, 7.12, 7.13, 7.14, 7.15, 7.16, 7.17, 8.03, 8.04, 8.09, 8.12, 8.16, 8.17, 9.07, 9.08, 9.1, 9.11, 9.12, 9.13, 9.16, 9.17, 10.12, 10.16, 11.1, 11.11, 11.13, 12.01, 12.02, 12.03, 12.05, 12.06, 12.07, 12.08, 12.09, 12.1, 12.11, 12.14, 12.15, 12.17, 12.18, 12.19, 12.2, 12.21, 12.22, 12.25, 12.26, 13.07, 13.08, 13.09, 13.11, 13.12, 13.14, 13.15, 14.01, 14.02, 14.04

Platform Manager(s)AuditAll Available Log Sources
CCF: Backup Activity InvThis investigation provides detail around activity from backup events.688

2.03, 2.09, 4.06, 4.07, 4.15, 4.26, 4.31, 4.32, 4.33, 4.41, 4.42, 4.43, 5.06, 5.07, 5.09, 7.01, 7.03, 7.05, 7.08, 7.09, 7.12, 7.14, 7.16, 7.17, 8.03, 8.04, 8.09, 8.12, 8.16, 8.17, 9.07, 9.08, 9.1, 9.11, 9.13, 9.16, 9.17, 10.12, 10.16

Data Processor(s)OperationsAll Available Log Sources
CCF: Compromises Detected InvThis investigation provides a summary of detected compromises of security by Entity and Impacted Host.690

2.03, 2.06, 2.09, 2.1, 4.06, 4.07, 4.09, 4.15, 4.25, 4.26, 4.31, 4.32, 4.33, 4.35, 4.41, 4.42, 4.43, 4.44, 5.06, 5.07, 5.09, 7.01, 7.03, 7.05, 7.06, 7.07, 7.08, 7.09, 7.12, 7.14, 7.15, 7.16, 7.17, 8.03, 8.04, 8.09, 8.12, 8.16, 8.17, 9.07, 9.08, 9.1, 9.11, 9.12, 9.13, 9.16, 9.17, 10.12, 10.16

LogMart(s)SecurityAll Available Log Sources
CCF: Config/Policy Change InvThis investigation provides a summary of the occurrence of configuration or policy changes across critical and production environments (entity structure).675

2.03, 2.04, 2.05, 2.09, 3.04, 3.05, 4.03, 4.05, 4.06, 4.08, 4.15, 4.26, 4.31, 4.32, 4.33, 4.41, 4.42, 4.43, 5.06, 5.07, 5.09, 6.08, 6.11, 6.15, 6.18, 6.23, 6.24, 7.01, 7.03, 7.05, 7.08, 7.09, 7.12, 7.14, 7.16, 7.17, 8.03, 8.04, 8.09, 8.12, 8.16, 8.17, 9.07, 9.08, 9.1, 9.11, 9.13, 9.16, 9.17, 10.12, 10.16, 13.07, 13.08, 13.11, 13.14, 13.15, 14.04

Data Processor(s)AuditAll Available Log Sources
CCF: Critical Environment Error InvThis investigation provides summary details around critical or error messages received from critical servers or systems (entity structure) to support change management procedures.676

2.03, 2.04, 2.05, 2.09, 3.04, 3.05, 4.03, 4.05, 4.06, 4.07, 4.08, 4.15, 4.26, 4.31, 4.32, 4.33, 4.41, 4.42, 4.43, 5.06, 5.07, 5.09, 6.08, 6.11, 6.15, 6.18, 6.23, 6.24, 7.01, 7.03, 7.05, 7.08, 7.09, 7.12, 7.14, 7.16, 7.17, 8.03, 8.04, 8.09, 8.12, 8.16, 8.17, 9.07, 9.08, 9.1, 9.11, 9.13, 9.16, 9.17, 10.12, 10.16, 14.04

Platform Manager(s)OperationsAll Available Log Sources
CCF: Deleted Account InvThis investigation provides detailed information when any new accounts are deleted across any logged environments (entity structure).706

2.01, 2.03, 2.09, 4.06, 4.15, 4.16, 4.17, 4.21, 4.22, 4.26, 4.31, 4.32, 4.33, 4.41, 4.42, 4.43, 5.06, 5.07, 5.09, 7.01, 7.03, 7.05, 7.08, 7.09, 7.11, 7.12, 7.14, 7.16, 7.17, 8.03, 8.04, 8.09, 8.12, 8.16, 8.17, 9.07, 9.08, 9.1, 9.11, 9.13, 9.16, 9.17, 10.12, 10.16, 11.1, 11.11, 11.13, 12.01, 12.02, 12.03, 12.05, 12.06, 12.07, 12.08, 12.09, 12.1, 12.11, 12.14, 12.15, 12.17, 12.18, 12.19, 12.2, 12.21, 12.22, 12.25, 12.26, 13.07, 13.08, 13.11, 13.12, 13.14, 13.15, 14.02

Platform Manager(s)AuditAll Available Log Sources
CCF: Denial of Service InvThis investigation provides details of detected denial of service attempts.707

2.03, 2.06, 2.09, 2.1, 4.06, 4.07, 4.09, 4.15, 4.25, 4.26, 4.31, 4.32, 4.33, 4.35, 4.41, 4.42, 4.43, 4.44, 5.06, 5.07, 5.09, 7.01, 7.03, 7.05, 7.06, 7.07, 7.08, 7.09, 7.11, 7.12, 7.14, 7.15, 7.16, 7.17, 8.03, 8.04, 8.09, 8.12, 8.16, 8.17, 9.07, 9.08, 9.1, 9.11, 9.12, 9.13, 9.16, 9.17, 10.12, 10.16

Data Processor(s)SecurityAll Available Log Sources
CCF: Disabled Account InvThis investigation provides detailed information when any new accounts are revoked (disabled) across any logged environments (entity structure).705

2.01, 2.03, 2.09, 4.06, 4.15, 4.16, 4.17, 4.21, 4.22, 4.26, 4.31, 4.32, 4.33, 4.41, 4.42, 4.43, 5.06, 5.07, 5.09, 7.01, 7.03, 7.05, 7.08, 7.09, 7.11, 7.12, 7.14, 7.16, 7.17, 8.03, 8.04, 8.09, 8.12, 8.16, 8.17, 9.07, 9.08, 9.1, 9.11, 9.13, 9.16, 9.17, 10.12, 10.16, 11.1, 11.11, 11.13, 12.01, 12.02, 12.03, 12.05, 12.06, 12.07, 12.08, 12.09, 12.1, 12.11, 12.14, 12.15, 12.17, 12.18, 12.19, 12.2, 12.21, 12.22, 12.25, 12.26, 13.07, 13.08, 13.11, 13.12, 13.14, 13.15, 14.02

Platform Manager(s)AuditAll Available Log Sources
CCF: Enabled Account InvThis investigation provides detailed information when any new accounts are granted (enabled) across any logged environments (entity structure).704

2.01, 2.03, 2.09, 4.06, 4.15, 4.16, 4.17, 4.21, 4.22, 4.26, 4.31, 4.32, 4.33, 4.41, 4.42, 4.43, 5.06, 5.07, 5.09, 7.01, 7.03, 7.05, 7.08, 7.09, 7.11, 7.12, 7.14, 7.16, 7.17, 8.03, 8.04, 8.09, 8.12, 8.16, 8.17, 9.07, 9.08, 9.1, 9.11, 9.13, 9.16, 9.17, 10.12, 10.16, 11.1, 11.11, 11.13, 12.01, 12.02, 12.03, 12.05, 12.06, 12.07, 12.08, 12.09, 12.1, 12.11, 12.14, 12.15, 12.17, 12.18, 12.19, 12.2, 12.21, 12.22, 12.25, 12.26, 13.07, 13.08, 13.11, 13.12, 13.14, 13.15, 14.02

Platform Manager(s)AuditAll Available Log Sources
CCF: Excessive Authentication Failure InvThis investigation provides detailed information around excessive user account authentication failures  (>10 authentication failures in 30 minutes) across any logged environments (entity structure).708

2.03, 2.09, 4.06, 4.15, 4.16, 4.26, 4.31, 4.32, 4.33, 4.41, 4.42, 4.43, 5.06, 5.07, 5.09, 7.01, 7.03, 7.05, 7.08, 7.09, 7.11, 7.12, 7.14, 7.16, 7.17, 8.03, 8.04, 8.09, 8.12, 8.16, 8.17, 9.07, 9.08, 9.1, 9.11, 9.13, 9.16, 9.17, 10.12, 10.16, 13.07, 13.08, 13.11, 13.12, 13.14, 13.15, 14.02

Platform Manager(s)SecurityAll Available Log Sources
CCF: GeoIP InvThis report summarizes GeoIP activity that is associated with AI Engine GeoIP rules, in the CCF compliance automation suite.696

2.03, 2.09, 4.06, 4.07, 4.15, 4.16, 4.2, 4.21, 4.22, 4.26, 4.31, 4.32, 4.33, 4.41, 4.42, 4.43, 5.06, 5.07, 5.09, 7.01, 7.03, 7.05, 7.08, 7.09, 7.11, 7.12, 7.14, 7.16, 7.17, 8.03, 8.04, 8.09, 8.12, 8.16, 8.17, 9.07, 9.08, 9.1, 9.11, 9.13, 9.16, 9.17, 10.12, 10.16, 13.07, 13.08, 13.11, 13.12, 13.14, 13.15, 14.02

Platform Manager(s)SecurityAll Available Log Sources
CCF: Host Access Granted And Revoked InvThis investigation details all access granted and revoked for production systems.691

2.01, 2.03, 2.09, 4.06, 4.07, 4.15, 4.16, 4.17, 4.21, 4.22, 4.26, 4.31, 4.32, 4.33, 4.41, 4.42, 4.43, 5.06, 5.07, 5.09, 7.01, 7.03, 7.05, 7.08, 7.09, 7.12, 7.14, 7.16, 7.17, 8.03, 8.04, 8.09, 8.12, 8.16, 8.17, 9.07, 9.08, 9.1, 9.11, 9.13, 9.16, 9.17, 10.12, 10.16, 11.1, 11.11, 11.13, 12.01, 12.02, 12.03, 12.05, 12.06, 12.07, 12.08, 12.09, 12.1, 12.11, 12.14, 12.15, 12.17, 12.18, 12.19, 12.2, 12.21, 12.22, 12.26, 13.07, 13.08, 13.11, 13.12, 13.14, 13.15, 14.02

Data Processor(s)AuditAll Available Log Sources
CCF: LogRhythm Data Loss Defender Log InvThis investigation provides information on data generated by the LogRhythm Data Loss Defender.  Data is grouped by Entity, Impacted Host, Common Event, and Object with a count of how many times that condition has been experienced within the investigation period.692

2.03, 2.09, 4.06, 4.07, 4.15, 4.16, 4.18, 4.19, 4.26, 4.31, 4.32, 4.33, 4.41, 4.42, 4.43, 5.06, 5.07, 5.08, 5.09, 7.01, 7.03, 7.05, 7.08, 7.09, 7.12, 7.14, 7.16, 7.17, 8.03, 8.04, 8.09, 8.12, 8.16, 8.17, 9.07, 9.08, 9.1, 9.11, 9.13, 9.16, 9.17, 10.12, 10.16, 11.1, 11.11, 11.13, 13.09, 13.12, 14.02

Data Processor(s)AuditAll Available Log Sources
CCF: Malware Detected InvThis investigation provides a summary of malware activity by entity and impacted host within the organization's critical and production environments (entity structure).677

2.03, 2.06, 2.09, 2.1, 4.06, 4.07, 4.09, 4.15, 4.25, 4.26, 4.31, 4.32, 4.33, 4.35, 4.41, 4.42, 4.43, 4.44, 5.06, 5.07, 5.09, 7.01, 7.03, 7.05, 7.06, 7.07, 7.08, 7.09, 7.12, 7.14, 7.15, 7.16, 7.17, 8.03, 8.04, 8.09, 8.12, 8.16, 8.17, 9.07, 9.08, 9.1, 9.11, 9.12, 9.13, 9.16, 9.17, 10.12, 10.16

Platform Manager(s)SecurityAll Available Log Sources
CCF: Object Access InvThis investigation summarizes object access by Impacted Host.693

2.01, 2.03, 2.09, 4.03, 4.06, 4.07, 4.15, 4.16, 4.17, 4.21, 4.22, 4.26, 4.31, 4.32, 4.33, 4.41, 4.42, 4.43, 5.06, 5.07, 5.08, 5.09, 7.01, 7.03, 7.05, 7.08, 7.09, 7.11, 7.12, 7.14, 7.16, 7.17, 8.03, 8.04, 8.09, 8.12, 8.16, 8.17, 9.07, 9.08, 9.1, 9.11, 9.13, 9.16, 9.17, 10.12, 10.16, 13.07, 13.08, 13.11, 13.12, 13.14, 13.15, 14.02

Data Processor(s)AuditAll Available Log Sources
CCF: Password Modification InvThis investigation provides detail around password modification to accounts within the environment.702

2.01, 2.03, 2.09, 4.06, 4.15, 4.16, 4.17, 4.21, 4.22, 4.26, 4.31, 4.32, 4.33, 4.41, 4.42, 4.43, 5.06, 5.07, 5.09, 7.01, 7.03, 7.05, 7.08, 7.09, 7.11, 7.12, 7.14, 7.16, 7.17, 8.03, 8.04, 8.09, 8.12, 8.16, 8.17, 9.07, 9.08, 9.1, 9.11, 9.13, 9.16, 9.17, 10.12, 10.16, 11.1, 11.11, 11.13, 12.01, 12.02, 12.03, 12.05, 12.06, 12.07, 12.08, 12.09, 12.1, 12.11, 12.14, 12.15, 12.17, 12.18, 12.19, 12.2, 12.21, 12.22, 12.25, 12.26, 13.07, 13.08, 13.11, 13.12, 13.14, 13.15, 14.02

Platform Manager(s)AuditAll Available Log Sources
CCF: Patch Activity InvThis investigation provides a summary of applied patches grouped by Origin Host. It can demonstrate that all system components have the latest security patches installed.678

2.03, 2.04, 2.05, 2.09, 3.04, 3.05, 4.03, 4.05, 4.06, 4.07, 4.08, 4.15, 4.26, 4.31, 4.32, 4.33, 4.41, 4.42, 4.43, 5.06, 5.07, 5.09, 6.08, 6.11, 6.15, 6.18, 6.23, 6.24, 7.01, 7.03, 7.05, 7.08, 7.09, 7.12, 7.14, 7.16, 7.17, 8.03, 8.04, 8.09, 8.12, 8.16, 8.17, 9.07, 9.08, 9.1, 9.11, 9.13, 9.16, 9.17, 10.12, 10.16, 13.07, 13.08, 13.11, 13.14, 13.15, 14.04

Data Processor(s)SecurityAll Available Log Sources
CCF: Physical Access InvThis investigation summarizes physical door access/authentication success and failures within the organization's physical security perimeter.679

2.01, 2.03, 2.09, 4.06, 4.15, 4.17, 4.21, 4.22, 4.26, 4.31, 4.32, 4.33, 4.41, 4.42, 4.43, 5.06, 5.07, 5.09, 7.01, 7.03, 7.05, 7.08, 7.09, 7.11, 7.12, 7.13, 7.14, 7.16, 7.17, 8.03, 8.04, 8.09, 8.12, 8.16, 8.17, 9.07, 9.08, 9.1, 9.11, 9.13, 9.16, 9.17, 10.12, 10.16, 13.12

Platform Manager(s)AuditAll Available Log Sources
CCF: Privileged Account Escalation InvThis investigation provides detail around privileged access escalation within a Linux and Windows OS.  This requires configuration and enablement of CCF: Windows RunAs Privilege Escalation & CCF: Linux sudo Privilege Escalation AIE rules.700

2.01, 2.03, 2.09, 4.06, 4.15, 4.16, 4.17, 4.21, 4.22, 4.26, 4.31, 4.32, 4.33, 4.41, 4.42, 4.43, 5.06, 5.07, 5.09, 7.01, 7.03, 7.05, 7.08, 7.09, 7.11, 7.12, 7.14, 7.16, 7.17, 8.03, 8.04, 8.09, 8.12, 8.16, 8.17, 9.07, 9.08, 9.1, 9.11, 9.13, 9.16, 9.17, 10.12, 10.16, 11.1, 11.11, 11.13, 12.01, 12.02, 12.03, 12.05, 12.06, 12.07, 12.08, 12.09, 12.1, 12.11, 12.14, 12.15, 12.17, 12.18, 12.19, 12.2, 12.21, 12.22, 12.25, 12.26, 13.07, 13.08, 13.11, 13.12, 13.14, 13.15, 14.02

Platform Manager(s)SecurityAll Available Log Sources
CCF: Privileged Account Modification InvThis investigation provides details around modifications made to privileged accounts within the environment.  This investigation requires the CCF: Privileged Accounts (user list) to be established and updated periodically.703

2.01, 2.03, 2.09, 4.06, 4.15, 4.16, 4.17, 4.21, 4.22, 4.26, 4.31, 4.32, 4.33, 4.41, 4.42, 4.43, 5.06, 5.07, 5.09, 7.01, 7.03, 7.05, 7.08, 7.09, 7.11, 7.12, 7.14, 7.16, 7.17, 8.03, 8.04, 8.09, 8.12, 8.16, 8.17, 9.07, 9.08, 9.1, 9.11, 9.13, 9.16, 9.17, 10.12, 10.16, 11.1, 11.11, 11.13, 12.01, 12.02, 12.03, 12.05, 12.06, 12.07, 12.08, 12.09, 12.1, 12.11, 12.14, 12.15, 12.17, 12.18, 12.19, 12.2, 12.21, 12.22, 12.25, 12.26, 13.07, 13.08, 13.11, 13.12, 13.14, 13.15, 14.02

Data Processor(s)AuditAll Available Log Sources
CCF: Rogue Access Point InvThis investigation provides a summary of all detected rogue wireless access points by Impacted Host across critical, production, and online banking environments (entity structure).680

2.03, 2.06, 2.09, 2.1, 4.06, 4.07, 4.09, 4.15, 4.16, 4.25, 4.26, 4.31, 4.32, 4.33, 4.35, 4.41, 4.42, 4.43, 4.44, 5.06, 5.07, 5.09, 7.01, 7.03, 7.05, 7.06, 7.07, 7.08, 7.09, 7.11, 7.12, 7.14, 7.15, 7.16, 7.17, 8.03, 8.04, 8.09, 8.12, 8.16, 8.17, 9.07, 9.08, 9.1, 9.11, 9.12, 9.13, 9.16, 9.17, 10.12, 10.16, 14.02

Platform Manager(s)SecurityAll Available Log Sources
CCF: Signature Activity InvThis investigation provides summary information on signature update activity across critical and production environments (entity structure).681

2.03, 2.04, 2.05, 2.09, 3.04, 3.05, 4.03, 4.05, 4.06, 4.07, 4.08, 4.15, 4.26, 4.31, 4.32, 4.33, 4.41, 4.42, 4.43, 5.06, 5.07, 5.09, 6.08, 6.11, 6.15, 6.18, 6.23, 6.24, 7.01, 7.03, 7.05, 7.08, 7.09, 7.12, 7.14, 7.16, 7.17, 8.03, 8.04, 8.09, 8.12, 8.16, 8.17, 9.07, 9.08, 9.1, 9.11, 9.13, 9.16, 9.17, 10.12, 10.16, 13.07, 13.08, 13.11, 13.14, 13.15, 14.04

LogMart(s)OperationsAll Available Log Sources
CCF: Social Media InvSummarizes the top URLs related to Social Media activity.695

2.03, 2.09, 4.06, 4.07, 4.15, 4.16, 4.26, 4.31, 4.32, 4.33, 4.41, 4.42, 4.43, 5.06, 5.07, 5.09, 7.01, 7.03, 7.05, 7.08, 7.09, 7.12, 7.14, 7.16, 7.17, 8.03, 8.04, 8.09, 8.12, 8.16, 8.17, 9.07, 9.08, 9.1, 9.11, 9.13, 9.16, 9.17, 10.12, 10.16, 14.02

Platform Manager(s)AuditAll Available Log Sources
CCF: Suspected Wireless Attack InvThis investigation provides information on suspected wireless attacks at the internal boundary including the type of attack and impacted (targeted) host and application (if applicable).  This is based on Critical and Production environments (can be defined with entity structure).682

2.03, 2.09, 4.06, 4.07, 4.15, 4.16, 4.26, 4.31, 4.32, 4.33, 4.41, 4.42, 4.43, 5.06, 5.07, 5.09, 7.01, 7.03, 7.05, 7.08, 7.09, 7.12, 7.14, 7.16, 7.17, 8.03, 8.04, 8.09, 8.12, 8.16, 8.17, 9.07, 9.08, 9.1, 9.11, 9.13, 9.16, 9.17, 10.12, 10.16, 14.02

Platform Manager(s)SecurityAll Available Log Sources
CCF: Suspicious Users InvThis investigation lists all users generating suspicious activity ordered by the number of events detected highest to lowest.685

2.03, 2.09, 4.06, 4.07, 4.15, 4.16, 4.26, 4.31, 4.32, 4.33, 4.41, 4.42, 4.43, 5.06, 5.07, 5.09, 7.01, 7.03, 7.05, 7.08, 7.09, 7.11, 7.12, 7.14, 7.16, 7.17, 8.03, 8.04, 8.09, 8.12, 8.16, 8.17, 9.07, 9.08, 9.1, 9.11, 9.13, 9.16, 9.17, 10.12, 10.16, 13.07, 13.08, 13.11, 13.12, 13.14, 13.15, 14.02

Data Processor(s)SecurityAll Available Log Sources
CCF: Time Sync Error InvThis investigation provides a summary of time sync errors occurring within critical and production environments (can be defined with entity structure).683

2.01, 2.03, 2.04, 2.05, 2.06, 2.09, 2.1, 3.04, 3.05, 4.03, 4.05, 4.06, 4.07, 4.08, 4.09, 4.15, 4.16, 4.17, 4.18, 4.19, 4.21, 4.22, 4.25, 4.26, 4.31, 4.32, 4.33, 4.35, 4.41, 4.42, 4.43, 4.44, 5.06, 5.07, 5.09, 6.08, 6.11, 6.15, 6.18, 6.23, 6.24, 7.01, 7.03, 7.05, 7.06, 7.07, 7.08, 7.09, 7.12, 7.14, 7.15, 7.16, 7.17, 8.03, 8.04, 8.09, 8.12, 8.16, 8.17, 9.07, 9.08, 9.1, 9.11, 9.12, 9.13, 9.16, 9.17, 10.12, 10.16, 11.1, 11.11, 11.13, 12.01, 12.02, 12.03, 12.05, 12.06, 12.07, 12.08, 12.09, 12.1, 12.11, 12.14, 12.15, 12.17, 12.18, 12.19, 12.2, 12.21, 12.22, 12.26, 13.07, 13.08, 13.09, 13.11, 13.14, 13.15, 14.01, 14.02, 14.04

Platform Manager(s)AuditAll Available Log Sources
CCF: Unknown User Account InvThis investigation provides detail of activity from unknown user accounts, based off of CCF user lists.697

2.01, 2.03, 2.09, 4.06, 4.07, 4.15, 4.16, 4.17, 4.21, 4.22, 4.26, 4.31, 4.32, 4.33, 4.41, 4.42, 4.43, 5.06, 5.07, 5.09, 7.01, 7.03, 7.05, 7.08, 7.09, 7.11, 7.12, 7.14, 7.16, 7.17, 8.03, 8.04, 8.09, 8.12, 8.16, 8.17, 9.07, 9.08, 9.1, 9.11, 9.13, 9.16, 9.17, 10.12, 10.16, 11.1, 11.11, 11.13, 12.01, 12.02, 12.03, 12.05, 12.06, 12.07, 12.08, 12.09, 12.1, 12.11, 12.14, 12.15, 12.17, 12.18, 12.19, 12.2, 12.21, 12.22, 12.25, 12.26, 13.07, 13.08, 13.11, 13.12, 13.14, 13.15, 14.02

Data Processor(s)SecurityAll Available Log Sources
CCF: Use Of Non-Encrypted Protocols InvThis investigation lists any use of non-encrypted protocols.686

2.03, 2.09, 4.06, 4.07, 4.15, 4.18, 4.19, 4.26, 4.31, 4.32, 4.33, 4.41, 4.42, 4.43, 5.06, 5.07, 5.09, 6.02, 6.14, 7.01, 7.03, 7.05, 7.08, 7.09, 7.12, 7.14, 7.16, 7.17, 8.03, 8.04, 8.09, 8.12, 8.16, 8.17, 8.18, 9.04, 9.07, 9.08, 9.1, 9.11, 9.13, 9.16, 9.17, 10.12, 10.16, 11.1, 11.11, 11.13, 13.09, 13.1

LogMart(s)AuditAll Available Log Sources
CCF: User Misuse InvThis investigation summarizes detected misuse by user.687

2.03, 2.09, 4.06, 4.07, 4.15, 4.16, 4.26, 4.31, 4.32, 4.33, 4.41, 4.42, 4.43, 5.06, 5.07, 5.09, 7.01, 7.03, 7.05, 7.08, 7.09, 7.11, 7.12, 7.14, 7.16, 7.17, 8.03, 8.04, 8.09, 8.12, 8.16, 8.17, 9.07, 9.08, 9.1, 9.11, 9.13, 9.16, 9.17, 10.12, 10.16, 13.07, 13.08, 13.11, 13.12, 13.14, 13.15, 14.02

Platform Manager(s)SecurityAll Available Log Sources
CCF: User Object Access InvThis investigation summarizes successful object access activity by user.694

2.01, 2.03, 2.09, 4.03, 4.06, 4.07, 4.15, 4.16, 4.17, 4.21, 4.22, 4.26, 4.31, 4.32, 4.33, 4.41, 4.42, 4.43, 5.06, 5.07, 5.08, 5.09, 7.01, 7.03, 7.05, 7.08, 7.09, 7.11, 7.12, 7.13, 7.14, 7.16, 7.17, 8.03, 8.04, 8.09, 8.12, 8.16, 8.17, 9.07, 9.08, 9.1, 9.11, 9.13, 9.16, 9.17, 10.12, 10.16, 13.07, 13.08, 13.11, 13.12, 13.14, 13.15, 14.02

Data Processor(s)AuditAll Available Log Sources
CCF: Vulnerability Detected InvThis investigation provides a summary of potential vulnerabilities detected across the critical and production environments (can be defined with entity structure).684

2.03, 2.06, 2.09, 2.1, 4.06, 4.07, 4.09, 4.15, 4.25, 4.26, 4.31, 4.32, 4.33, 4.35, 4.41, 4.42, 4.43, 4.44, 5.06, 5.07, 5.09, 7.01, 7.03, 7.05, 7.06, 7.07, 7.08, 7.09, 7.12, 7.14, 7.15, 7.16, 7.17, 8.03, 8.04, 8.09, 8.12, 8.16, 8.17, 9.07, 9.08, 9.1, 9.11, 9.12, 9.13, 9.16, 9.17, 10.12, 10.16

Platform Manager(s)SecurityAll Available Log Sources
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.