Active Directory Correlation Rules

Active Directory Correlation Rules

Purposes: POC (internal use only)

Version: Sentinel 7 (it would work on Sentinel 6 as well)

Type: Solution Pack

Some notes:
- This solution pack was built based on some (not all) Change Guardian rules and there are around 47 correlation rules
- It could be used when Change Guardian is missing and you need some correlation rules specifically for Active Directory.
- It was grouped in 3 different control types: for Users, for Groups and for Computers
- Some of them request or use dynamic list (e.g. AD_Authorized_Accounts) so it would be needed to populate them according to customer environment after importing and installing.
- Just some correlation rules were tested considering all scenarios so maybe it would be needed some changes on them

NetIQ does not test or validate any software, code or other materials provided in, on or through NetIQ Cool Solutions (collectively, "Materials"), so please use caution when downloading or accessing any Materials from Cool Solutions and ensure that you have reasonable and current security, spyware and anti-virus measures in place on your computer and/or network prior to downloading. Additionally, do not use any Materials downloaded from Cool Solutions in any production environment without first testing the Materials to ensure they are compatible with your version of NetIQ software or any other hardware or software present in your network or environment. Cool Solutions is not a substitute for authorized NetIQ support and should not be used as such. NETIQ COOL SOLUTIONS AND ANY MATERIALS ARE PROVIDED ON AN AS-IS, AS-AVAILABLE BASIS WITHOUT ANY WARRANTY OF ANY KIND. By downloading this file, you are agreeing to these terms of use. To report a problem please contact: Your use of Cool Solutions is governed by the Cool Solutions Terms and Conditions.


Some content on Community Tips & Information pages is not officially supported by Micro Focus. Please refer to our Terms of Use for more detail.
Top Contributors
Version history
Revision #:
1 of 1
Last update:
‎2012-08-18 19:12
Updated by:
The opinions expressed above are the personal opinions of the authors, not of Micro Focus. By using this site, you accept the Terms of Use and Rules of Participation. Certain versions of content ("Material") accessible here may contain branding from Hewlett-Packard Company (now HP Inc.) and Hewlett Packard Enterprise Company. As of September 1, 2017, the Material is now offered by Micro Focus, a separately owned and operated company. Any reference to the HP and Hewlett Packard Enterprise/HPE marks is historical in nature, and the HP and Hewlett Packard Enterprise/HPE marks are the property of their respective owners.