Hub
Security

CyberArk Privileged Threat Analytics

CyberArk Privileged Threat Analytics (PTA) security alerts as PTA sends them to a SIEM over syslog in CEF, each line the ECS JSON document the Elastic cyberark_pta integration builds, with the CEF record in event.original. For SIEM parsing and correlation testing: one PTA server watches one Vault with 120 Vault users, 163 privileged accounts and 97 administrator workstations and jump hosts, about 490 alerts on a weekday and 405 on a weekend day. Every record is a PTA detection, not benign activity. Recurring episodes chain dormant-user, irregular-hours and credential-theft alerts on one privileged account.

Quick Start

uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
  --path generators/security-cyberark-pta/generator.yml \
  --id pta \
  --live-mode true

Event Types

Event IDDescriptionFrequencyCategory
23Privileged access to the Vault during irregular hours (severity 2)60.3% of alertsVault access
1Suspected credentials theft (severity 8)27.5% of alertsCredential use outside the Vault
26Active dormant Vault user (severity 5)12.2% of alertsVault access

Realism Features

  • About 490 alerts on a weekday and 405 on a weekend day, hours in UTC. Irregular-hours alerts peak in the evening (about 26 an hour at 20:00 on weekdays and 32 at weekends), with a smaller early-morning peak (about 14 an hour at 06:00), 3-4 an hour after midnight and about 11 an hour in office hours from users whose usual hours differ; Saturdays and Sundays add about 8 an hour between 08:00 and 22:00. Credential-theft and dormant-user alerts follow the weekday working day (about 10-13 and 4-6 an hour between 08:00 and 18:00, about 1 an hour or fewer at night), with 3-5 theft alerts an hour through the weekend day.
  • Activity is uneven across actors: fourteen on-call administrators raise about 40% of the irregular-hours alerts (about 7-8 a day each) and about 64% of the dormant-user alerts, and six administrator workstations whose owners connect with known passwords raise about 22% of the theft alerts (4-5 a day each). Other users raise about ten alerts a week at the median, and most other workstations a few.
  • Incidents vary in shape: single alerts, repeats by the same actor minutes later (an irregular-hours access on the same or another account, a workstation reusing the account) and every two-alert part of the chain - a dormant user accessing the same account at an irregular hour minutes later in the evening or at night, irregular-hours access followed by credential theft on that account 5-60 minutes later, and a dormant-user alert followed by credential theft.
  • The CEF header and 16 extension keys follow a real PTA 11.4 Elastic fixture and a PTA 12.0 Secureworks Taegis sample, with their labels and link form for all three classes; the EventID is a MongoDB ObjectId prefixed with the detection second, as in both records. Class 1 comes from the Elastic PTA 12.6 example, which matches the CyberArk documentation example rather than a captured record.
  • The JSON follows the Elastic parsed output without collector fields. @timestamp is the detection time on a whole second without milliseconds, deviceCustomDate1 stays in epoch milliseconds, and sourceAddress and source.ip are left out when src=None because no public fixture shows how the pipeline parses that value.
  • Only the three detections with a published raw record are modeled, and the meaning of duser, dhost and dst in Vault-user alerts is assumed. Rates, hour and weekday curves, repeat frequencies and actor pools are synthetic; the busiest Vault users raise dormant-user alerts up to about three times a day, far more often than a real dormancy period would allow. Repeated alerts of one actor are rarely less than a minute and a half apart (median about 6 minutes), where PTA may raise alerts of one Vault login within seconds. Severities are fixed per class, with no risk scoring, alert aggregation, ExtraData content, external links, syslog header or transport.

Sample Output

{
  "@timestamp": "2026-09-15T19:14:08Z",
  "cef": {
    "device": {
      "event_class_id": "23",
      "product": "PTA",
      "vendor": "CyberArk",
      "version": "12.0"
    },
    "extensions": {
      "destinationAddress": "10.20.30.37",
      "destinationHostName": "srv-app-02.corp.example.test",
      "destinationUserName": "administrator@srv-app-02.corp.example.test",
      "deviceCustomDate1": "1789499648000",
      "deviceCustomDate1Label": "DetectionDate",
      "deviceCustomString1": "None",
      "deviceCustomString1Label": "ExtraData",
      "deviceCustomString2": "6aa9990050dae0b42a456337",
      "deviceCustomString2Label": "EventID",
      "deviceCustomString3": "https://pvwa.corp.example.test:443/PasswordVault/v10/pta/events/6aa9990050dae0b42a456337",
      "deviceCustomString3Label": "PTALink",
      "deviceCustomString4": "None",
      "deviceCustomString4Label": "ExternalLink",
      "sourceHostName": "None",
      "sourceUserName": "i.tarasov(Vault user)"
    },
    "name": "Privileged access to the Vault during irregular hours",
    "severity": "2",
    "version": "0"
  },
  "cyberark_pta": {
    "log": {
      "event_type": "23"
    }
  },
  "destination": {
    "domain": "srv-app-02.corp.example.test",
    "ip": "10.20.30.37",
    "user": {
      "domain": "srv-app-02.corp.example.test",
      "email": "administrator@srv-app-02.corp.example.test",
      "name": "administrator"
    }
  },
  "ecs": {
    "version": "8.11.0"
  },
  "event": {
    "code": "23",
    "dataset": "cyberark_pta.events",
    "id": "6aa9990050dae0b42a456337",
    "original": "CEF:0|CyberArk|PTA|12.0|23|Privileged access to the Vault during irregular hours|2|suser=i.tarasov(Vault user) shost=None src=None duser=administrator@srv-app-02.corp.example.test dhost=srv-app-02.corp.example.test dst=10.20.30.37 cs1Label=ExtraData cs1=None cs2Label=EventID cs2=6aa9990050dae0b42a456337 deviceCustomDate1Label=DetectionDate deviceCustomDate1=1789499648000 cs3Label=PTALink cs3=https://pvwa.corp.example.test:443/PasswordVault/v10/pta/events/6aa9990050dae0b42a456337 cs4Label=ExternalLink cs4=None",
    "reason": "Privileged access to the Vault during irregular hours",
    "reference": "https://pvwa.corp.example.test:443/PasswordVault/v10/pta/events/6aa9990050dae0b42a456337",
    "severity": 2,
    "url": "None"
  },
  "observer": {
    "product": "PTA",
    "vendor": "CyberArk",
    "version": "12.0"
  },
  "related": {
    "user": [
      "i.tarasov(Vault user)",
      "administrator",
      "administrator@srv-app-02.corp.example.test"
    ]
  },
  "source": {
    "domain": "None",
    "user": {
      "name": "i.tarasov(Vault user)"
    }
  }
}

Parameters

ParameterDefaultDescription
anomaly_modetrueAdd recurring anomaly episodes to the background
anomaly_interval_hours24Hours between episode starts; at least 6
pta_version12.0Version in the CEF header, cef.device.version and observer.version
pvwa_hostpvwa.corp.example.testPVWA host in the PTA event link (cs3)

Related Generators