Center Discovery

Microsoft.AdvancedThreatAnalytics.1_9.Center.Discovery (Discovery)

Discovers Microsoft ATA 1.9 Center using PowerShell

Knowledge Base article:

Summary

This discovery discovers instances of Microsoft ATA 1.9 Center class as well as their properties on computers.

Element properties:

TargetMicrosoft.AdvancedThreatAnalytics.1_9.Seed
EnabledTrue
Frequency14400
RemotableFalse

Object Discovery Details:

Discovered Classes and their attribuets:

Member Modules:

ID Module Type TypeId RunAs 
PowerShell DataSource Microsoft.AdvancedThreatAnalytics.1_9.Center.Discovery.DataSource Default

Source Code:

<Discovery ID="Microsoft.AdvancedThreatAnalytics.1_9.Center.Discovery" Enabled="true" Target="Microsoft.AdvancedThreatAnalytics.1_9.Seed" ConfirmDelivery="true" Remotable="false" Priority="Normal">
<Category>Discovery</Category>
<DiscoveryTypes>
<DiscoveryClass TypeID="Microsoft.AdvancedThreatAnalytics.1_9.Center">
<Property TypeID="Microsoft.AdvancedThreatAnalytics.1_9.Center" PropertyID="ServerName"/>
<Property TypeID="Microsoft.AdvancedThreatAnalytics.1_9.Center" PropertyID="Version"/>
<Property TypeID="Microsoft.AdvancedThreatAnalytics.1_9.Center" PropertyID="ConsoleAddress"/>
<Property TypeID="Microsoft.AdvancedThreatAnalytics.1_9.Center" PropertyID="ServiceIP"/>
<Property TypeID="Microsoft.AdvancedThreatAnalytics.1_9.Center" PropertyID="ServicePort"/>
<Property TypeID="Microsoft.AdvancedThreatAnalytics.1_9.Center" PropertyID="ConsoleCertificateThumbprint"/>
<Property TypeID="Microsoft.AdvancedThreatAnalytics.1_9.Center" PropertyID="InstallationPath"/>
<Property TypeID="Microsoft.AdvancedThreatAnalytics.1_9.Center" PropertyID="ADForest"/>
<Property TypeID="System!System.Entity" PropertyID="DisplayName"/>
</DiscoveryClass>
<DiscoveryClass TypeID="Microsoft.AdvancedThreatAnalytics.1_9.Database"/>
</DiscoveryTypes>
<DataSource ID="PowerShell" TypeID="Microsoft.AdvancedThreatAnalytics.1_9.Center.Discovery.DataSource">
<computerName>$Target/Host/Property[Type="Windows!Microsoft.Windows.Computer"]/PrincipalName$</computerName>
<IntervalSeconds>14400</IntervalSeconds>
</DataSource>
</Discovery>