Skip to main content

Collection Manager Window

The Collection Manager window enables you to manage all Microsoft Collections. Click Configuration > Collections on the menu to launch it. This window is only available to Threat Prevention administrators.

Collection Manager Window

Collections are reusable lists of policy filter settings that help streamline the task of associating filters with event types on the Event Type tab during Policy Configuration or Template Configuration. They are configured globally and can be used in multiple policies in place of or in conjunction with individual filters. These collections are empty until you populate them with your environment information. When a collection is modified, the modifications affect all policies referencing the collection. At least one Agent must be deployed to populate Collections.

To use policy templates to create new policies, Collections must be configured. Several templates are configured using Collections as a policy filter. If the Collection is empty, then the policy does not monitor what it was designed to monitor.

Collections are organized into the following categories for Microsoft Collections:

  • Domains & Servers – Any domain or server (by name)
  • Contexts – Any context (e.g. containers and organizational units) within Active Directory
  • Objects – Any Active Directory object
  • Exchange Objects – Any mail-enabled user accounts or distribution lists
  • Lockdown Objects – Any Active Directory object, used for lockdown purposes
  • Exchange Trustees – Any account that has permission to another account’s mailbox or folder
  • Perpetrators – Any security principal that is making a change, used for monitoring purposes
  • Lockdown Perpetrators – Any security principal that is making a change, used for lockdown purposes
  • Exchange Perpetrators – Any security principal that is making a change in an Exchange environment, used for both monitoring and lockdown purposes
  • Classes – Any class within Active Directory
  • Attributes – Any attribute within Active Directory
  • IP Addresses – Any client address
  • Hosts – Any computer (by NetBIOS, DNS, and IP address)
  • File Paths – List of file paths for Windows file systems to be used with multiple agents

Select a collection category and click Manage… i to open the List of Collections Window.

Preconfigured Collections

Threat Prevention has the following pre-configured Collections:

Collection TypeName
Domains and ServersSBServers
ObjectsAdministrator Accounts
ObjectsAdministrator Groups
ObjectsSensitive Groups
ObjectsService Accounts
PerpetratorsAdministrative Accounts
PerpetratorsDomain Administrators
PerpetratorsFailed Authentications
PerpetratorsService Accounts
PerpetratorsSuccessful Authentications
PerpetratorsSuccessful HIPPAA PHI Account Authentications
PerpetratorsSystem Accounts
Lockdown PerpetratorsAllow Perpetrators
Lockdown PerpetratorsCritical GPO - Allow Perpetrators
Lockdown PerpetratorsDNS Records - Allow Perpetrators
Lockdown PerpetratorsGPOs - Allow  Perpetrators
Lockdown PerpetratorsGroup Lockdown - Allow Perpetrators
Lockdown PerpetratorsGroup User OU Object Delete and Move - Allow Perpetrators
Lockdown PerpetratorsObject Permissions - Allow Perpetrators
Lockdown PerpetratorsOU Structure - Allow Perpetrators
Lockdown PerpetratorsRoot Object - Allow Perpetrators
Lockdown PerpetratorsUser Lockdown - Allow Perpetrators
ClassesExclude Classes
ClassesThreat Manager - AD Excluded Classes
AttributesExclude Attributes
AttributesExclude User Attributes
AttributesProperty Set: DNS-Host-Name-Attributes
AttributesProperty Set: Domain-Other-Parameters
AttributesProperty Set: Domain-Password
AttributesProperty Set: General-Information
AttributesProperty Set: Membership
AttributesProperty Set: Personal-Information
AttributesProperty Set: Private-Information
AttributesProperty Set: Public-Information
AttributesProperty Set: RAS-Information
AttributesProperty Set: Terminal-Server-License-Server
AttributesProperty Set: User-Account-Restrictions
AttributesProperty Set: User-Login
AttributesProperty Set: Web-Information
AttributesThreat Manager - AD Excluded Attributes
HostsDomain Controllers
HostsExchanges Servers
File PathsFolders with Sensitive Data. If you
File PathsOpen Shares