Know when a file, directory or permission changes against a baseline you set — including the bulk change that matters more as one event than as thousands of lines.
Some risks are data changing while it stays exactly where it is. A configuration file overwritten outside a change window. A contract altered after it was approved. A directory of records modified at three in the morning when nobody was working. A permission quietly widened so a folder became readable across the organisation.
File integrity monitoring watches the locations you nominate and reports change against a baseline you set. The point is not to log everything — logs nobody reads are not evidence. The point is that an expected change stays quiet and an unexpected one does not, and that when you look at a change later you can see what the file was before as well as after.
Four gaps that only change monitoring closes.
Controls stop what they are configured to stop. Change monitoring is how you find out about the thing that got through.
Someone with valid permissions altering a record does not trigger an access alert, because nothing about the access was wrong.
Thousands of files modified in minutes is one significant event, but most tooling reports it as thousands of separate lines nobody reads.
Knowing a file changed is far less useful than being able to see what it said before somebody changed it.
Six capability areas built around keeping the signal usable.
You nominate which files and directories matter. Everything is measured against that known-good state rather than against a general assumption.
Content is the obvious one, but a permission change or a quiet move is often the more meaningful signal.
A deployment window or a scheduled job should not produce alerts. Declaring what is routine is what keeps the unexpected visible.
When many files change together, that pattern is the finding. It is raised as a single event describing the shape of what happened.
The state of a monitored file is retained on both sides of a change, so an investigation reads the difference rather than inferring it.
Monitoring continues on a host with no outbound connection, and records reconcile centrally once the link is available again.
Integrity findings are written as structured events in the same record as policy decisions, so an investigation does not have to join two systems by hand.
A setting changed outside a change window is often the first visible sign of either a mistake or an intrusion.
A large number of files rewritten in a short period has a distinctive shape, and raising it as one event is what makes it noticeable.
A signed agreement or an approved record that changes afterwards, with the previous state kept so the difference is provable.
A permission change on a sensitive directory is reported as a change in its own right, not only as a difference at the next scan.
Declared change windows and grouped bulk events exist so the alerts that do arrive are worth reading. An unread log is not evidence.
An investigation can read what changed rather than reconstructing it from a timestamp and a hash.
Change events sit beside policy decisions in the same searchable record, so an incident reads as one sequence.
A monitored host with no outbound connection keeps recording, and reconciles centrally when the link returns.
That is the main design problem, and it is addressed two ways: you declare the change windows and processes that are routine, and bulk change is raised as one event rather than thousands.
It retains the prior state of a file you have explicitly put under monitoring, for the retention period you set, so a change can be examined. Nothing outside your nominated locations is retained.
Monitoring continues locally and the records reconcile with the central view once a connection is available again.
Both. Permission and ownership changes are reported as changes in their own right, which is often the more meaningful signal.
The other three deal with data moving. This one deals with data changing where it sits. All four write to the same event record, so an investigation covers both without joining systems by hand.
The four products are designed to hand work to each other. Each one is stronger for what the others produce.
Find sensitive data across the shares, endpoints, mailboxes and cloud stores you nominate — and see who can currently reach it.
Find out more →Apply your organisation's own categories to the data discovery found — automatically where the match is clear, with a reviewer where it is not.
Find out more →Decide what labelled data may leave, and act at the moment it tries — on the endpoint, in email, in the browser and on removable media.
Find out more →Integrity monitoring is easiest to judge against a location you already consider sensitive. Tell us which one and we will baseline it in the session.